Senior Devsecops Engineer

Luza Group

Lisboa

Híbrido

EUR 60 000 - 90 000

Tempo integral

há 44 horas
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Remote work flexibility
Equipment provided
Benefits plan

Resumo da oferta

Syffer is seeking a skilled DevSecOps Engineer to define and implement secure architectures and CI/CD security controls across complex delivery pipelines. You will integrate security tools (GitHub Advanced Security, SonarQube, JFrog) and ensure governance, traceability, and secure release management.

You'll collaborate with development teams, promote secure practices, and operate in a hybrid work model. Fluency in Portuguese and English is required, and experience in regulated enterprise

Qualificações

  • Proven experience in DevSecOps, application security, or DevOps engineering.
  • Experience with CI/CD pipelines and secure delivery practices.
  • Knowledge of Git workflows, release management, and deployment governance.

Responsabilidades

  • Define and implement secure DevSecOps architectures and CI/CD security controls (SAST, SCA, secrets, containers, SBOM, quality gates).
  • Integrate and manage security tools (GitHub Advanced Security, SonarQube, JFrog) within development workflows.
  • Establish secure artifact management and controlled promotion across environments.
  • Manage vulnerabilities end-to-end: analysis, prioritization, remediation support, and reporting.
  • Configure GitHub security features and enforce repository and PR governance standards.
  • Maintain code quality and security policies using SonarQube.
  • Secure artifact repositories and dependencies using JFrog Artifactory and Xray.
  • Define branching strategies and enforce secure release and deployment controls.
  • Ensure traceability, auditability, and proper governance across the delivery lifecycle.
  • Support and enable development teams through guidance, training, and practical secure implementations.
  • Hybrid work model.

Conhecimentos

DevSecOps
Application security
DevOps engineering
Vulnerability management
Regulated environments

Ferramentas

GitHub Advanced Security
SonarQube
JFrog Artifactory
Xray
GitHub Actions
Azure DevOps
Jenkins
GitLab CI

Descrição da oferta de emprego

Syffer is an all-inclusive consulting company focused on talent, tech and innovation. We exist to elevate companies and humans all around the world, making change, from the inside to the outside.

We believe that technology + human kindness positively impacts every community around the world. Our approach is simple, we see a world without borders, and believe in equal opportunities. We are guided by our core principles of spreading positivity, good energy and promote equality and care for others.

Our hiring process is unique! People are selected by their value, education, talent and personality. We dont present ethnicity, religion, national origin, age, gender, sexual orientation or identity.

Its time to burst the bubble, and we will do it together!

What You'll do:
  • Define and implement secure DevSecOps architectures and CI/CD security controls (SAST, SCA, secrets, containers, SBOM, quality gates);
  • Integrate and manage security tools (GitHub Advanced Security, SonarQube, JFrog) within development workflows;
  • Establish secure artifact management and controlled promotion across environments;
  • Manage vulnerabilities end-to-end: analysis, prioritization, remediation support, and reporting;
  • Configure GitHub security features and enforce repository and PR governance standards;
  • Maintain code quality and security policies using SonarQube;
  • Secure artifact repositories and dependencies using JFrog Artifactory and Xray;
  • Define branching strategies and enforce secure release and deployment controls;
  • Ensure traceability, auditability, and proper governance across the delivery lifecycle;
  • Support and enable development teams through guidance, training, and practical secure implementations;
  • Hybrid work model;
Who You Are:
  • Proven experience in DevSecOps, application security, or DevOps engineering;
  • Strong hands-on experience with CI/CD pipelines and secure delivery practices;
  • Experience with: GitHub Enterprise & GitHub Advanced Security, SonarQube configuration and governance, JFrog Artifactory and Xray;
  • Strong understanding of vulnerability management and secure artifact lifecycle;
  • Experience working directly with development teams in remediation efforts;
  • Knowledge of Git workflows, release management, and deployment governance;
  • Experience in regulated or large enterprise environments;
  • Fluent in Portuguese and English;
Technical Skills
  • Security & DevSecOps Tools: GitHub Advanced Security, SonarQube, JFrog Artifactory & Xray;
  • CI/CD & Engineering: GitHub Actions, Azure DevOps, Jenkins, GitLab CI, pipeline-as-code, automated security gates;
  • Application Security: SAST, SCA, secrets management, OWASP Top 10, vulnerability triage and remediation;
  • Cloud & Containers: Docker/OCI, Kubernetes/OpenShift, container registry and image governance;
  • Engineering Practices: GitFlow, branching strategies, pull request governance, artifact immutability and traceability;
What you'll get:
  • Wage according to candidate's professional experience;
  • Remote Work whenever possible;
  • Delivery of work equipment adjusted to the performance of functions;
  • Benefits plan;
  • And others.

Work together with expert teams on projects of large magnitude and intensity, long term together with our clients, all leaders in their industries.

Are you ready to step into a diverse and inclusive world with us?

Together we will promote uniquess!

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Senior DevSecOps Engineer
Senior DevSecOps Engineer

LUZA Group • Oeiras

Presencial
EUR 60 000 - 90 000
Remote work whenever possible
Work equipment provided
Benefits plan
Remote Senior DevSecOps Engineer — Secure CI/CD Expert
Remote Senior DevSecOps Engineer — Secure CI/CD Expert

LUZA Group • Oeiras

Híbrido
EUR 60 000 - 90 000
Remote work whenever possible
Work equipment provided
Benefits plan
Remote Senior DevSecOps Engineer
Remote Senior DevSecOps Engineer

Luza Group • Lisboa

Híbrido
EUR 60 000 - 90 000
Remote work flexibility
Equipment provided
Benefits plan
Application Security Engineer
Application Security Engineer

LUZA Group • Porto

Híbrido
EUR 50 000 - 70 000
Remote work when possible
Equipment provided
Benefits plan
Senior IT Cloud Infrastructure Administrator
Senior IT Cloud Infrastructure Administrator

LUZA Group • Lisboa

Presencial
EUR 60 000 - 85 000
Remote work when possible
Equipment provided
Benefits plan
+2
DevSecOps (Lisbon / Porto - Hybrid)
DevSecOps (Lisbon / Porto - Hybrid)

Claranet limited • Lisboa, Porto

Híbrido
EUR 60 000 - 80 000
Integration into a dynamic and motivated team
Additional training
Salary package according to the role performed
Application Security & DevSecOps Engineer
Application Security & DevSecOps Engineer

Fyld • Lisboa

Presencial
EUR 50 000 - 75 000
Senior DevSecOps & Product Security Engineer
Senior DevSecOps & Product Security Engineer

Doxis • Porto

Híbrido
EUR 70 000 - 110 000
Private healthcare
Udemy memberships
Udemy Business access
+1
Application Security Engineer
Application Security Engineer

Hexa Consulting • Portugal

Híbrido
EUR 18 000 - 22 000
Private health insurance
Mental health support
Learning & certification support
+2
Solution Architect Senior
Solution Architect Senior

Decskill • Lisboa

Presencial
EUR 70 000 - 95 000