DevSecOps
Extia β Romania Β· Posted ~1 day ago
π Log in to save this job, tailor your resume & track your apply process β 7 days free, no card needed.
Log in to add to target listDescription
π£ Would you like to join a company that puts people at the heart of its concerns? We are waiting for you! Since 2007, Extia, an IT consulting company, has been offering a unique approach in its field by combining well-being at work and performance.
Our philosophy at Extia is βFirst who, then what", so let's go for it!
πFirst who?
Pragmatic, autonomous, and delivery-focused, you are able to unblock implementation issues independently.Hands-on and technically rigorous, with a strong ability to influence and coordinate security initiatives across engineering teams.Comfortable working in a multi-team, multi-platform environment with strong written communication skills.
Our current roles are hybrid, requiring 2 days per week in the office (Bucharest).
πThen what?
DevSecOps focusing on strengthening pipeline security and build infrastructure, with the following tasks:
Assess and harden CI/CD pipelines across Strategic Platforms against recognized supply-chain security standards (SLSA, OWASP CI/CD Top 10, CIS benchmarks).Implement key security controls on priority pipelines, supporting the rollout of signed commits, protected branches, runner hardening, and SLSA Level 2 build provenance.Deploy a centralized secrets management solution, removing hardcoded credentials and defining secrets access models and rotation policies.Define the roadmap for reaching SLSA Level 3, including container image signing strategy (toolchain, key management, Kubernetes admission control).Produce baseline audits, document actions, and provide clear handover material and closure reports for platform teams.Work closely with platform security leads, DevOps teams, and the Group Information Security function.
Required technical skills:
Min.
5 years of experience in DevSecOps, platform security, or CI/CD infrastructure security.Proven hands-on experience auditing and hardening CI/CD pipelines.Practical experience deploying and operating secrets management solutions in production environments.Solid understanding of software supply chain security frameworks, especially SLSA and OWASP CI/CD Top 10.Experience implementing container image signing in Kubernetes environments.
Nice to have: Knowledge of GitHub Advanced Security / GitLab Ultimate, artefact integrity verification tooling, CIS Software Supply Chain Security guidance, and relevant certifications in cloud, Kubernetes, or DevSecOps security.
π Do you recognize yourself in the "Who" and represent the "What"? Apply and let's talk!
We have 68,970 jobs that might be an even better fit for you
DontApply's real value goes far beyond a single job link or company name. Just upload your resume β in under a minute we'll analyze all 68,970 jobs and tell you exactly which ones you should apply to right now.
Upload My Resume