DevSecOps Engineer

Randstad Polska Sp. z o.o.

Kraków

Hybrid

PLN 300,000 - 420,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work model (Kraków office)
Global exposure to open-source/cloud‑N
Flexible work arrangements

Job summary

Randstad Polska Sp. z o.o. in Kraków is seeking an experienced DevSecOps Engineer to drive end-to-end software supply chain security and CI/CD platform engineering in a cloud-native Kubernetes environment on GCP.

You will bridge software engineering and platform security, engineer Jenkins Groovy pipelines, integrate SBOM/CycloneDX, SLSA, and implement advanced automation with Python while optimizing pipelines and supporting Helm/Terraform deployments.

Qualifications

  • 7+ years of overall engineering experience, including at least 3 years in CI/CD platform engineering or DevSecOps.
  • Strong Jenkins Groovy expertise and experience building advanced Shared Libraries.
  • Advanced Python for custom automation tools and JSON/YAML processing.
  • Deep knowledge of packaging and containerization (Maven, NPM, Python packaging) with hands-on Helm, Terraform, and container image metadata.
  • Practical understanding of SBOM, CycloneDX, SLSA, and image digests.
  • Experience with SonarQube and Sonatype IQ for container scanning and SAST.
  • Proven pipeline tuning skills (caching, parallelization, dependency pruning).
  • Strong awareness of security compliance and governance practices.

Responsibilities

  • Design and expand Jenkins Groovy Shared Libraries and Tekton pipelines.
  • Integrate security scanning tools and implement SBOM/SLSA frameworks.
  • Develop Python automation scripts for configuration processing and API integrations.
  • Publish and standardize Helm charts and Terraform modules for GCP/Kubernetes deployments.
  • Troubleshoot pipeline issues and optimize CI/CD performance.

Skills

Jenkins Groovy
Python automation
Kubernetes
Helm & Terraform
SBOM/CycloneDX/SLSA
SonarQube/Sonatype IQ
CI/CD optimization
GitOps
GCP/AWS cloud

Tools

Terraform
Helm
Maven
NPM

Job description

We are looking for an experienced DevSecOps Engineer to drive end-to-end software supply chain security and enterprise CI/CD platform engineering across a cloud-native Kubernetes ecosystem on Google Cloud Platform (GCP). In this role, you will bridge software engineering and platform security, championing DevSecOps practices, engineering advanced Jenkins Groovy and Tekton pipelines, and securing artifact delivery using tools like SonarQube, Sonatype IQ, and SLSA frameworks.

If you bring a strong software engineering background, deep expertise in Kubernetes and CI/CD automation, and a passion for building resilient, highly secure release platforms, we want to hear from you.


What will your tasks involve?
  • CI/CD Platform Engineering: Design and expand Jenkins Groovy Shared Libraries and modern Kubernetes-native Tekton pipelines
  • Software Supply Chain Security: Integrate security scanning tools (SonarQube, Sonatype IQ) and implement security frameworks (SBOM/CycloneDX, SLSA, artifact signing)
  • Automation & Tooling: Develop custom Python automation scripts for advanced configuration processing (JSON/YAML) and API integrations
  • Cloud & Deployment Support: Publish and standardize Helm charts and Terraform modules for applications on Google Cloud Platform (GCP) and Kubernetes
  • Performance & Support: Optimize CI/CD pipeline performance (caching, parallelization) and troubleshoot user-reported pipeline issues for engineering teams

What we expect from you?

Requirements (Must-Have):

  • Experience: 7+ years of overall engineering experience, including at least 3 years specializing in CI/CD platform engineering or DevSecOps
  • Jenkins & Groovy: Strong expertise in engineering advanced Jenkins Groovy Shared Libraries
  • Advanced Python: Proven experience in building custom automation tools and scripts in Python (advanced JSON/YAML processing)
  • Packaging & Containerization: Deep knowledge of package management (Maven, NPM, Python packaging) and hands‑on exposure to Helm, Terraform, and container image metadata
  • Software Supply Chain Security: Practical understanding of SLSA frameworks, SBOM (CycloneDX), and image digests
  • Security Scanning Tools: Experience with SonarQube and Sonatype IQ for container scanning and SAST
  • Performance Optimization: Proven track record in pipeline tuning (caching, parallelization, dependency pruning)
  • Compliance Awareness: Strong awareness of security compliance and governance standard practices

Nice-to-Have:

  • Artifact signing and attestations (Cosign, OCI registry standard)
  • Publishing patterns for Terraform modules and Helm charts
  • Experience with GitOps or release automation patterns
  • Hands-on GCP or AWS cloud experience

Soft Skills:

  • Precise and effective technical communicator
  • Strong documentation discipline
  • Ownership mindset with the ability to operate independently with minimal supervision

What you can expect from us?
  • Contract: B2B
  • Work-Life Balance & Flexibility: Hybrid work model (3 days per week in our modern Kraków office, combining team collaboration with remote flexibility)
  • Global Exposure: Opportunity to work in a dynamic, international environment with cutting‑edge open‑source and cloud technologies

this job offer is intended for people over 18 years of age

досвід

powyżej 24 miesięcy

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Security Technical Delivery Lead
Software Security Technical Delivery Lead

Randstad Polska Sp. z o.o. • Kraków

Hybrid
PLN 300,000 - 420,000
Hybrid work model in Kraków office
Private medical care
MultiSport card
+1
Software Security Engineer Backend
Software Security Engineer Backend

Randstad Polska Sp. z o.o. • Kraków

Hybrid
PLN 180,000 - 280,000
Private medical care
MultiSport / sports card
DevOps Consultant with GCP
DevOps Consultant with GCP

GFT Technologies Poland • Kraków

Hybrid
PLN 180,000 - 240,000
DevOps Engineer with GCP
DevOps Engineer with GCP

GFT Technologies Poland • Kraków

On-site
PLN 180,000 - 240,000
Medical package
Sport facilities subsidy
Lunch subsidy
+1
Senior Software & DevSecOps Engineer (Go/Java)
Senior Software & DevSecOps Engineer (Go/Java)

Randstad Polska Sp. z o.o. • Warszawa

On-site
PLN 180,000 - 240,000
Senior DevOps Consultant with GCP
Senior DevOps Consultant with GCP

GFT Technologies Poland • Kraków

Hybrid
PLN 180,000 - 240,000
Senior DevOps Engineer with GCP
Senior DevOps Engineer with GCP

Clurgo Ltd. • Kraków

On-site
PLN 180,000 - 240,000
Opieka medyczna
Karta multisport
Lekcje języka angielskiego
Senior DevOps Engineer with GCP
Senior DevOps Engineer with GCP

GFT Technologies Poland • Kraków

On-site
PLN 200,000 - 320,000
Hybrid Kraków office (6 days/month)
Medical insurance
Lunch subsidy
GCP DevSecOps Engineer (10/994)
GCP DevSecOps Engineer (10/994)

Infolet • Kraków

Hybrid
PLN 240,000 - 360,000
Relocation package (4500 PLN total)
Extended medical care
Multisport Benefit card
+1
DevOps Engineer with GCP (f/m/x)
DevOps Engineer with GCP (f/m/x)

Sii Sp. z o.o. • Kraków

On-site
PLN 180,000 - 300,000
Private healthcare
Benefits cafeteria platform
Remote work (hybrid)