Unlock Full Resume Report

New offer - be the first one to apply!

September 17, 2026

Senior DevSecOps Engineer

Senior • On-site

Lisbon, Portugal

Quick Facts

  • Role: Senior DevSecOps Engineer

Description

Embed security controls, architecture patterns, and operational security practices into the software delivery lifecycle. You will combine hands-on DevSecOps engineering with security architecture advisory, vulnerability management, and secure CI/CD enablement—working closely with development teams to ensure code, dependencies, container images, secrets, and deployment artifacts are continuously assessed before production.

Responsibilities

  • Define and implement secure DevSecOps architectures and CI/CD security controls (SAST, SCA, secrets, containers, SBOM, quality gates).
  • Integrate and manage security tools in development workflows (GitHub Advanced Security, SonarQube, JFrog).
  • Establish secure artifact management and controlled promotion across environments.
  • Manage vulnerabilities end-to-end: analysis, prioritization, remediation support, and reporting.
  • Configure GitHub security features and enforce repository and PR governance.
  • Maintain code quality and security policies using SonarQube.
  • Secure artifact repositories and dependencies using JFrog Artifactory and JFrog Xray.
  • Define branching strategies and enforce secure release and deployment controls.
  • Ensure traceability, auditability, and governance across the delivery lifecycle.
  • Support and enable development teams through guidance, training, and practical secure implementations.

Requirements

  • Proven experience in DevSecOps, application security, or DevOps engineering.
  • Strong hands-on experience with CI/CD pipelines and secure delivery practices.
  • Experience with GitHub Enterprise and GitHub Advanced Security.
  • Experience with SonarQube configuration and governance.
  • Experience with JFrog Artifactory and JFrog Xray.
  • Strong understanding of vulnerability management and secure artifact lifecycle.
  • Experience working directly with development teams in remediation efforts.
  • Knowledge of Git workflows, release management, and deployment governance.
  • Experience in regulated or large enterprise environments.

Nice to Have

  • GitHub Advanced Security certification.
  • JFrog Artifactory/Xray training.
  • SonarQube administration.
  • Secure SDLC or OWASP-based training.
  • Cloud security certifications (Azure, Kubernetes, OpenShift).
  • DevSecOps certifications.
  • Security certifications such as CISSP, CSSLP, GIAC, or similar.

Other Details

Hands-on experience is valued more than certifications. The role also requires strong collaboration and stakeholder engagement skills, with the ability to explain security risks clearly to diverse audiences, plus a pragmatic decision-making approach and strong documentation and communication.

Similar jobs you might like