DevSecOps Architect / Technical Lead

DOU Polska

Warszawa

Hybrid

PLN 180,000 - 280,000

Full time

18 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Private health insurance and sports
Certification compensation
Referral program
Training portal access
Remote or hybrid work option

Job summary

Andersen is seeking a DevSecOps Architect / Technical Lead to drive a large-scale digital banking modernization. You will define secure CI/CD standards, shape an Azure-centric platform security plan and mentor delivery teams across engineering, security and architecture.

The role offers both remote and office options within a hybrid setup. Key focus areas include SBOM, artifact signing, gate-based release controls, and cross-team security strategy implementation with hands-on execution and

Qualifications

  • 5+ years of experience in DevSecOps, cloud security or platform security.
  • Experience designing and driving DevSecOps processes across multiple teams.
  • Translating security/DevSecOps strategy into practical roadmaps and standards.
  • Owning technical decisions and promoting DevSecOps adoption across engineering teams.
  • Strong hands-on experience with Microsoft Azure.
  • Hands-on with security controls in CI/CD (SAST, SCA, DAST, secret scanning, IaC scanning, container scanning).
  • Practical Kubernetes/container security experience (AKS).
  • Experience with Infrastructure as Code (Terraform).
  • Experience with identity, secrets, and certificate management.
  • Understanding SBOM, artifact signing, provenance and secure promotion of artifacts.
  • Ability to combine architecture with hands-on implementation and troubleshooting.
  • Experience mentoring engineers and working across infra, security, and architecture teams.
  • English level Upper-Intermediate+.

Responsibilities

  • Translate the DevSecOps master plan into a practical implementation roadmap.
  • Define reusable CI/CD, security and release-management standards.
  • Support transition to Azure Repos and Azure Pipelines.
  • Implement security scanning and release gates in CI/CD pipelines.
  • Configure security controls for AKS, container images, identities and secrets.
  • Establish artifact signing, SBOM generation and secure promotion processes.
  • Integrate platform security events with SIEM solutions.
  • Define vulnerability-management, audit-evidence and incident-response processes.
  • Provide technical leadership and knowledge transfer to delivery teams.
  • Participate in configuration, integration and troubleshooting activities.

Skills

DevSecOps
Azure
Kubernetes
Terraform
CI/CD
Security architecture
Leadership
Mentoring
English (Upper-Intermediate+)

Tools

Azure DevOps
AKS
Terraform
SonarQube
Sonatype/Nexus
Gitleaks/Checkov/OWASP ZAP
Azure Key Vault
Azure Container Registry
Defender for Containers
Microsoft Sentinel
Gatekeeper/OPA

Job description

Andersen is hiring a DevSecOps Architect / Technical Lead for a project modernizing digital banking architecture and enhancing security, scalability, and platform reliability.

The customer is a financial services organization providing banking products and digital solutions for individual and business clients. The company operates through an established service network and online platforms and is part of a larger international financial group, supporting ongoing development of its services for a broad client base.

The project is focused on defining a structured architecture roadmap for a large-scale digital banking transformation program. It includes target-state architecture, platform modernization, API governance, security, data and analytics, system decoupling, and phased migration of business capabilities to reduce system dependencies and accelerate future digital development.

