Senior DevOps Engineer - Cyber Resilience Act Compliance

co.brick Poland
Remote
Apply
AI Summary

Ensure CRA compliance for the Fluke device ecosystem by translating legal and product compliance requirements into technical solutions. Launch and scale SAST/SCA tools, generate/maintain SBOMs, and work with multiple build systems. Demonstrate independence by launching end-to-end solutions in a complex ecosystem.

Key Highlights
CRA Compliance
Security Automation
Toolchain Integration
Vulnerability Management
Legacy Transformation
Key Responsibilities
Translate legal and product compliance requirements into concrete technical solutions within CI/CD pipelines.
Launch and scale SAST/SCA tools and generate/maintain SBOMs.
Work with multiple build systems and implement reusable security workflows.
Co-create a central database for vulnerabilities and waivers to ensure consistent risk management and audit traceability.
Introduce automation and security controls in environments with a high number of repositories and limited existing CI/CD.
Technical Skills Required
C/C++ DevOps CI/CD GitHub Actions GitLab CI AWS SAST SCA
Benefits & Perks
130-150 PLN/h net + VAT (B2B)

Job Description


co.brick talents — powered by AI, powered by people.

The primary objective of this project is to ensure a vast and diverse portfolio of products—specifically the Fluke device ecosystem—meets the rigorous requirements of the upcoming Cyber Resilience Act (CRA). This is not a greenfield project; it involves "injecting" security controls into existing, often legacy codebases, heterogeneous toolchains, and varied build systems.

Details

  • Timeline: April 1, 2026 – December 31, 2026
  • Rate: 130-150 PLN/h net + VAT (B2B)
  • Location: 100% Remote
  • Seniority: Senior

Responsibilities

  • CRA Compliance: Translate legal and product compliance requirements into concrete technical solutions within CI/CD pipelines.
  • Security Automation: Launch and scale SAST/SCA tools (e.g., Veracode, CodeSonar) and generate/maintain SBOMs (Software Bill of Materials).
  • Toolchain Integration: Work with multiple build systems (CMake, Make, vendor-specific solutions) and implement reusable security workflows.
  • Vulnerability Management: Co-create a central database for vulnerabilities and waivers to ensure consistent risk management and audit traceability.
  • Legacy Transformation: Introduce automation and security controls in environments with a high number of repositories and limited existing CI/CD.
  • Ownership: Demonstrate a high level of independence by launching end-to-end solutions in a complex ecosystem of long-lifecycle devices.

Requirements

  • Expertise: Strong engineering profile combining DevOps/CI/CD with application and product security.
  • Programming: Proficiency in C/C++ (essential for understanding the embedded and legacy codebase).
  • CI/CD Tools: Advanced experience with GitHub Actions, GitLab CI, and AWS.
  • Security Analysis: Practical experience with SAST and SCA tools for existing codebases.
  • Compliance Mindset: Experience working with security regulations or product compliance.

Similar Jobs

Explore other opportunities that match your interests

Senior Full Stack Developer

Programming
9h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Miratech

Poland

Senior Python Developer for Healthcare and Life Science Project

Programming
4d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Netguru

Poland

React Developer with Mendix

Programming
5d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

People More

Poland

Subscribe our newsletter

New Things Will Always Update Regularly