.
DevSecOps Engineer @ Mindbox Sp.z.o.o.
  • Kraków
DevSecOps Engineer @ Mindbox Sp.z.o.o.
Kraków, Kraków, Lesser Poland Voivodeship, Polska
Mindbox Sp.z.o.o.
28. 11. 2025
Informacje o stanowisku

Creating an inspiring place to thrive for the talented, we use their expertise and courage to introduce the technology of the future into your business. - This is the foundation of Mindbox and the goal of our business and technology journey. We operate and develop in four areas:

? Autonomous Enterprise - automation of business processes using RPA, OCR, and AI.

?Business Managment Systems ERP - we implement, adapt, optimize, and maintain flexible, safe, and open ERP of production and distribution companies worldwide.

?Talent Network - we provide access to the best specialists.

 Modern Architecture - we build integrated, sustainable, and open CI / CD environments based on containers enabling safe and more frequent delivery of proven changes in the application code.

We treat technology as a tool to achieve a goal. Thanks to our consultants reliability and proactive approach, initial projects usually become long-term cooperation. For over 16 years, it has provided various services to support clients in digital transformation.

We offer:

  • We are open to the employment form according to your preferences
  • Work with experienced and engaged team, willing to learn, share knowledge and open for growth and new ideas
  • Hybrid or remote working system
  • Mindbox is a dynamically growing IT company, but still not a large one – everybody can have a real impact on where we are going next
  • We invest in developing skills and abilities of our employees
  • We have attractive benefits and provide all the tools required for work f.e.computer
  • Interpolska Health Care, Multisport, Warta Insurance, training platform (Sages)

Project Overview:

Own and evolve our Jenkins Shared Library powering multi-language builds (Java/Maven, Node/NPM, Python, Helm, Terraform, containers). Deliver fast, secure, provenance-rich pipelines (SLSA, SBOM, digests) and strengthen supply‑chain integrity across teams.


Essential Skills: 

  • 7+ years engineering; 3+ in CI/CD platform or DevSecOps.
  • Strong Jenkins + Groovy shared library expertise.
  • Advanced Python automation (JSON/YAML processing, tooling scripts).
  • Deep Maven/NPM/Python packaging knowledge; exposure to Helm/Terraform and container image metadata.
  • Supply-chain security (SLSA, CycloneDX SBOM, digests).
  • Experience with SonarQube, Sonatype IQ, container and SAST scanning.
  • Proven performance tuning (caching, parallelization, dependency pruning).
  • Compliance Awareness.

Nice-to-Have

  • Artifact signing / attestations (cosign, OCI).
  • Terraform module and Helm chart publishing patterns.
  • GitOps or release automation experience.
  • GCP/AWS cloud experience

Soft Skills: 

  • Precise communicator
  • documentation discipline. 
  • Ownership mindset, able to operate with minimal supervision.

Creating an inspiring place to thrive for the talented, we use their expertise and courage to introduce the technology of the future into your business. - This is the foundation of Mindbox and the goal of our business and technology journey. We operate and develop in four areas:

? Autonomous Enterprise - automation of business processes using RPA, OCR, and AI.

?Business Managment Systems ERP - we implement, adapt, optimize, and maintain flexible, safe, and open ERP of production and distribution companies worldwide.

?Talent Network - we provide access to the best specialists.

 Modern Architecture - we build integrated, sustainable, and open CI / CD environments based on containers enabling safe and more frequent delivery of proven changes in the application code.

We treat technology as a tool to achieve a goal. Thanks to our consultants reliability and proactive approach, initial projects usually become long-term cooperation. For over 16 years, it has provided various services to support clients in digital transformation.

We offer:

  • We are open to the employment form according to your preferences
  • Work with experienced and engaged team, willing to learn, share knowledge and open for growth and new ideas
  • Hybrid or remote working system
  • Mindbox is a dynamically growing IT company, but still not a large one – everybody can have a real impact on where we are going next
  • We invest in developing skills and abilities of our employees
  • We have attractive benefits and provide all the tools required for work f.e.computer
  • Interpolska Health Care, Multisport, Warta Insurance, training platform (Sages)

Project Overview:

Own and evolve our Jenkins Shared Library powering multi-language builds (Java/Maven, Node/NPM, Python, Helm, Terraform, containers). Deliver fast, secure, provenance-rich pipelines (SLSA, SBOM, digests) and strengthen supply‑chain integrity across teams.

,[• Design and maintain Groovy pipeline steps (build, test, package, scan, deploy)., • Extend Python tooling for SLSA provenance, SBOM generation, hash/digest accuracy, and security scan aggregation (SonarQube, Sonatype IQ, SAST/Container)., • Optimize performance (parallel builds, caching, scope-reduced BOMs, dependency prefetch)., • Ensure artifact integrity (correct SHA1/SHA256 mapping, reproducible inputs, evidence modeling)., • Refactor legacy scripts (remove global state, consolidate hashing, standardize templates)., • Document ci-config.yaml standards and usage patterns., • Mentor engineers on secure pipeline development and supply-chain practices., • Troubleshoot and prevent pipeline incidents. Requirements: Groovy, JSON, YAML, Maven, npm, Helm, Terraform, Security, SonarQube, SAST, Performance tuning, Python, Jenkins, GitOps, GCP, AWS Cloud Additionally: Sport subscription, Private healthcare, International projects.

  • Praca Kraków
  • Kraków - Oferty pracy w okolicznych lokalizacjach


    110 848
    15 050