DevSecOps Engineer

Camlin Group

Kraków

Hybrid

PLN 140,000 - 210,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model (office in Kraków)
Company Pension & Life Assurance Sche
On-site parking (car and bike)
MyBenefit with Multisport & private 의료

Job summary

Camlin is seeking a DevSecOps Engineer to strengthen our Embedded Systems Unit in Kraków. You will work with embedded development teams and the ISMS to ensure cybersecurity requirements (CRA, RED, IEC 62443) are met across development, testing, manufacturing, and deployment environments.

The role is hybrid and remote-friendly, with at least one onsite interview in the Kraków office. You will support full lifecycle of embedded systems, toolchains, factory test infrastructure, and backend services.

Qualifications

  • Familiarity with SCA/SAST/DAST tools such as SonarQube, JFrog XRay, or similar.
  • Understanding of SBOM standards (CycloneDX, SPDX).
  • Programming in Python, Node.js.
  • Experience with SQL databases and API design.
  • Practical knowledge of monitoring and observability tools (Grafana, Prometheus, Loki).
  • Ability to maintain and troubleshoot factory automation systems and backend services.
  • Experience with Embedded Linux and Yocto.

Responsibilities

  • Execute secure development workflows defined by ISMS.
  • Run SCA / SAST / DAST tools within CI/CD pipelines.
  • Coordinate grey-box or white-box security tests on firmware and backend releases.
  • Validate RED 3.3(d/e/f) cybersecurity safeguards and IEC 62443 component requirements.
  • Generate and maintain Software Bills of Materials (SBOMs).
  • Operate and maintain firmware signing pipelines.
  • Support secure manufacturing workflows such as device identity injection and protected configuration handling.
  • Own and improve factory self-tests, diagnostics, and manufacturing server infrastructure.
  • Add new dashboards, performance metrics, and manufacturing KPIs.
  • Implement data visualization, alerting, and monitoring in Grafana.

Skills

SCA/SAST/DAST tools
SBOM standards
Python
Node.js
SQL databases
API design
Grafana
Prometheus
Loki
Embedded Linux
Yocto
Factory automation

Tools

SonarQube
JFrog XRay
GitLab

Job description

About Camlin

Camlin is a global technology leader that operates with the vision of bringing revolutionary products to life for a wide range of industries, including power and rail, and also has interests in a number of R&D projects in a variety of scientific sectors.

About Camlin

Camlin is a global technology leader that operates with the vision of bringing revolutionary products to life for a wide range of industries, including power and rail, and also has interests in a number of R&D projects in a variety of scientific sectors. At Camlin we believe in high quality engineering and design, allowing us to develop market leading products and services. In short, we love creating value for our customers by solving difficult problems. As of now, Camlin operates in over 20 countries worldwide. We are looking for a DevSecOps Engineer (or a DevOps Engineer with a strong security mindset) to strengthen our Embedded Systems Unit. In this role, you will collaborate closely with embedded development teams and our Information Security Management System (ISMS) team to ensure that our industrial and field‑deployed products meet cybersecurity requirements defined in CRA, RED, and IEC 62443. You will not be responsible for creating governance processes; instead, you will execute and apply the workflows and policies defined by ISMS, ensuring they are consistently implemented across development, testing, manufacturing, and deployment environments. You will support the full lifecycle of our embedded systems, toolchains, factory test infrastructure, and backend services. IMPORTANT NOTE: Although this role is in a hybrid way of working and remote friendly, at least One Interview from selection process will require to be onsite in our Krakow office.

