np. Python, Warszawa, Startup

DevSecOps Architect / Technical Lead

location-pointer-icon Warszawa
29000 - 34000 PLN
Brutto / Miesiąc / Umowa o pracę
Security

Andersen is hiring a DevSecOps Architect / Technical Lead for a project modernizing digital banking architecture and enhancing security, scalability, and platform reliability. 

The customer is a financial services organization providing banking products and digital solutions for individual and business clients. The company operates through an established service network and online platforms and is part of a larger international financial group, supporting ongoing development of its services for a broad client base. 

The project is focused on defining a structured architecture roadmap for a large-scale digital banking transformation program. It includes target-state architecture, platform modernization, API governance, security, data and analytics, system decoupling, and phased migration of business capabilities to reduce system dependencies and accelerate future digital development. 

Responsibilities: 

- Translating the DevSecOps master plan into a practical implementation roadmap. 

- Defining reusable CI/CD, security and release-management standards. 

- Supporting the transition from Bitbucket/Jenkins to Azure Repos and Azure Pipelines. 

- Implementing security scanning and release gates in CI/CD pipelines. 

- Configuring security controls for AKS, container images, identities and secrets. 

- Establishing artifact signing, SBOM generation and secure promotion processes. 

- Integrating platform security events with the bank’s monitoring and SIEM solutions. 

- Defining vulnerability-management, audit-evidence and incident-response processes. 

- Providing technical leadership, recommendations and knowledge transfer to delivery teams. 

- Participating directly in configuration, integration and troubleshooting activities. 

Requirements: 

- Experience in DevSecOps, cloud security or platform security for 5+ years.  

- Proven experience designing and driving DevSecOps processes, architecture, or engineering standards across multiple teams, not only implementing predefined solutions within a single project. 

- Experience translating high-level security or DevSecOps strategy into a practical technical roadmap, architecture decisions, standards, and implementation guidance. 

- Experience owning technical decisions and driving the adoption of DevSecOps practices across engineering teams. 

- Strong hands-on experience with Microsoft Azure. 

- Hands-on experience implementing security controls and gates across CI/CD, including several of the following: SAST, SCA, DAST, secret scanning, IaC scanning, and container scanning. 

- Practical experience with Kubernetes and container security, preferably AKS. 

- Experience with Infrastructure as Code, preferably Terraform. 

- Experience with identity, secrets, and certificate management. 

- Understanding of software supply-chain security practices such as SBOM, artifact signing, provenance, and secure artifact promotion. 

- Ability to combine architecture and technical leadership with hands-on implementation and troubleshooting. 

- Experience mentoring or technically guiding engineers and working across development, platform, security, and architecture teams. 

- Level of English – from Upper-Intermediate and above. 

Nice-to-haves: 

- Experience in the banking domain. 

- Experience with Jenkins, Bitbucket and migration to Azure DevOps. 

- Experience with Azure Key Vault, Azure Container Registry and Defender for Containers. 

- Familiarity with tools such as SonarQube, Sonatype, Nexus, Gitleaks, Checkov or OWASP ZAP. 

- Understanding of SBOM, artifact signing and software supply-chain security. 

- Experience with DefectDojo, Microsoft Sentinel or other vulnerability-management and SIEM solutions. 

- Experience with Azure Policy, Gatekeeper, OPA or Kubernetes admission controls. 

- Experience in banking or another regulated industry. 

- Understanding of DORA, audit traceability and segregation-of-duties requirements. 

Reasons why this job would be interesting to you: 

- Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc.. 

- The opportunity to change the project and/or develop expertise in an interesting business domain. 

- Job conditions – you can work both fully remotely and from the office or can choose a hybrid variant. 

- Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee. 

- The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities. 

- Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated. 

- Bright corporate life (parties / pizza days / PlayStation / fruits / coffee / snacks / movies). 

- Certification compensation (AWS, PMP, etc). 

- Referral program. 

- Private health insurance and sports compensation, depending on the type of employment. 

Your personal data is protected in accordance with GDPR regulations. Learn more: https://andersenlab.com/privacy-policy/pl 

Join us! 

https://people.andersenlab.com/ 

AndersenLab
Outsource
500 - 1000
Branża
Fintech/Banking, Automotive, GameDev, E-commerce, Telecom
Założona
2007

Ta strona używa plików cookie, aby zapewnić Ci lepsze wrażenia podczas przeglądania.

Dowiedz się więcej o tym, jak używamy plików cookie i jak zmienić preferencje dotyczące plików cookie w naszej Polityka plików cookie.

Zmień ustawienia
Zapisz Akceptuj wszystkie cookies