JobRaahGet matched free

Jobs

Security Engineer, Cloud and Software Supply Chain

tricentis · CZ - Prague · Czechia · Hybrid

Posted Oct 7, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

We are seeking a motivated Engineer to help secure our cloud platforms and the software supply chain that builds and delivers our products. As part of the Product Security organization, you will work closely with Product Security, Security Operations, Engineering, and Site Reliability Engineering to make sure the code we write, the dependencies we consume, the pipelines we run, and the cloud environments we deploy to are secure by design. This is a hands-on engineering role for someone who enjoys building automation, hardening CI/CD pipelines, and turning manual security checks into guardrails that scale across AWS, Azure, and Kubernetes. The ideal candidate has solid DevOps or cloud engineering foundations, a growing depth in security, and a curiosity about emerging supply chain threats, including those introduced by AI tooling and third-party models. Key Responsibilities Harden CI/CD pipelines (GitHub Actions, Azure DevOps) using least-privilege tokens, OIDC federation to cloud providers, pinned dependencies and actions, and protected branches and environments Implement and operate controls for build integrity and provenance, including artifact signing, SBOM generation and attestations aligned with the SLSA framework Integrate and tune software composition analysis, container image scanning, secrets detection, and IaC scanning so findings are accurate, actionable, and enforced at the right gates Help manage the security of artifact registries and package sources, including protections against dependency confusion and malicious or compromised packages Evaluate and monitor third-party dependencies, open source components, and AI artifacts (models, datasets, plugins, MCP servers) for supply chain risk Implement and maintain cloud security controls and best practices across AWS and Azure, with exposure to GCP Secure containerized workloads and Kubernetes clusters, including admission control, image signature verification, Pod Security Standards, and runtime hardening Build and support security guardrails in multi-cluster, hybrid (cloud and on-premise), and serverless environments using GitOps and infrastructure-as-code Leverage automation to continuously audit cloud posture, identity and access configurations, and network exposure, and drive remediation with owning teams Support the deployment and operation of security services such as WAF, DDoS protection, secrets management, and identity federation Collaboration and Continuous Improvement Identify manual security processes and replace them with automated, developer-friendly workflows Participate in threat modeling for pipelines, cloud architectures, and new platform capabilities Contribute to vulnerability triage and incident response for cloud and supply chain related events Write clear documentation, runbooks, and secure patterns that engineering teams can adopt with minimal friction Required Qualifications Education and Experience 2+ years of experience…