Responsibilities
Secure Development & Compliance
  • Execute secure development workflows defined by ISMS. Support developers in applying secure coding, secure update mechanisms, access‑control, and documentation practices aligned with CRA/RED/IEC 62443.
Vulnerability Scanning & Reporting
  • Run SCA / SAST / DAST tools (e.g., SonarQube, JFrog XRay) within CI/CD pipelines.
  • Prepare actionable vulnerability reports aligned with CRA and IEC 62443 vulnerability‑handling requirements.
Security Testing
  • Perform or coordinate grey‑box or white‑box security tests on firmware and backend releases.
  • Validate system behaviour against RED 3.3(d/e/f) cybersecurity safeguards and IEC 62443 component requirements.
Software License & SBOM Reporting
  • Generate and maintain Software Bills of Materials (SBOMs).
  • Produce OSS license compliance reports to support CRA transparency and supply‑chain documentation.
Security Tooling for Production & Field Devices
  • Operate and maintain firmware signing pipelines.
  • Handle certificate provisioning, key management tools, and secure device onboarding workflows defined by ISMS.
  • Support secure manufacturing workflows such as device identity injection and protected configuration handling.
Factory Test Systems
  • Own and improve factory self‑tests, diagnostics, and manufacturing server infrastructure.
  • Add new dashboards, performance metrics, and manufacturing KPIs.
  • Implement data visualization, alerting, and monitoring in tools such as Grafana.
Database & Backend Infrastructure
  • Maintain and further develop the manufacturing database.
  • Implement structured schema versioning.
  • Develop APIs to replace direct SQL access and improve data integrity.
  • Optimize database structure, queries, and overall performance.
CI/CD & Automated Deployment
  • Maintain secure, reproducible CI/CD build and release pipelines for embedded firmware and backend services.
  • Manage deployment workflows, including environment provisioning, artifact signing, and release traceability.
Technical Skills
Required Skills & Qualifications
  • Familiarity with SCA/SAST/DAST tools such as SonarQube, JFrog XRay, or similar.
  • Understanding of SBOM standards (CycloneDX, SPDX).
  • Programming in Python, Node.js.
  • Experience with SQL databases and API design.
  • Practical knowledge of monitoring and observability tools (Grafana, Prometheus, Loki).
  • Ability to maintain and troubleshoot factory automation systems and backend services.
  • Experience with Embedded Linux and Yocto
Cybersecurity & Standards
  • Understanding of cybersecurity principles relevant to embedded systems.
  • Awareness of CRA, RED cybersecurity requirements, and IEC 62443 concepts (zones, conduits, secure development lifecycle).
  • Willingness for executing ISMS‑defined processes (secure SDLC, vulnerability management, incident support).
  • Familiarity with secure communication protocols (TLS, certificate pinning, encrypted transport layers).
Desired Qualifications (Nice‑to‑Have)
  • Familiarity with CI/CD pipeline development in GitLab
  • Understanding of database architecture
  • Experience with Node.js
  • Hands‑on with Grafana
Benefits:
  • Employment contract with competitive salary
  • Work in small, self‑organized and autonomous development teams with the ability to choose technologies and best practices
  • Hybrid work model (office in Kraków)
  • Company Pension & Life Assurance Schemes
  • On-site parking (car and bike)
  • UoP with 80% author’s rights tax relief
  • MyBenefit system with Multisport membership, private healthcare (Medicover)
  • Wellness programmes
Our Values
  • We work together
  • We believe in people
  • We won’t accept the ‘way it has always been done’
  • We listen to learn
  • We’re trying to do the right thing
Equal Employment Opportunity Statement

Individuals seeking employment at Camlin are considered without regards to race, colour, religion, national origin, age, sex, marital states, ancestry, physical or mental disability, gender identity or sexual orientation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

Camlin • Poland

Hybrid
PLN 256,000 - 342,000
Competitive salary
Hybrid work model
Company Pension & Life Assurance Schemes
+4
Embedded DevSecOps Engineer: Secure Firmware & CI/CD
Embedded DevSecOps Engineer: Secure Firmware & CI/CD

Camlin Group • Kraków

Hybrid
PLN 140,000 - 210,000
Hybrid work model (office in Kraków)
Company Pension & Life Assurance Sche
On-site parking (car and bike)
+1
Hardware Test Automation & Validation Engineer
Hardware Test Automation & Validation Engineer

Camlin Group • Kraków

On-site
PLN 90,000 - 130,000
Competitive salary
Multisport membership (MyBenefit)
Private healthcare (Medicover)
+3
Engineer - Cybersecurity (Vulnerability & Threat Management)
Engineer - Cybersecurity (Vulnerability & Threat Management)

Sysco Corporation • Poland

Hybrid
PLN 40,000 - 60,000
Professional development opportunities
Collaborative culture
Modern security technologies
Associate Cloud Engineer (DevSecOps)
Associate Cloud Engineer (DevSecOps)

Kingfisher • Poland

Hybrid
Private medical healthcare for you and
Medicover sports card (FitMore)
Life insurance financed by the company
+4
C++ Embedded Engineer
C++ Embedded Engineer

SQUAD Ukraine Limited • Wrocław

On-site
Equal opportunities corporate culture
Performance-based annual reviews
Loyalty Bonus
+3
С & C++ Embedded Engineer
С & C++ Embedded Engineer

SQUAD Ukraine Limited • Wrocław

On-site
PLN 70,000 - 100,000
Competitive salary packages
Performance and Loyalty Bonuses
Paid vacation and medical leaves
+2
Software Engineer
Software Engineer

Kingfisher plc • Kraków

Hybrid
Private medical healthcare at LUXMED
Medicover sports card
Life insurance financed by the employer
+5
Embedded Automated Test & Test System Engineer
Embedded Automated Test & Test System Engineer

United States Digital Space LLC • Poland

On-site
PLN 156,000 - 670,000
Healthcare benefits
Parental leave
Paid time off
+4
DevSecOps Security Consultant
DevSecOps Security Consultant

ALTEN Polska • Kraków

On-site
PLN 180,000 - 240,000
Full-time contract
Work equipment provided
Conferences and trainings
+2