Przejdź do treści
Aplikuj teraz

Ta oferta jest na kilku portalach

Mindbox Sp. z o.o.

DevSecOps Engineer

Mindbox Sp. z o.o. Zobacz wszystkie oferty
24000 - 29000 PLN
B2B
Praca hybrydowa
Senior
Kraków
Wygasa 17 paź 2026
4 dni temu

W skrócie

DevSecOps Engineer needed for Mindbox in Kraków. Responsibilities include Jenkins pipeline development, Python tooling, supply chain security, and mentoring. Requires 7+ years engineering, 3+ in DevSecOps/CI/CD. Hybrid work, B2B contract.

Skrót przygotowany przez AI na podstawie treści ogłoszenia.

Technologies we use

About the project

This is how we organize our work

This is how we work

Your responsibilities

  • Design, implement, and maintain Groovy-based Jenkins pipeline steps for build, test, packaging, scanning, and deployment.
  • Extend and refine Python tooling for SLSA provenance, SBOM generation, hash/digest verification, and security scan aggregation (SonarQube, Sonatype IQ, SAST, container scans).
  • Optimize pipeline performance through parallelization, caching, and smart dependency management.
  • Ensure artifact integrity, reproducible builds, and accurate cryptographic mappings (SHA1/SHA256).
  • Refactor legacy scripts for stability and compliance, apply standard templates, and eliminate global state issues.
  • Define and document ci-config.yaml standards and enforce usage patterns.
  • Mentor teams on DevSecOps best practices, supply chain security, and secure pipeline design.
  • Troubleshoot and proactively prevent pipeline incidents across environments.
  • Note: Detailed project information will be shared during the recruitment process.

Our requirements

  • Minimum 7+ years in engineering roles, with 3+ years in DevSecOps or CI/CD platform engineering.
  • Strong hands-on expertise with Jenkins Shared Libraries (Groovy).
  • Advanced Python programming for automation, YAML/JSON parsing, and tooling development.
  • Solid understanding of multi-language build pipelines: Java/Maven, Node/NPM, Python, with exposure to Helm, Terraform, and container image metadata handling.
  • Deep knowledge of supply chain security standards (e.g., SLSA, SBOM via CycloneDX, artifact digests).
  • Experience with static and container scanning tools: SonarQube, Sonatype IQ, SAST.
  • Proven ability in build optimization techniques, caching, and dependency pruning.
  • Compliance Awareness & Documentation Discipline.

What we offer

  • Flexible cooperation model – choose the form that suits you best (B2B, employment contract, etc.)
  • Hybrid work setup – 6 days a month from the office in Kraków
  • Collaborative team culture – work alongside experienced professionals eager to share knowledge
  • Continuous development – access to training platforms and growth opportunities
  • Comprehensive benefits – including Interpolska Health Care, Multisport card, Warta Insurance, and more
  • High quality equipment – laptop and essential software provided

This is how we work on a project

Benefits

Opublikowana 2026-09-17
Źródło