This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
This role involves embedding security into software delivery pipelines, designing and implementing security controls, and ensuring code integrity across systems. You'll engage in secure code reviews, vulnerability management, and mentoring team members while collaborating as a trusted partner across departments.
Job Responsibility:
secure SDLC & DevSecOps integration
design and implement security controls for build and release pipelines (GitHub Actions, Jenkins, GitLab, Azure DevOps)
ensure code integrity via signing, artifact scanning, and build provenance
automate SAST, DAST, SCA, and container image scanning as part of the software delivery pipeline
identify and remediate misconfigurations in pipeline environments and access control
design, implement, and monitor WAF rules and API protections
perform API risk assessments
champion secure design patterns
conduct secure code reviews and support automation of testing pipelines
triage, prioritize, and track security issues identified in code, pipelines, and deployed environments
facilitate threat modeling sessions for applications, APIs, and pipeline workflows
expand security automation coverage, including API discovery, dependency scanning, SBOM generation, and secrets detection
mentor developers and DevOps engineers on secure pipeline and coding practices
act as a trusted partner to product, platform engineering, and DevOps leaders
translate security risk into business impact
collaborate with SOC/IR teams in response to software supply chain or pipeline compromises
Requirements:
5–8+ years of experience in Application Security, Product Security, or Secure Software Development