Jobs › Companies › Tricentis › Security Engineer, Cloud and Software Supply Chain

Sobre esta vaga de Security Engineer, Cloud and Software Supply Chain na Tricentis

Tricentis · Híbrido · CZ - Prague

We are seeking a motivated Engineer to help secure our cloud platforms and the software supply chain that builds and delivers our products. As part of the Product Security organization, you will work closely with Product Security, Security Operations, Engineering, and Site Reliability Engineering to make sure the code we write, the dependencies we consume, the pipelines we run, and the cloud environments we deploy to are secure by design.


This is a hands-on engineering role for someone who enjoys building automation, hardening CI/CD pipelines, and turning manual security checks into guardrails that scale across AWS, Azure, and Kubernetes. The ideal candidate has solid DevOps or cloud engineering foundations, a growing depth in security, and a curiosity about emerging supply chain threats, including those introduced by AI tooling and third-party models.


Key Responsibilities

  • Harden CI/CD pipelines (GitHub Actions, Azure DevOps) using least-privilege tokens, OIDC federation to cloud providers, pinned dependencies and actions, and protected branches and environments
  • Implement and operate controls for build integrity and provenance, including artifact signing, SBOM generation and attestations aligned with the SLSA framework
  • Integrate and tune software composition analysis, container image scanning, secrets detection, and IaC scanning so findings are accurate, actionable, and enforced at the right gates
  • Help manage the security of artifact registries and package sources, including protections against dependency confusion and malicious or compromised packages
  • Evaluate and monitor third-party dependencies, open source components, and AI artifacts (models, datasets, plugins, MCP servers) for supply chain risk
  • Implement and maintain cloud security controls and best practices across AWS and Azure, with exposure to GCP
  • Secure containerized workloads and Kubernetes clusters, including admission control, image signature verification, Pod Security Standards, and runtime hardening
  • Build and support security guardrails in multi-cluster, hybrid (cloud and on-premise), and serverless environments using GitOps and infrastructure-as-code
  • Leverage automation to continuously audit cloud posture, identity and access configurations, and network exposure, and drive remediation with owning teams
  • Support the deployment and operation of security services such as WAF, DDoS protection, secrets management, and identity federation
  • Collaboration and Continuous Improvement
  • Identify manual security processes and replace them with automated, developer-friendly workflows
  • Participate in threat modeling for pipelines, cloud architectures, and new platform capabilities
  • Contribute to vulnerability triage and incident response for cloud and supply chain related events
  • Write clear documentation, runbooks, and secure patterns that engineering teams can adopt with minimal friction

Required Qualifications


Education and Experience

  • 2+ years of experience in DevOps, cloud engineering, platform engineering, or security engineering
  • 2+ years of hands-on experience with AWS or Azure services in a production environment

Technical Skills

  • Hands-on experience building or maintaining CI/CD pipelines (e.g., GitHub Actions, Azure DevOps) and an understanding of how they can be attacked and defended
  • Working knowledge of containerization with Docker, Kubernetes, and Helm
  • Experience with infrastructure-as-code tools such as Terraform, Bicep/ARM templates, or CloudFormation
  • Proficiency in at least one scripting language (Python, Bash, or PowerShell)
  • Understanding of identity and access management concepts (IAM, RBAC, OAuth, OIDC, workload identity)
  • Familiarity with common supply chain and cloud threats (e.g., dependency confusion, credential leakage in pipelines, misconfigured storage, over-privileged identities)
  • Communicative written and verbal communication skills in English

Nice to have

  • Experience generating and consuming SBOMs and applying them to vulnerability management
  • Experience with policy-as-code engines
  • Cloud or security certifications (e.g., AWS Security Specialty, Azure Security Engineer Associate, CKS)
  • Interest in AI security, including risks from AI coding assistants, third-party models, and AI agent integrations
  • Working knowledge of the full SDLC and agile methodologies such as Scrum and Kanban

Tricentis Core Values

Knowing what we need to achieve and how to achieve it is important. Tricentis core values define our ways of working and the behaviors we model that create an enjoyable and successful Tricentis life.

  • Demonstrate Self-Awareness: Own your strengths and limitations.
  • Finish What We Start: Do what we say we are going to do.
  • Move Fast: Create momentum and efficiency.
  • Run Towards Change: Challenge the status quo.
  • Serve Our Customers & Communities: Create a positive experience with each interaction.
  • Solve Problems Together: We win or lose as one team.
  • Think Big & Believe: Set extraordinary goals and believe you can achieve them.


