Senior DevSecOps Engineer
About the Role
We are looking for an experienced Senior DevSecOps Engineer to join a DevOps environment and take responsibility for implementing and operating secure software delivery practices across the development lifecycle.
You will work closely with software development teams, cybersecurity specialists, and infrastructure engineers to embed security into CI/CD pipelines, development workflows, and infrastructure. A key focus will be SBOM, software supply chain security, vulnerability management, and security automation.
Key Responsibilities
Implement and maintain secure software delivery practices across the development lifecycle.
Integrate security controls and automated security checks into CI/CD pipelines.
Implement and maintain SBOM (Software Bill of Materials) frameworks and toolchains.
Strengthen software supply chain security and dependency management.
Implement and maintain SAST and DAST solutions within development toolchains.
Automate vulnerability scanning, security checks, and remediation workflows.
Develop security integrations and pipeline automation using Python, Bash, or similar scripting languages.
Implement and maintain key security functions supporting product cybersecurity requirements.
Collaborate with development, cybersecurity, DevOps, and infrastructure teams.
Continuously improve security practices, tooling, and the overall product security posture.
Required Experience
Strong hands-on experience in DevSecOps and product cybersecurity environments.
Experience working with SBOM frameworks and toolchains.
Good understanding of software supply chain security.
Hands-on experience with vulnerability scanning tools.
Experience implementing SAST and DAST within CI/CD pipelines.
Strong scripting and automation skills using Python, Bash, or similar languages.
Experience with tools such as Black Duck, Trivy, SonarQube, Nexus, or equivalent solutions.
Strong understanding of secure CI/CD workflows and security automation.
Knowledge of security frameworks such as OWASP Top 10, MITRE ATT&CK, or similar.
Beneficial Experience
Experience from regulated or product-focused industries such as automotive, industrial, embedded systems, or IoT.
Experience with container security and Kubernetes environments.
Familiarity with SIEM, centralized logging, security monitoring, and observability platforms.
Previous experience working with product cybersecurity requirements in large-scale engineering organizations.
Who You Are
You are a hands-on security-focused engineer who understands both software development and cybersecurity. You enjoy automating security controls rather than relying on manual processes and are comfortable collaborating across development, DevOps, infrastructure, and cybersecurity teams.
If you have strong experience in DevSecOps, SBOM, SAST/DAST, software supply chain security, and secure CI/CD, we would be happy to hear from you.
- Department
- IT & Engineering
- Locations
- Gothenburg , Sweden
About Aurora Engineering AB
Aurora Engineering AB is a Swedish engineering consultancy providing technical expertise and project support within the automotive and industrial sectors. We connect skilled engineers with innovative companies to deliver high-quality solutions in product development, design, testing, and digital engineering.