Senior DevSecOps Engineer – Kubernetes & Software Supply Chain Security

location_onCopenhagen, Denmarkschedulefor 8 timer siden
apartmentArbejdsstil:På stedet
trending_upErfaringsniveau:Senior
badgeBeskæftigelse:Fuldtid
Ansøg nuopen_in_new

Jobbeskrivelse

Twoday is the leading digital transformation partner in Northern Europe with a global presence. With approximately 3,000 technologies, we collaborate with the most admired private and public organizations to deliver cutting-edge digital solutions. Our deep industry expertise spans Data & AI, software development, digital experiences, and business applications. Operating across the Nordics and Lithuania, our team generated a revenue of 280 million euros in 2023. We serve over 8,000 customers, supporting their digital transformation journeys.

Senior DevSecOps Engineer – Kubernetes & Software Supply Chain Security

Permanent position at Twoday | Copenhagen

Twoday is a leading digital transformation partner in Northern Europe, with approximately 3,000 specialists delivering digital solutions to public and private organisations.

We are looking for an experienced, hands-on DevSecOps Engineer to strengthen security across development pipelines, Kubernetes platforms and production environments for one of our major public-sector clients.

This is a role for someone who implements, automates and maintains security controls – not someone who only advises on them.

Your role

You will work alongside an experienced operations team, embedding security into development, deployment and daily operations while helping the team adopt secure, sustainable engineering practices.

Your responsibilities will include:

  • Implementing automated security controls across CI/CD pipelines, including SAST, SCA, secret scanning, container scanning and Infrastructure as Code (IaC) scanning.
  • Securing the software supply chain through SBOM generation (CycloneDX/SPDX), artefact signing and verification (e.g. Sigstore/cosign), SLSA principles and secure branch, review and release processes.
  • Securing CI/CD pipelines and runners using least-privilege principles.
  • Implementing Kubernetes security controls, including admission control, policy-as-code, Pod Security Standards, RBAC, network policies and secrets management.
  • Hardening Linux and Windows environments and managing vulnerabilities from identification through to remediation.
  • Supporting runtime threat detection, security monitoring, incident response and forensic investigations.
  • Establishing security frameworks for AI-assisted development and autonomous AI agents, including controlled permissions, review gates, traceability and protection against prompt injection.
  • Documenting security controls for compliance and audit purposes, while sharing knowledge and transferring solutions to the internal team.

What we're looking for

You have practical DevSecOps experience and can demonstrate that you have implemented security controls in real development and production environments.

We are particularly interested in experience with:

  • Software supply chain security: SAST, SCA, secret scanning, SBOM, artefact signing and verification, container and IaC scanning.
  • CI/CD and automation: GitLab CI, GitHub Actions or similar, secure pipelines and runners, Terraform, Ansible and scripting with Python, Bash or PowerShell.
  • Kubernetes security: Kyverno, OPA Gatekeeper or similar, admission control, Pod Security Standards, RBAC, network policies and secrets management using Vault, External Secrets or equivalent.
  • Platform security: CIS-based Linux hardening, Windows Server hardening and runtime detection tools such as Falco.
  • Vulnerability management and incident response: Risk-based remediation, logging, SIEM solutions such as ELK or Wazuh, incident handling and forensics.
  • AI security: Security controls for AI-assisted and agentic workflows, including autonomy boundaries, human review, prompt injection protection and secure credential handling.
  • Compliance: NIS2, ISO 27001/27002 and GDPR.

Experience with virtualisation platforms such as Proxmox is useful. Experience from the public sector or organisations subject to NIS2 is an advantage, but not essential.

The environment follows an open-source-first approach with EU-based infrastructure. Experience with US hyperscalers is not relevant to this assignment.

You must be fluent in Danish and English, both written and spoken, and able to work onsite full time in Copenhagen.

Who you are

You are hands-on, security-conscious and pragmatic. You see security as an enabler rather than an obstacle, prioritise risks sensibly and enjoy helping experienced engineers strengthen their security practices. You take ownership, document your work and build solutions that others can maintain.

Why Twoday?

At Twoday, you will work with skilled colleagues on complex, business-critical solutions that make a real difference. We offer a collaborative environment with professional freedom, technical challenges and opportunities to develop your expertise.

Interested?

We would love to hear from you. Apply today and help us build secure, reliable and future-ready digital platforms.

Diversity & inclusion

Do you not meet all the requirements? Studies show that women and minorities are less likely to apply if they don’t meet every qualification. At Twoday, we are committed to building an inclusive workplace where everyone is welcome.

If this role excites you, we encourage you to apply.

Nævnte færdigheder

Søg dette job

Use the application link supplied with this listing to apply to twodaydenmark.teamtailor.com. Check the destination before entering personal information.

Ansøg nuopen_in_new