DevSecOps Engineer
Offer summary

(Summary generated by AI based on the full job description)

The project focuses on secure, high-performance CI/CD pipelines for multi-language applications with an emphasis on supply chain integrity and compliance. Key technologies include Jenkins Shared Libraries (Groovy), Python, Java/Maven, Node/NPM and security tools such as SonarQube, Sonatype IQ, SAST. Responsibilities cover designing and maintaining pipelines, optimizing performance, ensuring artifact integrity, refactoring scripts, and mentoring in DevSecOps and supply chain security.

you can start ASAP

DevSecOps Engineer

Company: Mindbox Sp. z o.o.

from: 26 May 2026
to: 25 June 2026
24 000 - 29 000net (+ VAT)/ mth.B2B contract (full-time)
Offer parameters
level:senior
working mode:hybrid
location:Kraków, Lesser Poland
Kraków, Lesser Poland

Requirements

Expected technologies

Jenkins
Groovy
YAML
JSON
Java
Maven
Node
NPM
Python
Java/Maven
SonarQube
Sonatype IQ
SAST

Operating system

Windows

Our requirements

  • Minimum 7+ years in engineering roles, with 3+ years in DevSecOps or CI/CD platform engineering.
  • Strong hands-on expertise with Jenkins Shared Libraries (Groovy).
  • Advanced Python programming for automation, YAML/JSON parsing, and tooling development.
  • Solid understanding of multi-language build pipelines: Java/Maven, Node/NPM, Python, with exposure to Helm, Terraform, and container image metadata handling.
  • Deep knowledge of supply chain security standards (e.g., SLSA, SBOM via CycloneDX, artifact digests).
  • Experience with static and container scanning tools: SonarQube, Sonatype IQ, SAST.
  • Proven ability in build optimization techniques, caching, and dependency pruning.
  • Compliance Awareness & Documentation Discipline.

Your responsibilities

  • Design, implement, and maintain Groovy-based Jenkins pipeline steps for build, test, packaging, scanning, and deployment.
  • Extend and refine Python tooling for SLSA provenance, SBOM generation, hash/digest verification, and security scan aggregation (SonarQube, Sonatype IQ, SAST, container scans).
  • Optimize pipeline performance through parallelization, caching, and smart dependency management.
  • Ensure artifact integrity, reproducible builds, and accurate cryptographic mappings (SHA1/SHA256).
  • Refactor legacy scripts for stability and compliance, apply standard templates, and eliminate global state issues.
  • Define and document ci-config.yaml standards and enforce usage patterns.
  • Mentor teams on DevSecOps best practices, supply chain security, and secure pipeline design.
  • Troubleshoot and proactively prevent pipeline incidents across environments.
  • Note: Detailed project information will be shared during the recruitment process.

About the project

Are you an expert in CI/CD platforms with a strong security mindset? We are seeking a DevSecOps Engineer to design and evolve secure, high-performance build pipelines for multi-language applications, ensuring supply chain integrity and compliance in a global environment.
Sounds like your kind of challenge?

This is how we organize our work

This is how we work

agile

This is how we work on a project

  • Continuous Deployment
  • Continuous Integration
  • DevOps
Joining this project you’ll become part of Mindbox – a tech-driven company where consulting, engineering, and talent meet to build meaningful digital solutions. We’ll back you up every step of the way, accelerate your development, and ensure your skills make a difference.
Company

What we offer

  • Flexible cooperation model – choose the form that suits you best (B2B, employment contract, etc.)
  • Hybrid work setup – hybrid; 2 days per week from the office in Warsaw, 3 days per week remote
  • Collaborative team culture – work alongside experienced professionals eager to share knowledge
  • Continuous development – access to training platforms and growth opportunities
  • Comprehensive benefits – including Interpolska Health Care, Multisport card, Warta Insurance, and more
  • High quality equipment – laptop and essential software provided

Benefits

  • sharing the costs of sports activities
  • private medical care
  • sharing the costs of professional training & courses
  • life insurance

Mindbox Sp. z o.o.

At Mindbox, we connect top IT talents with technology projects for leading enterprises across Europe.
Our focus is on matching your skills with work that matters – projects that use modern tech stacks, solve real business challenges, and give you space to grow. By joining us, you’ll deliver technology solutions for well-known brands, supported by the Mindbox team that values knowledge-sharing and continuous development. We make sure you have the tools, flexibility, and guidance to do your best work – and to keep moving forward in your career.
DevSecOps Engineer
24k–29k zł / mth. (B2B)
I apply to:
Mindbox Sp. z o.o.
Kraków, Lesser Poland
Pracodawca zbiera zgłoszenia przez swój system.
Przejdziesz na zewnętrzny formularz.

By clicking "Aplikuj" you confirm that you've read and accepted our Terms and Conditions.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Need more information?

  • Make sure the body of the offer doesn’t already include what you’re looking for.
  • Ask a question if you need more information you’re interested in.
  • We’ll forward your question to the employer and aim to provide a response within 3 business days.

Share this offer