DevSecOps Engineer IRC303558

GlobalLogic Inc.

Polska

On-site

PLN 180,000 - 260,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

GlobalLogic is building a dedicated security validation team focused on vulnerability assessment and security testing across our products and systems. The team runs structured testing campaigns, including penetration testing, vulnerability discovery and triage, secure code review, and automated test suites to scale the process.

We explore AI models to accelerate security testing while remaining hands-on security engineering.

Qualifications

  • Hands-on with CI/CD tooling and security in pipelines.
  • Experience with SAST/DAST/DAST in pipelines and secrets scanning.
  • Proficient in IaC security and cloud fundamentals.
  • Familiarity with container security and image hardening.
  • Knowledge of security standards: OWASP, NIST, CIS, ISO 27001.
  • Ability to build AI agents and embed LLMs into the SDLC.

Responsibilities

  • Build and maintain secure CI/CD pipelines with security gates.
  • Automate security testing and policy checks across the SDLC.
  • Implement IaC security and secure baseline configurations.
  • Manage secrets and credentials across environments.
  • Secure containers and Kubernetes with image scanning and hardening.
  • Route findings into developer workflows and dashboards.
  • Define policy-as-code guardrails and track drift.
  • Support vulnerability management and remediation in pipelines.
  • Collaborate with developers to embed security by design.
  • Monitor security events and assist incident response.
  • Contribute to AI-assisted automation for security tasks.

Skills

CI/CD tooling
Security testing
Scripting & automation
Linux administration
Security standards
AI/LLMs in SDLC
Cloud security
Secrets management

Tools

GitLab CI
GitHub Actions
Jenkins
Azure DevOps
Semgrep
Snyk
Trivy
OWASP ZAP
Terraform
HashiCorp Vault
Docker
Kubernetes

Job description

and DevSecOps; Containerization and Orchestration using Docker, Containerization, Cybersecurity Technologies, DevSecOps / Shift-Left Security, Docker

An enterprise technology group is building a dedicated security validation team focused on vulnerability assessment and security testing across the group’s products and systems. The team runs structured testing campaigns: penetration testing, vulnerability discovery and triage, secure code review, and building automated test suites to make the process repeatable at scale.
The team also gets early access to specialized AI models and evaluates how they can accelerate security testing – an area we’re actively investing in, though the core of the work remains hands‑on security engineering. Scope covers internal systems as well as business-unit products across the group, agreed campaign by campaign. The team starts small and scales into a permanent capability.

Requirements

4+ years in DevOps / DevSecOps or software engineering with a strong security focus.
Hands‑on with CI/CD tooling (e.g. GitLab CI, GitHub Actions, Jenkins, Azure DevOps).
Security scanning in pipelines: SAST, DAST, SCA, secrets scanning (e.g. Semgrep, Snyk, Trivy, OWASP ZAP).
Infrastructure-as-Code (e.g. Terraform) and IaC security.
Containers and Kubernetes security (Docker, K8s, image scanning, hardening).
Cloud platforms (AWS / Azure / GCP) and cloud security fundamentals.
Secrets management (e.g. HashiCorp Vault, cloud KMS) and IAM basics.
Scripting and automation (Python, Bash) and Git.
Familiarity with standards and frameworks: OWASP, NIST, CIS Benchmarks, ISO 27001.
Understanding of and hands‑on experience with different LLMs; ability to build AI agents; and knowledge of embedding LLMs into the SDLC and pipelines.

Strong Linux skills (administration, hardening, command line, shell scripting).

Nice to have: certifications (e.g. CKA/CKS, AWS/Azure Security, CISSP); pentesting or vulnerability-management exposure.

Job responsibilities

Build and maintain secure CI/CD pipelines; embed security gates (SAST, DAST, SCA, secrets scanning) into the build.
Automate security testing and policy checks across the SDLC (shift‑left).
Implement Infrastructure-as-Code (IaC) security and secure baseline configuration.
Manage secrets, keys and credentials (vaulting, rotation) across environments.
Secure containers and Kubernetes (image scanning, hardening, runtime policies).
Set up security tooling and route findings into developer workflows and dashboards.
Define and enforce policy‑as‑code guardrails; track exceptions and drift.
Support vulnerability management: triage, prioritize and follow remediation through pipelines.
Work with developers and architects to embed security by design.
Monitor, log and respond to pipeline and cloud security events; support incident response.
Contribute to AI‑assisted automation (LLMs/agents) for security tasks in the pipeline.

