DevSecOps Engineer

Huxley — Netherlands · Posted ~2 hours ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

We are looking for a hands-on DevSecOps Engineer to join a central DevSecOps team within a highly innovative software engineering environment. This is an excellent opportunity for a DevOps professional with a strong automation mindset and a genuine interest in security to further develop their DevSecOps expertise. You will work alongside experienced security engineers to scale security practices across the software development lifecycle, improve vulnerability management processes, and help development teams build secure, high-quality software at scale. Responsibilities Own and maintain security scanning pipelines within CI/CD environments using Bamboo, Bitbucket, and Azure DevOps.Drive shift-left security initiatives and implement near real-time vulnerability reporting for engineering teams.Manage and govern Kubernetes golden base images, ensuring security hardening, compliance, and automated adoption across microservices.Act as administrator and business owner of Application Security Posture Management (ASPM) tooling.Contribute to an internally developed lifecycle and vulnerability management platform built with Python, Docker, Kubernetes, and Helm.Integrate and maintain SAST, DAST, and SCA tooling within CI/CD pipelines.Configure and manage JFrog Xray and Artifactory security scanning policies and integrations.Support container and Kubernetes security best practices.Collaborate with Development, Operations, and Security teams to improve secure engineering practices and security awareness. Required Skills & Experience 2+ years of experience in DevOps, DevSecOps, Platform Engineering, or similar roles.Strong experience with CI/CD pipelines.Experience with Bamboo, Bitbucket and/or Azure DevOps.Python development experience.Working knowledge of Java and Maven build environments. Hands-on Docker, Kubernetes, and Helm experience.Knowledge of security tooling such as SonarQube, Checkmarx, OWASP ZAP, BlackDuck or Trivy.Experience with JFrog Xray and Artifactory.Bash scripting and Git experience.Interest in AI-assisted development tools, including GitHub Copilot and AI agents. Nice to Have Knowledge of security frameworks such as CIS, MITRE, NIST, ISO27001, or EU CRA.ASPM tooling experience.HashiCorp Vault or GitGuardian experience.Terraform and/or Ansible.Splunk or ELK.Security certifications such as CISSP or Security+. Key Competencies Strong stakeholder management and communication skills.Passion for automation and security.Continuous learning mindset.Pragmatic problem-solving approach.Team-oriented and delivery-focused attitude. Let op: vacaturefraude Helaas komt vacaturefraude steeds vaker voor. We waarschuwen je voor mogelijke misleiding: * Wij zullen nooit via WhatsApp of in een videogesprek vragen om jouw persoonlijke gegevens (zoals een kopie van je ID, bankgegevens of BSN). * Twijfel je over de echtheid van een vacature of contactpersoon? Neem dan altijd rechtstreeks contact met ons op via de officiële contactgegevens op onze website. Important: job fraud Unfortunately, job fraud is becoming more common. Beware of such scams: * We will never ask for personal information (such as a copy of your ID, bank details, or social security number) via WhatsApp or during a video call. * If you're unsure whether a vacancy or contact person is legitimate, please reach out to us directly using the official contact details on our website.