Security Engineer, Cloud and Software Supply Chain
Core
Secure cloud platforms and the software supply chain by hardening CI/CD pipelines, managing dependencies, and implementing security controls across AWS, Azure, and Kubernetes.
Role type
Security Engineer (Cloud and Software Supply Chain)
Builds
Automated security guardrails, hardened CI/CD pipelines, secure containerized workloads, and cloud security controls.
Domain
Cloud Security / DevSecOps / Software Supply Chain
Required skills
CI/CD pipeline hardening, container security (Docker, Kubernetes, Helm), infrastructure-as-code (Terraform, Bicep, CloudFormation), scripting (Python, Bash, PowerShell), identity and access management (IAM, OIDC), software composition analysis, artifact signing and SBOM generation.
Preferred skills
Policy-as-code engines, cloud security certifications (AWS Security Specialty, CKS), AI security knowledge.
Technologies
GitHub Actions, Azure DevOps, AWS, Azure, Kubernetes, Docker, Helm, Terraform, Bicep, ARM, CloudFormation, Python, Bash, PowerShell, SLSA, WAF, Secrets Management. (via careerplan.io/jobs/JR106003-security-engineer-cloud-and-software-supply-chain-at-tricentis)
Responsibilities
Harden CI/CD pipelines using least-privilege tokens and OIDC; implement build integrity controls like artifact signing and SBOM generation; integrate SCA, container scanning, and IaC scanning; manage artifact registries and protect against dependency confusion; secure containerized workloads and Kubernetes clusters; build security guardrails in multi-cluster and serverless environments; audit cloud posture and drive remediation; support security services like WAF and secrets management.
Seniority
Mid-level, hands-on IC