DevSecOps Security Consultant

Thrive It Systems Ltd — Poland · Posted ~8 hours ago

Senior Full-time

Skills

DevSecOps Cybersecurity CI/CD security Threat modeling Security architecture Policy as Code Vulnerability management SBOM Software provenance Code signing Risk assessment CI/CD

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

An enterprise technology organization is seeking a DevSecOps Security Consultant to strengthen the security of engineering platforms. You will assess CI/CD pipelines, build systems, repositories, runtime infrastructure, and developer tooling; perform threat modeling; establish secure architecture patterns; and automate security controls using Policy as Code. You will also integrate software supply-chain security practices and develop risk-based remediation roadmaps.

Highlights

Shape enterprise-wide cybersecurity maturity for engineering platforms and establish practical security standards and controls. The role offers broad exposure across CI/CD, infrastructure, developer tooling, software supply-chain security, risk management, and security architecture.

Description

Develop and maintain an Engineering Platform Cybersecurity Maturity Framework for consistent security assessment across platformsConduct security reviews of CICD pipelines, build systems, artifact repositories, runtime infrastructure, and developer toolingPerform threat modelling and security gap analysis to identify vulnerabilities and systemic risksEstablish secure architecture patterns and engineering standards for enterprise engineering platformsDefine and implement security baselines using Policy as Code and automated security controlsPartner with platform owners to remediate security gaps related to access controls, configuration security, and artifact integrityIntegrate vulnerability management, SBOM, software provenance, and code signing practices into engineering workflowsPrioritize security gaps according to business risk, regulatory impact, and operational criticalityDevelop actionable security roadmaps that balance immediate remediation with long-term improvementsEmbed Secure by Design and DevSecOps practices into engineering platformsAdvise platform owners, technology stakeholders, and security leadership on platform security risksTranslate technical security risks into clear business impacts and remediation recommendationsTrack maturity scores and report security posture, roadmap progress, risks, and improvement outcomesRepresent platform security initiatives in governance and risk forumsContinuously improve security frameworks in response to emerging threats, technologies, and regulatory expectationsPromote cybersecurity awareness, engineering excellence, and knowledge sharing across technology teams Qualifications: Proven Cybersecurity experience (7-11 years) within large-scale regulated or similarly complex enterprise environmentsDeep technical knowledge of engineering platforms including CICD systems, build tools, artifact repositories, runtime environments, and developer toolingStrong DevSecOps experience including secure pipeline design and automated security control implementationExperience integrating security scanning tools into software delivery pipelinesStrong knowledge of Service Mesh, Cryptography, Network Security, and Application SecurityStrong Vulnerability Management and Risk Management experienceExperience conducting Threat Modelling, Platform Security Assessments, and Gap AnalysisExperience developing Cybersecurity Maturity Models, Frameworks, and Security RoadmapsKnowledge of Policy as Code and automated security guardrailsUnderstanding of SBOM, Software Provenance, Code Signing, and Software Supply Chain SecurityStrong stakeholder management skills with the ability to influence senior leadershipAbility to drive security improvements across federated engineering and technology teamsExcellent communication skills with the ability to translate technical risks into business impactHands-on knowledge of AWS, Azure, GCP, and Kubernetes security is desirableProfessional certifications such as CISSP, CISM, CCSK, or CCSP are advantageousExperience with regulatory engagement and global technology environments is preferred Required Skills: Application Security (application security framework/ threat modelling/ Secure SDLC/ DevSecOps/Application Security Architecture Review)Python-Cybersecurity