McKesson

Lead DevSecOps Engineer

McKesson
Apply
14 hours ago
Cork, IrelandStaff+

Responsibilities

  • Lead enterprise application security and DevSecOps initiatives across cloud, on-premises, and hybrid environments.
  • Design and implement security controls within CI/CD pipelines and developer platforms.
  • Operationalize application security and software supply chain security tools, including GitHub Advanced Security, OWASP ZAP, Veracode, SonarQube, JFrog Xray/Curation, Black Duck, Sonatype, and FOSSA.
  • Develop security automation and integrations using Python, Bash, JavaScript, or similar scripting languages.
  • Partner with engineering and platform teams on secure-by-design practices for applications, APIs, containers, and cloud workloads.
  • Provide technical leadership for security incidents, vulnerability management, and remediation activities.
  • Develop and maintain security standards for Kubernetes, containers, Terraform, and cloud-native application platforms.
  • Build policy-as-code, security automation, and self-service security capabilities.
  • Mentor engineers and influence security architecture, standards, and roadmaps.

Requirements

  • 10+ years of progressive experience in cybersecurity engineering, application security, DevSecOps, cloud security, or related security engineering disciplines.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or equivalent experience.
  • Experience implementing and operating enterprise-scale security tools such as GitHub Advanced Security, SonarQube, and OWASP ZAP.
  • Experience with software supply chain security and open-source risk management tools such as JFrog Xray/Curation, Black Duck, Sonatype, or FOSSA.
  • Proficiency in scripting and automation with Python, Bash, JavaScript, or similar languages.
  • Experience securing CI/CD pipelines using GitHub Actions, Jenkins, GitLab CI, Azure DevOps, or comparable platforms.
  • Hands-on experience securing AWS, Azure, and/or GCP environments.
  • Experience with Docker and Kubernetes.
  • Experience managing GitHub or GitLab source code management platforms and software delivery infrastructure.
  • Preferred master's degree in Cybersecurity, Computer Science, or a related field.
  • Preferred experience with policy-as-code, infrastructure-as-code security, automated security guardrails, threat modeling, secure code reviews, application security testing, zero-trust architectures, identity security, cryptography, and cloud-native security controls.
  • Preferred relevant certifications such as CISSP, CCSP, CSSLP, AWS Security Specialty, Azure Security Engineer, or GIAC certifications.
  • Preferred experience with security metrics, executive reporting, large-scale security transformation, mentoring engineers, Kubernetes platforms, container registries, artifact signing, SBOM management, provenance, dependency governance, and secure build practices.

Benefits

  • Total Rewards package with comprehensive benefits supporting physical, mental, and financial well-being.
  • Competitive base pay range of €82,500 to €137,500 per year, with potential annual bonus or long-term incentive opportunities.
  • Compensation considers performance, experience, skills, equity, market evaluations, and geographic markets.

Tech Stack

Categories

McKesson

About McKesson

10,000+ employees

McKesson is a public healthcare company that distributes pharmaceuticals and medical‑surgical supplies and provides pharmacy and provider technology and services. It sells to pharmacies, hospitals, health systems, and biopharma manufacturers through logistics, specialty and oncology support, pharmacy management, and healthcare IT/analytics offerings. Founded in 1833 and headquartered in Irving, Texas, it trades on the NYSE under the ticker MCK.

Contact me