.
DevSecOps Engineer
  • Kraków
DevSecOps Engineer
Kraków, Kraków, Lesser Poland Voivodeship, Polska
Mindbox Sp. z o.o.
30. 11. 2025
Informacje o stanowisku

technologies-expected :


  • Jenkins
  • Groovy
  • Python
  • Maven
  • NPM
  • Helm
  • Terraform
  • SonarQube
  • Sonatype IQ

technologies-optional :


  • Google Cloud Platform
  • AWS

about-project :


  • We are looking for a DevSecOps Engineer to own and evolve our Jenkins Shared Library, powering multi-language builds (Java/Maven, Node/NPM, Python, Helm, Terraform, containers). You will deliver fast, secure, provenance-rich pipelines (SLSA, SBOM, digests) and strengthen supply-chain integrity across teams.
  • Sounds like your kind of challenge?

responsibilities :


  • Design and maintain Groovy pipeline steps (build, test, package, scan, deploy)
  • Extend Python tooling for SLSA provenance, SBOM generation, hash/digest accuracy, and security scan aggregation (SonarQube, Sonatype IQ, SAST/Container)
  • Optimize performance (parallel builds, caching, scope-reduced BOMs, dependency prefetch)
  • Ensure artifact integrity (correct SHA1/SHA256 mapping, reproducible inputs, evidence modeling)
  • Refactor legacy scripts (remove global state, consolidate hashing, standardize templates)
  • Document ci-config.yaml standards and usage patterns
  • Mentor engineers on secure pipeline development and supply-chain practices
  • Troubleshoot and prevent pipeline incidents
  • Note: Detailed project information will be shared during the recruitment process.

requirements-expected :


  • 7+ years of engineering experience; 3+ years in CI/CD platform or DevSecOps
  • Strong Jenkins + Groovy shared library expertise
  • Advanced Python automation (JSON/YAML processing, tooling scripts)
  • Deep knowledge of Maven/NPM/Python packaging; exposure to Helm/Terraform and container image metadata
  • Supply-chain security (SLSA, CycloneDX SBOM, digests)
  • Experience with SonarQube, Sonatype IQ, container and SAST scanning
  • Proven performance tuning (caching, parallelization, dependency pruning)
  • Compliance awareness

offered :


  • Flexible cooperation model – choose the form that suits you best (B2B, employment contract, etc.)
  • Hybrid work setup – remote days available depending on the client’s arrangements
  • Collaborative team culture – work alongside experienced professionals eager to share knowledge
  • Continuous development – access to training platforms and growth opportunities
  • Comprehensive benefits – including Interpolska Health Care, Multisport card, Warta Insurance, and more
  • High quality equipment – laptop and essential software provided

benefits :


  • sharing the costs of sports activities
  • private medical care
  • sharing the costs of professional training & courses
  • life insurance

  • Praca Kraków
  • Kraków - Oferty pracy w okolicznych lokalizacjach


    116 160
    17 541