What we offer

Empowering Projects: With 500+ clients spanning diverse industries and domains, we provide an exciting opportunity to contribute to groundbreaking projects that leverage cutting‑edge technologies. As a team, we engineer digital products that positively impact people’s lives.

Empowering Growth: We foster a culture of continuous learning and professional development. Our dedication is to provide timely and comprehensive assistance for every consultant through our dedicated Learning & Development team, ensuring their continuous growth and success.

DE&I Matters: At GlobalLogic, we deeply value and embrace diversity. We are dedicated to providing equal opportunities for all individuals, fostering an inclusive and empowering work environment.

Career Development: Our corporate culture places a strong emphasis on career development, offering abundant opportunities for growth. Regular interactions with our teams ensure their engagement, motivation, and recognition. We empower our team members to pursue their career goals with confidence and enthusiasm.

Comprehensive Benefits: In addition to equitable compensation, we provide a comprehensive benefits package that prioritizes the overall well‑being of our consultants. We genuinely care about their health and strive to create a positive work environment.

Flexible Opportunities: At GlobalLogic, we prioritize work-life balance by offering flexible opportunities tailored to your lifestyle. Explore relocation and rotation options for diverse cultural and professional experiences in different countries with our company.

About GlobalLogic

GlobalLogic, a Hitachi Group Company, is a trusted digital engineering partner to the world’s largest and most forward‑thinking companies. Since 2000, we’ve been at the forefront of the digital revolution – helping create some of the most innovative and widely used digital products and experiences. Today we continue to collaborate with clients in transforming businesses and redefining industries through intelligent products, platforms, and services.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Architect IRC302828
Cyber Security Architect IRC302828

GlobalLogic • Kraków

On-site
PLN 260,000 - 420,000
Comprehensive Benefits
Flexible Opportunities
Relocation & Rotation Options
Senior/Principal Security Engineer IRC303167
Senior/Principal Security Engineer IRC303167

GlobalLogic • Kraków

On-site
PLN 180,000 - 240,000
Diversity
Equal opportunities
Inclusive environment
+2
Information Security Officer
Information Security Officer

Hitachi, Ltd. • Wrocław

On-site
PLN 150,000 - 210,000
Information Security Officer IRC305340
Information Security Officer IRC305340

GlobalLogic Inc. • Polska

Hybrid
PLN 160,000 - 260,000
Career development
Flexible opportunities
Relocation options
+2
Senior Azure DevOps Engineer IRC303723
Senior Azure DevOps Engineer IRC303723

GlobalLogic Inc. • Polska

On-site
PLN 180,000 - 210,000
Relocation options
Flexible work opportunities
Career development support
Senior Azure DevOps Engineer IRC303723
Senior Azure DevOps Engineer IRC303723

GlobalLogic Inc. • Polska

Hybrid
PLN 300,000 - 420,000
Relocation options
Learning & Development
Diversity & Inclusion
+3
Information Security Officer IRC305340
Information Security Officer IRC305340

GlobalLogic Inc. • Kraków

On-site
PLN 120,000 - 180,000
Diverse projects
Learning & Development
DE&I emphasis
+3
Lead DevOps for Embedded Systems IRC304487
Lead DevOps for Embedded Systems IRC304487

GlobalLogic • Kraków

On-site
PLN 180,000 - 290,000
Relocation options
Rotation programs
Learning & development
+2
Security Operations Center (SOC) Lead / Manager
Security Operations Center (SOC) Lead / Manager

Hitachi, Ltd. • Kraków

Hybrid
PLN 360,000 - 480,000
Relocation options
Learning & Development
Inclusive culture
Lead DevOps Engineer
Lead DevOps Engineer

Hitachi, Ltd. • Kraków

Remote
PLN 240,000 - 360,000