You can look forward to: 

  • Flexible working schedule (no core hours)  
  • Learning and career growth opportunities  
  • 25 days of paid time off  
  • 3 Sick Days  
  • 2 days of paid Volunteering Leave per year to get involved in your local community or in a cause that matters to you  
  • Hybrid work environment with home-office allowance 
  • Meal allowance 
  • Pension Contribution   
  • Life & Disability Insurance 
  • Paid Sickness Leave   
  • A team of passionate professionals who are experts in their fields 
  • Events for employees to learn, celebrate, and socialize (training sessions, hackathons, parties, sports events, board game gatherings, BBQs), and much more 


About Tricentis: 

Tricentis is a software company officially founded in 2007, with primary focus on software quality assurance. Whether exploratory or automated, functional or performance, API or UI, as well as mainframes or custom applications or packaged applications, or cloud-native applications - our comprehensive suite of specialized Continuous Testing tools makes DevOps real by giving our clients the confidence to release on demand. 


Tricentis has more than 1500 employees working in across over 20 global offices in US, EMEA, APAC serving over 2100 customers, and currently expanding our R&D centers to two new locations in the Czech Republic – Prague and Brno - Hybrid office environment. 


Tricentis is proud to be an equal opportunity workplace. Qualified applicants will receive consideration for employment without regard to race, color, ethnicity, gender, religious affiliation, age, sexual orientation, socioeconomic status, or physical and mental disability and other statuses protected by law.

Tricentis is proud to be an equal opportunity workplace. Qualified applicants will receive consideration for employment without regard to race, color, ethnicity, gender, religious affiliation, age, sexual orientation, socioeconomic status, or physical and mental disability and other statuses protected by law.

Global Sanctions Compliance

We comply with all applicable global sanctions and export control laws. Candidates must not be listed on any government restricted party lists (including OFAC SDN List and U.S. Commerce Department restricted lists) and must certify that their employment would not violate any sanctions or export control regulations. Candidates must notify us of any changes to their status during the application process or subsequent employment.

Pronto para se candidatar à Tricentis?
Candidatar-se à Tricentis

Sobre a Tricentis

Tricentis is a global leader in continuous testing and quality engineering. The Tricentis AI-based, continuous testing portfolio of products provide a new and fundamentally different way to perform software testing. An approach that’s totally automated, fully codeless, and intelligently driven by AI. It addresses both agile development and complex enterprise apps, enabling enterprises to accelerate their digital transformation by dramatically increasing software release speed, reducing costs, and improving software quality. Widely credited for reinventing software testing for DevOps, cloud, and enterprise applications, Tricentis has been recognized as a leader by all major industry analysts,

Ver todas as vagas na Tricentis →

Vagas semelhantes

Xero
Senior Security Engineer - Defence
Xero
⚡ Candidate-se cedo AU: Melbourne: (260 Burwood Rd... Híbrido
● Nova 👁 Vista ✓ Candidatada há 5h
Wordsmith AI
IT Security Engineer
Wordsmith AI
⚡ Candidate-se cedo Edinburgh Presencial
● Nova 👁 Vista ✓ Candidatada há 5h
First Citizens Bank
Information Security Engineer II - IAM (Automation)
First Citizens Bank
⚡ Candidate-se cedo Bangalore, India Presencial
● Nova 👁 Vista ✓ Candidatada há 5h
Darktrace
Senior Cybersecurity Pre-sales Engineer
Darktrace
⚡ Candidate-se cedo Milan Office, Italy Presencial
● Nova 👁 Vista ✓ Candidatada há 5h
Shieldai
Cybersecurity Platform Engineer (R5531)
Shieldai
⚡ Candidate-se cedo Seattle, Washington Presencial
● Nova 👁 Vista ✓ Candidatada há 5h
Sierra Space
Cybersecurity Engineer III
Sierra Space
⚡ Candidate-se cedo Louisville, CO Presencial $122,109–$167,899
● Nova 👁 Vista ✓ Candidatada há 5h
Moderna
Senior AI Security Engineer
Moderna
⚡ Candidate-se cedo Warsaw - Poland Presencial
● Nova 👁 Vista ✓ Candidatada há 5h
TI
Senior Security Operations Engineer
Tines
⚡ Candidate-se cedo United States (Remote) · local restrito
● Nova 👁 Vista ✓ Candidatada há 5h
Conagra Brands
Application Security Engineer
Conagra Brands
⚡ Candidate-se cedo Omaha, Nebraska Presencial $73,600–$109,300
● Nova 👁 Vista ✓ Candidatada há 6h

Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

Mais vagas na Tricentis

Ver todas as vagas na Tricentis →

Candidatar-se agora
🤖

Opa — calma aí

A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Ganhe vantagem na sua busca por emprego.

Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

Entre no canal — é grátis