Java DevSecOps Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+25 more
Job description
You will work closely with our Senior DevSecOps Engineer and grow your practical security knowledge on the job - deep security expertise upfront is not a prerequisite. What matters most is a strong drive and ability to learn, a DevOps engineering background with software engineering skills, a genuine curiosity about security, and the ability to build and maintain automated tooling. Role and responsibilities
- Own and maintain security scanning pipelines for product releases using Atlassian Bamboo with Bitbucket and Azure DevOps.
- Develop and maintain shift-left security scanning with near real-time vulnerability reporting delivered directly to product teams.
- Own, maintain, and enforce the use of golden base images in Kubernetes tenants - ensuring they are always up to date, security-hardened, and automatically propagated to consumer microservices.
- Serve as the administrator and business owner of our Application Security Posture Management (ASPM) tooling.
- Actively contribute to and maintain our internally developed lifecycle and vulnerability management portal (Python, Docker, Kubernetes, Helm).
- Integrate and operate SAST, DAST, and SCA tools (e.g., SonarQube, Checkmarx, OWASP ZAP, BlackDuck, Trivy) in CI/CD pipelines.
- Configure and maintain JFrog Xray as the artifact security scanner - including security scan triggers, scanning policies, and integration with JFrog Artifactory.
- Ensure best practices in containerized environments (Docker, Kubernetes) including deployment and runtime security configurations.
- Collaborate with development, operations, and security teams to embed security awareness and share guidance on secure engineering practices.
- Investigate, remediate, and verify 3rd-party dependency vulnerabilities across the product codebase - including updating Maven dependencies, validating fixes with JUnit tests, and triggering qualification pipelines in Bamboo to confirm nothing is broken.
Requirements
We are looking for a hands-on DevSecOps Engineer with Software Development skills to join our central DevSecOps team and help scale security across our software development lifecycle. In this role you will own and evolve shift-left security practices, maintain security scanning pipelines, govern Kubernetes golden images, help product teams stay on top of vulnerabilities through near real-time reporting and remediate 3rd-party dependency vulnerabilities., * A Bachelor or Master degree in a technical field, or equivalent professional experience.
- 4+ years of experience in DevOps, DevSecOps, or a closely related engineering role.
- Hands-on experience with CI/CD pipelines - Atlassian Bamboo, Bitbucket, and/or Azure DevOps experience is a strong advantage.
- Python development skills; ability to maintain and extend existing tooling.
- Working knowledge of Java and Maven - the product codebase is predominantly Java/Maven based. You should be able to update dependencies, resolve version conflicts, and run JUnit test suites to verify security fixes.
- Familiarity with triggering and interpreting Bamboo qualification pipelines as part of the change verification process.
- Experience with containerized environments: Docker, Kubernetes, Helm.
- Comfort working with shell scripting (bash) and version control (git).
- Hands-on experience or strong interest in AI-assisted development tools - including GitHub Copilot, AI agents, and agentic development workflows.
Nice to have
- Knowledge of security standards and frameworks (e.g., CIS, MITRE, NIST, ISO 27001, EU CRA).
- Experience with ASPM platforms or security posture tooling.
- Familiarity with secrets management tools (e.g., HashiCorp Vault, GitGuardian).
- Infrastructure-as-code experience (e.g., Terraform, Ansible).
-
Experience with SIEM tools (e.g., Splunk, ELK) for security monitoring.
- CISSP, Security+, or equivalent certification is a plus but not required.
- Familiarity with SAST, DAST, and SCA tooling (e.g., SonarQube, Checkmarx, OWASP ZAP, Trivy).
- Familiarity with JFrog Xray and Artifactory for artifact security scanning and policy management.
Skills
- Strong collaboration and communication skills - able to work effectively with both technical and non-technical stakeholders.
- Genuine enthusiasm for combining security with DevOps practices.
- Open to learning: willing to grow practical security knowledge guided by the team.
- Curiosity-driven mindset - you keep up with tooling trends, including AI-driven development practices.
-
Good problem solver - able to translate operational security challenges into clear, maintainable automated solutions.
- Team player with a pragmatic delivery focus
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Fully Remote Software Engineer Jobs
How to land a developer job in Amsterdam
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents