Java DevSecOps Engineer

ASML
Veldhoven, Netherlands
10 days ago
Apply on www.careerjet.nl
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) Artificial Intelligence Microsoft Azure Burp Suite DevOps Information Security Management Junit Python (Programming Language) Key Management Apache Maven Ansible Shell Script
+25 more
Security Information and Event Management Software Engineering SonarQube Tripwire Software Vulnerability Management GitHub Copilot Software Security Git Containerization Kubernetes Synopsys Black Duck Hashicorp Bitbucket Checkmarx Terraform Splunk Software Version Control Devsecops Atlassian Bamboo Docker Static Application Security Testing Vulnerability Analysis Artifactory Microservices Dynamic Application Security Testing

Job description

You will work closely with our Senior DevSecOps Engineer and grow your practical security knowledge on the job - deep security expertise upfront is not a prerequisite. What matters most is a strong drive and ability to learn, a DevOps engineering background with software engineering skills, a genuine curiosity about security, and the ability to build and maintain automated tooling. Role and responsibilities

  • Own and maintain security scanning pipelines for product releases using Atlassian Bamboo with Bitbucket and Azure DevOps.
  • Develop and maintain shift-left security scanning with near real-time vulnerability reporting delivered directly to product teams.
  • Own, maintain, and enforce the use of golden base images in Kubernetes tenants - ensuring they are always up to date, security-hardened, and automatically propagated to consumer microservices.
  • Serve as the administrator and business owner of our Application Security Posture Management (ASPM) tooling.
  • Actively contribute to and maintain our internally developed lifecycle and vulnerability management portal (Python, Docker, Kubernetes, Helm).
  • Integrate and operate SAST, DAST, and SCA tools (e.g., SonarQube, Checkmarx, OWASP ZAP, BlackDuck, Trivy) in CI/CD pipelines.
  • Configure and maintain JFrog Xray as the artifact security scanner - including security scan triggers, scanning policies, and integration with JFrog Artifactory.
  • Ensure best practices in containerized environments (Docker, Kubernetes) including deployment and runtime security configurations.
  • Collaborate with development, operations, and security teams to embed security awareness and share guidance on secure engineering practices.
  • Investigate, remediate, and verify 3rd-party dependency vulnerabilities across the product codebase - including updating Maven dependencies, validating fixes with JUnit tests, and triggering qualification pipelines in Bamboo to confirm nothing is broken.

Requirements

We are looking for a hands-on DevSecOps Engineer with Software Development skills to join our central DevSecOps team and help scale security across our software development lifecycle. In this role you will own and evolve shift-left security practices, maintain security scanning pipelines, govern Kubernetes golden images, help product teams stay on top of vulnerabilities through near real-time reporting and remediate 3rd-party dependency vulnerabilities., * A Bachelor or Master degree in a technical field, or equivalent professional experience.

  • 4+ years of experience in DevOps, DevSecOps, or a closely related engineering role.
  • Hands-on experience with CI/CD pipelines - Atlassian Bamboo, Bitbucket, and/or Azure DevOps experience is a strong advantage.
  • Python development skills; ability to maintain and extend existing tooling.
  • Working knowledge of Java and Maven - the product codebase is predominantly Java/Maven based. You should be able to update dependencies, resolve version conflicts, and run JUnit test suites to verify security fixes.
  • Familiarity with triggering and interpreting Bamboo qualification pipelines as part of the change verification process.
  • Experience with containerized environments: Docker, Kubernetes, Helm.
  • Comfort working with shell scripting (bash) and version control (git).
  • Hands-on experience or strong interest in AI-assisted development tools - including GitHub Copilot, AI agents, and agentic development workflows.

Nice to have

  • Knowledge of security standards and frameworks (e.g., CIS, MITRE, NIST, ISO 27001, EU CRA).
  • Experience with ASPM platforms or security posture tooling.
  • Familiarity with secrets management tools (e.g., HashiCorp Vault, GitGuardian).
  • Infrastructure-as-code experience (e.g., Terraform, Ansible).
  • Experience with SIEM tools (e.g., Splunk, ELK) for security monitoring.

  • CISSP, Security+, or equivalent certification is a plus but not required.
  • Familiarity with SAST, DAST, and SCA tooling (e.g., SonarQube, Checkmarx, OWASP ZAP, Trivy).
  • Familiarity with JFrog Xray and Artifactory for artifact security scanning and policy management.

Skills

  • Strong collaboration and communication skills - able to work effectively with both technical and non-technical stakeholders.
  • Genuine enthusiasm for combining security with DevOps practices.
  • Open to learning: willing to grow practical security knowledge guided by the team.
  • Curiosity-driven mindset - you keep up with tooling trends, including AI-driven development practices.
  • Good problem solver - able to translate operational security challenges into clear, maintainable automated solutions.

  • Team player with a pragmatic delivery focus

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.nl
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:15 min

Refactoring test code dependencies with Maven and JUnit

Benjamin Bischoff Benjamin Bischoff · Europe 2026 Virtual

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all