
Security & DevSecOps Engineer – Cyber Resilience Act (CRA) Compliance
SQUARE ONE RESOURCES sp. z o.o.
160 - 200 PLN / HOUR
B2B
Status
Hexjobs Insights
Zatrudnimy inżyniera do projektowania, wdrażania i utrzymania procesów bezpieczeństwa w zgodności z przepisami CRA w Warszawie. Praca w modelu B2B.
Schlüsselwörter
C/C++
DevOps
DevSecOps
CI/CD
SAST
SCA
SBOM
Veracode
CodeSonar
vulnerability management
Technologies we use
About the project
Your responsibilities
- Design, implement, and maintain scalable security workflows across multiple products and repositories.
- Translate legal and regulatory requirements (CRA) into actionable technical solutions.
- Implement and scale DevSecOps practices, including SAST, SCA, and SBOM generation.
- Integrate security tools (e.g., Veracode, CodeSonar) into CI/CD pipelines.
- Build and maintain centralized vulnerability management systems, including vulnerability databases and waiver management.
- Ensure full traceability for audits and consistent risk management practices.
- Collaborate across multiple teams to ensure end-to-end ownership of security solutions.
- Work in complex, heterogeneous, and legacy environments with limited automation.
- Optionally contribute to AI-assisted vulnerability remediation workflows and semi-automated
Our requirements
- Experienced engineer with strong technical security expertise and DevOps / DevSecOps skills.
- Proven experience working with security or product compliance regulations.
- Ability to translate legal requirements into technical implementations.
- Programming: C/C++
- DevOps / CI/CD pipelines (GitHub, GitLab, GitHub Actions, AWS)
- Security practices: application and product security, code analysis
- Tools: SAST, SCA, SBOM generation, Veracode, CodeSonar, CI/CD automation
- Build environments: CMake, Make, vendor-specific solutions, integration of security tools into custom pipelines
- Previous role in DevSecOps or similar security-focused engineering position.
- Experience with embedded systems and long-lifecycle products.
- Ability to operate at scale: multiple teams, repositories, and products.
- Strong ownership mentality with end-to-end solution delivery.
Optional
- High level of independence and decision-making authority.
- Pragmatic approach balancing regulatory compliance, engineering efficiency, and scalability.
- Ability to operate in heterogeneous, legacy environments with minimal standardization.
This is how we organize our work
This is how we work
This is how we work on a project
Aufrufe: 3
| Veröffentlicht | vor 7 Tagen |
| Läuft ab | in 23 Tagen |
| Art des Vertrags | B2B |
Ähnliche Jobs, die für Sie von Interesse sein könnten
Basierend auf "Security & DevSecOps Engineer – Cyber Resilience Act (CRA) Compliance"
Keine Angebote gefunden, versuchen Sie, Ihre Suchkriterien zu ändern.