Jobs › Companies › Tricentis › Security Engineer, Cloud and Software Supply Chain

About this Security Engineer, Cloud and Software Supply Chain role at Tricentis

Tricentis · Hybrid · CZ - Prague

We are seeking a motivated Engineer to help secure our cloud platforms and the software supply chain that builds and delivers our products. As part of the Product Security organization, you will work closely with Product Security, Security Operations, Engineering, and Site Reliability Engineering to make sure the code we write, the dependencies we consume, the pipelines we run, and the cloud environments we deploy to are secure by design.


This is a hands-on engineering role for someone who enjoys building automation, hardening CI/CD pipelines, and turning manual security checks into guardrails that scale across AWS, Azure, and Kubernetes. The ideal candidate has solid DevOps or cloud engineering foundations, a growing depth in security, and a curiosity about emerging supply chain threats, including those introduced by AI tooling and third-party models.


Key Responsibilities

  • Harden CI/CD pipelines (GitHub Actions, Azure DevOps) using least-privilege tokens, OIDC federation to cloud providers, pinned dependencies and actions, and protected branches and environments
  • Implement and operate controls for build integrity and provenance, including artifact signing, SBOM generation and attestations aligned with the SLSA framework
  • Integrate and tune software composition analysis, container image scanning, secrets detection, and IaC scanning so findings are accurate, actionable, and enforced at the right gates
  • Help manage the security of artifact registries and package sources, including protections against dependency confusion and malicious or compromised packages
  • Evaluate and monitor third-party dependencies, open source components, and AI artifacts (models, datasets, plugins, MCP servers) for supply chain risk
  • Implement and maintain cloud security controls and best practices across AWS and Azure, with exposure to GCP
  • Secure containerized workloads and Kubernetes clusters, including admission control, image signature verification, Pod Security Standards, and runtime hardening
  • Build and support security guardrails in multi-cluster, hybrid (cloud and on-premise), and serverless environments using GitOps and infrastructure-as-code
  • Leverage automation to continuously audit cloud posture, identity and access configurations, and network exposure, and drive remediation with owning teams
  • Support the deployment and operation of security services such as WAF, DDoS protection, secrets management, and identity federation
  • Collaboration and Continuous Improvement
  • Identify manual security processes and replace them with automated, developer-friendly workflows
  • Participate in threat modeling for pipelines, cloud architectures, and new platform capabilities
  • Contribute to vulnerability triage and incident response for cloud and supply chain related events
  • Write clear documentation, runbooks, and secure patterns that engineering teams can adopt with minimal friction

Required Qualifications


Education and Experience

  • 2+ years of experience in DevOps, cloud engineering, platform engineering, or security engineering
  • 2+ years of hands-on experience with AWS or Azure services in a production environment

Technical Skills

  • Hands-on experience building or maintaining CI/CD pipelines (e.g., GitHub Actions, Azure DevOps) and an understanding of how they can be attacked and defended
  • Working knowledge of containerization with Docker, Kubernetes, and Helm
  • Experience with infrastructure-as-code tools such as Terraform, Bicep/ARM templates, or CloudFormation
  • Proficiency in at least one scripting language (Python, Bash, or PowerShell)
  • Understanding of identity and access management concepts (IAM, RBAC, OAuth, OIDC, workload identity)
  • Familiarity with common supply chain and cloud threats (e.g., dependency confusion, credential leakage in pipelines, misconfigured storage, over-privileged identities)
  • Communicative written and verbal communication skills in English

Nice to have

  • Experience generating and consuming SBOMs and applying them to vulnerability management
  • Experience with policy-as-code engines
  • Cloud or security certifications (e.g., AWS Security Specialty, Azure Security Engineer Associate, CKS)
  • Interest in AI security, including risks from AI coding assistants, third-party models, and AI agent integrations
  • Working knowledge of the full SDLC and agile methodologies such as Scrum and Kanban

Tricentis Core Values

Knowing what we need to achieve and how to achieve it is important. Tricentis core values define our ways of working and the behaviors we model that create an enjoyable and successful Tricentis life.

  • Demonstrate Self-Awareness: Own your strengths and limitations.
  • Finish What We Start: Do what we say we are going to do.
  • Move Fast: Create momentum and efficiency.
  • Run Towards Change: Challenge the status quo.
  • Serve Our Customers & Communities: Create a positive experience with each interaction.
  • Solve Problems Together: We win or lose as one team.
  • Think Big & Believe: Set extraordinary goals and believe you can achieve them.


You can look forward to: 

  • Flexible working schedule (no core hours)  
  • Learning and career growth opportunities  
  • 25 days of paid time off  
  • 3 Sick Days  
  • 2 days of paid Volunteering Leave per year to get involved in your local community or in a cause that matters to you  
  • Hybrid work environment with home-office allowance 
  • Meal allowance 
  • Pension Contribution   
  • Life & Disability Insurance 
  • Paid Sickness Leave   
  • A team of passionate professionals who are experts in their fields 
  • Events for employees to learn, celebrate, and socialize (training sessions, hackathons, parties, sports events, board game gatherings, BBQs), and much more 


About Tricentis: 

Tricentis is a software company officially founded in 2007, with primary focus on software quality assurance. Whether exploratory or automated, functional or performance, API or UI, as well as mainframes or custom applications or packaged applications, or cloud-native applications - our comprehensive suite of specialized Continuous Testing tools makes DevOps real by giving our clients the confidence to release on demand. 


Tricentis has more than 1500 employees working in across over 20 global offices in US, EMEA, APAC serving over 2100 customers, and currently expanding our R&D centers to two new locations in the Czech Republic – Prague and Brno - Hybrid office environment. 


Tricentis is proud to be an equal opportunity workplace. Qualified applicants will receive consideration for employment without regard to race, color, ethnicity, gender, religious affiliation, age, sexual orientation, socioeconomic status, or physical and mental disability and other statuses protected by law.

Tricentis is proud to be an equal opportunity workplace. Qualified applicants will receive consideration for employment without regard to race, color, ethnicity, gender, religious affiliation, age, sexual orientation, socioeconomic status, or physical and mental disability and other statuses protected by law.

Global Sanctions Compliance

We comply with all applicable global sanctions and export control laws. Candidates must not be listed on any government restricted party lists (including OFAC SDN List and U.S. Commerce Department restricted lists) and must certify that their employment would not violate any sanctions or export control regulations. Candidates must notify us of any changes to their status during the application process or subsequent employment.

Ready to apply to Tricentis?
Apply to Tricentis

About Tricentis

Tricentis is a global leader in continuous testing and quality engineering. The Tricentis AI-based, continuous testing portfolio of products provide a new and fundamentally different way to perform software testing. An approach that’s totally automated, fully codeless, and intelligently driven by AI. It addresses both agile development and complex enterprise apps, enabling enterprises to accelerate their digital transformation by dramatically increasing software release speed, reducing costs, and improving software quality. Widely credited for reinventing software testing for DevOps, cloud, and enterprise applications, Tricentis has been recognized as a leader by all major industry analysts,

See all jobs at Tricentis →

Similar jobs

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at Tricentis

See all jobs at Tricentis →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free