Tricentis

Security Engineer, Cloud and Software Supply Chain

Tricentis
Apply
1 day ago
Prague, CzechiaMid Level

Responsibilities

  • Harden GitHub Actions and Azure DevOps pipelines using least-privilege tokens, OIDC federation, pinned dependencies and actions, and protected branches and environments.
  • Implement and operate build integrity and provenance controls, including artifact signing, SBOM generation, and attestations aligned with SLSA.
  • Integrate and tune software composition analysis, container image scanning, secrets detection, and infrastructure-as-code scanning.
  • Secure artifact registries, package sources, third-party dependencies, open-source components, and AI artifacts against supply chain risks.
  • Implement cloud security controls across AWS and Azure, with exposure to GCP, and secure containerized workloads and Kubernetes clusters.
  • Build security guardrails for multi-cluster, hybrid cloud and on-premise, and serverless environments using GitOps and infrastructure-as-code.
  • Automate audits of cloud posture, identity and access configurations, and network exposure, and drive remediation with owning teams.
  • Support WAF, DDoS protection, secrets management, identity federation, vulnerability triage, and incident response.
  • Automate manual security processes, participate in threat modeling, and write documentation, runbooks, and secure patterns for engineering teams.

Requirements

  • At least 2 years of experience in DevOps, cloud engineering, platform engineering, or security engineering.
  • At least 2 years of hands-on experience with AWS or Azure services in a production environment.
  • Hands-on experience building or maintaining CI/CD pipelines and understanding how they can be attacked and defended.
  • Working knowledge of Docker, Kubernetes, and Helm.
  • Experience with Terraform, Bicep/ARM templates, or CloudFormation.
  • Proficiency in at least one of Python, Bash, or PowerShell.
  • Understanding of IAM, RBAC, OAuth, OIDC, and workload identity concepts.
  • Familiarity with dependency confusion, credential leakage in pipelines, misconfigured storage, and over-privileged identity threats.
  • Strong written and verbal communication skills in English.
  • Preferred experience includes generating and consuming SBOMs, policy-as-code engines, cloud or security certifications, AI security, and SDLC methodologies such as Scrum and Kanban.

Benefits

  • Flexible working schedule with no core hours.
  • Hybrid work environment with a home-office allowance.
  • 25 days of paid time off, 3 sick days, and 2 days of paid volunteering leave per year.
  • Learning and career growth opportunities.
  • Meal allowance, pension contribution, life and disability insurance, and paid sickness leave.
  • Employee events including training sessions, hackathons, parties, sports events, board game gatherings, and BBQs.
  • Opportunity to work with a team of experienced professionals.

Tech Stack

Categories

Tricentis

About Tricentis

1,001-5,000 employees

Tricentis builds an AI-powered quality engineering platform for enterprises, spanning test automation, performance testing, and DevOps workflows (products include Tosca, qTest, and NeoLoad). It sells licenses and SaaS subscriptions to large organizations modernizing SAP, cloud, and custom apps, with customers such as T-Mobile and Allianz. Founded in 2007 and headquartered in Austin, Texas, the company is privately held.

Contact me