DevSecOps Security Consultant

ALTEN Polska

Kraków

On-site

PLN 180,000 - 240,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Full-time contract
Work equipment provided
Conferences and trainings
Certification opportunities
Opportunities to relocate within ALTEN

Job summary

ALTEN Polska is seeking an experienced Engineering Platform Security professional to design and implement a maturity framework, conduct security reviews, and drive secure-by-design practices across engineering platforms.

You will collaborate with platform owners and leadership to prioritise gaps, embed security patterns, and advance vulnerability management, SBOM, and code-signing within workflows.

Qualifications

  • Proven cybersecurity expertise in large, regulated environments.
  • Experience designing secure engineering platforms, CI/CD, and tooling.

Responsibilities

  • Develop and maintain an Engineering-Platform Cybersecurity Maturity Framework to standardise assessments across platforms.
  • Conduct platform security reviews against defined criteria (build systems, CI/CD pipelines, runtime infra, developer tooling).
  • Perform threat modelling and gap analysis to identify vulnerabilities and systemic risks affecting source code, artifacts, and workloads.
  • Establish standardised secure architecture patterns for build systems, CI/CD pipelines, runtime environments, and developer tooling.
  • Define and enforce platform security baselines using policy-as-code and automated controls.
  • Remediate gaps with platform owners and implement scalable solutions for artifact integrity and access control.
  • Integrate vulnerability management, SBOM, provenance, and code-signing within engineering workflows.
  • Prioritise gaps based on business risk and regulatory impact; build actionable security roadmaps.
  • Engage with platform owners and leadership; report maturity progress and risk posture.
  • Evolve the maturity framework in response to threats and regulatory expectations.
  • Drive a culture of secure-by-design engineering across federated teams.

Skills

Cybersecurity
DevSecOps
Threat modelling
Vulnerability mgmt
Security architecture
Stakeholder management
Regulatory engagement
Cloud security

Tools

Kubernetes
CI/CD tooling
SBOM tooling

Job description

We are part of the ALTEN Group – a leading European provider of engineering and technology consulting servics.

Join ALTEN Polska and let’s grow together !

Key Skills and Qualifications:
Framework and Assessment
  • Develop and maintain an Engineering-Platform Cybersecurity Maturity Framework to standardise assessments across platforms.
  • nConduct comprehensive platform security reviews (build systems, CI/CD pipelines, runtime infrastructure, developer tooling) against defined framework criteria.
  • Perform threat modelling and gap analysis, identifying vulnerabilities and systemic risks impacting source code, artifacts, and workloads.
Engineering Platform Security Enablement
  • Establish standardised secure architecture and engineering patterns for build systems, CI/CD pipelines, runtime environments, and developer tooling.
  • Define and enforce platform security baselines using policy-as-code and automated controls.
  • Partner with platform owners to remediate critical gaps and implement scalable solutions for artifact integrity, access control, and configuration security.
  • Integrate vulnerability management, SBOM, provenance, and code-signing practices within engineering workflows.
Roadmap Development & Execution
  • Prioritise identified gaps based on business risk, regulatory impact, and operational criticality.
  • Collaborate with platform owners and engineering leads to build actionable security roadmaps, balancing quick wins with long-term strategic improvements.
  • Partner with engineering teams to design, develop, and embed security patterns and best practices into engineering platforms.
Stakeholder Engagement & Governance
  • Serve as a trusted advisor to platform owners, senior technology stakeholders, and Cybersecurity leadership, translating technical risks into business impact.
  • Represent the function in key governance forums, providing updates on maturity progress, roadmap delivery, and risk posture.
  • Influence and align stakeholders across federated engineering teams to ensure consistent adoption of cybersecurity best practices.
  • Track and report maturity scores, ensuring measurable improvement across platforms.
  • Continuously evolve the maturity framework in response to emerging threats, technology evolution, and regulatory expectations.
  • Drive a culture of secure-by-design engineering th
Reuired experience & skills (must-have)
What you will bring to the role:

To be successful in this role you should have proven experience within the Technology sector with knowledge of the following skills:

  • Proven expertise in Cybersecurity within large-scale, regulated financial institutions or similarly complex environments.
  • Deep technical knowledge of engineering platforms, including CI/CD systems, build tools, artifact repositories, runtime environments, and developer tooling.
  • Strong experience with DevSecOps practices, including secure pipeline design, integration of security scanning tools, and automation of security controls.
  • Strong knowledge and understanding of service mesh, cryptography, network security, application security, vulnerability management, and risk management.
  • Demonstrable ability to conduct threat modelling, platform security assessments, and gap analysis.
  • Experience building and implementing maturity models, frameworks, or roadmaps in complex enterprise environments.
  • Strong stakeholder management skills, with the ability to influence senior leadership and drive change across federated technology teams.
  • Excellent communication skills, with the ability to translate technical risk into business impact.
Good to have:
  • Professional certifications such as CISSP, CISM, CCSK, CCSP, or equivalent.
  • Hands-on knowledge of cloud security (AWS, Azure, GCP) and container orchestration platforms (e.g., Kubernetes).
  • Experience in international and diverse environments, with exposure to regulatory engagement.
  • Familiarity with engineering excellence practices such as SLSA, supply chain security, SBOM, or secure developer tooling initiatives.
We offer
  • A full-time contract (B2B also possible)
  • All necessary work equipment is provided by us (computer, monitor etc).
  • Participation in company many conferences, trainings, workshops, integration meetings, etc.
  • Certification and training opportunities
  • Opportunity to relocate and work in different ALTEN Polska branches
  • After completion of the project, opportunity to engage in a subsequent one within the company.
  • Work in company with #GreatPlaceToWork Certificate\
  • Access to professional certifications with our technology partners (e.g. Google, ISTQB)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

ALTEN Polska • Kraków

On-site
PLN 120,000 - 180,000
Work equipment provided
Conference & training opportunities
Opportunities to relocate within ALTEN
+1
Software Engineer
Software Engineer

ALTEN Polska • Kraków

On-site
PLN 120,000 - 180,000
Work equipment provided
Conferences and trainings
Certification opportunities
+2
Senior Cloud Specialist
Senior Cloud Specialist

ALTEN Polska • Kraków

On-site
PLN 180,000 - 300,000
Full-time contract
Work equipment provided
Conferences and trainings
+5
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Talan Group • Warszawa

Hybrid
PLN 210,000 - 316,000
Private medical insurance
Life insurance
Training and career development
+1
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Wrocław

On-site
PLN 180,000 - 240,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Talan Group • Warszawa

Hybrid
PLN 252,000 - 337,000
Private medical insurance
Life insurance
Smart Office Pack
+1
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Warszawa

On-site
PLN 120,000 - 180,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Opole

On-site
PLN 160,000 - 260,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Łódź

On-site
PLN 90,000 - 130,000
Cybersecurity Consultant
Cybersecurity Consultant

Atos • Poland

On-site
PLN 150,000 - 200,000