Responsibilities
  • Translating the DevSecOps master plan into a practical implementation roadmap.
  • Defining reusable CI/CD, security and release-management standards.
  • Supporting the transition from Bitbucket/Jenkins to Azure Repos and Azure Pipelines.
  • Implementing security scanning and release gates in CI/CD pipelines.
  • Configuring security controls for AKS, container images, identities and secrets.
  • Establishing artifact signing, SBOM generation and secure promotion processes.
  • Integrating platform security events with the bank's monitoring and SIEM solutions.
  • Defining vulnerability-management, audit-evidence and incident-response processes.
  • Providing technical leadership, recommendations and knowledge transfer to delivery teams.
  • Participating directly in configuration, integration and troubleshooting activities.
Requirements
  • Experience in DevSecOps, cloud security or platform security for 5+ years.
  • Proven experience designing and driving DevSecOps processes, architecture, or engineering standards across multiple teams, not only implementing predefined solutions within a single project.
  • Experience translating high-level security or DevSecOps strategy into a practical technical roadmap, architecture decisions, standards, and implementation guidance.
  • Experience owning technical decisions and driving the adoption of DevSecOps practices across engineering teams.
  • Strong hands-on experience with Microsoft Azure.
  • Hands-on experience implementing security controls and gates across CI/CD, including several of the following: SAST, SCA, DAST, secret scanning, IaC scanning, and container scanning.
  • Practical experience with Kubernetes and container security, preferably AKS.
  • Experience with Infrastructure as Code, preferably Terraform.
  • Experience with identity, secrets, and certificate management.
  • Understanding of software supply-chain security practices such as SBOM, artifact signing, provenance, and secure artifact promotion.
  • Ability to combine architecture and technical leadership with hands-on implementation and troubleshooting.
  • Experience mentoring or technically guiding engineers and working across development, platform, security, and architecture teams.
  • Level of English – from Upper-Intermediate and above.
Nice-to-haves
  • Experience in the banking domain.
  • Experience with Jenkins, Bitbucket and migration to Azure DevOps.
  • Experience with Azure Key Vault, Azure Container Registry and Defender for Containers.
  • Familiarity with tools such as SonarQube, Sonatype, Nexus, Gitleaks, Checkov or OWASP ZAP.
  • Understanding of SBOM, artifact signing and software supply-chain security.
  • Experience with DefectDojo, Microsoft Sentinel or other vulnerability-management and SIEM solutions.
  • Experience with Azure Policy, Gatekeeper, OPA or Kubernetes admission controls.
  • Experience in banking or another regulated industry.
  • Understanding of DORA, audit traceability and segregation-of-duties requirements.
Reasons Why This Job Would Be Interesting To You
  • Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
  • The opportunity to change the project and/or develop expertise in an interesting business domain.
  • Job conditions - you can work both fully remotely and from the office or can choose a hybrid variant.
  • Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
  • The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
  • Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
  • Bright corporate life (parties / pizza days / PlayStation / fruits / coffee / snacks / movies).
  • Certification compensation (AWS, PMP, etc).
  • Referral program.
  • Private health insurance and sports compensation, depending on the type of employment.

Your personal data is protected in accordance with GDPR regulations. Learn more: https://andersenlab.com/privacy-policy/pl

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Management Consultant
Vulnerability Management Consultant

Andersen Lab • Polska

On-site
PLN 140,000 - 210,000
Private health insurance
Sports compensation
Mentoring programs
DevSecOps Architect / Technical Lead
DevSecOps Architect / Technical Lead

Solid Company • Polska

On-site
PLN 220,000 - 320,000
Penetration Tester
Penetration Tester

Andersen Lab • Polska

Hybrid
PLN 120,000 - 190,000
Private health insurance
Sports compensation
Remote/hybrid work options
SSIEM Administrator / Engineer
SSIEM Administrator / Engineer

Andersen Lab • Kraków

On-site
PLN 180,000 - 240,000
Private health insurance
Sports compensation
Mentoring program
+2
DevSecOps Engineer – Remote Work Type
DevSecOps Engineer – Remote Work Type

Directio Sp. z o.o. • Polska

Remote
PLN 279,000 - 368,000
Private healthcare
Multisport card
trainings
Senior DevSecOps Architect & Tech Lead – Azure Security
Senior DevSecOps Architect & Tech Lead – Azure Security

Solid Company • Polska

Hybrid
PLN 220,000 - 320,000
Senior DevSecOps Architect & Tech Lead: Azure & Security
Senior DevSecOps Architect & Tech Lead: Azure & Security

DOU Polska • Warszawa

Hybrid
PLN 180,000 - 280,000
Private health insurance and sports
Certification compensation
Referral program
+2
Senior Backend Developer (Java, Azure)
Senior Backend Developer (Java, Azure)

Luxoft Poland • Kraków

On-site
PLN 180,000 - 280,000
Private Medical & Dental care & Life保险
MyBenefit program (sports card, well‑|
Internal Mobility program
Senior Java AND Python Developer
Senior Java AND Python Developer

Luxoft Poland • Wrocław

On-site
PLN 180,000 - 260,000
Copyrights for higher net salary
Fully remote recruitment process
Stable employment
+4
Cloud security engineer - IAM (Azure & AWS)
Cloud security engineer - IAM (Azure & AWS)

PARETO SECURITIES AS • Warszawa

On-site
PLN 180,000 - 260,000
Mental health support
Free lunch at the office
Referral bonus up to PLN 10,000
+2