DevSecOps LeadBulgaria; Moldavia; Poland; Romania

United States April 14, 2026
Back to jobs

DevSecOps Lead

Bulgaria; Moldavia; Poland; Romania
Apply

Hello, let’s meet!

Who We Are

While Xebia is a global tech company, our journey in CEE started with two Polish companies – PGS Software, known for world-class cloud and software solutions, and GetInData, a pioneer in Big Data. Today, we’re a team of 1,000+ experts delivering top-notch work across cloud, data, and software. And we’re just getting started.

What We Do

We work on projects that matter – and that make a difference. From fintech and e-commerce to aviation, logistics, media, and fashion, we help our clients build scalable platforms, data and AI solutions, and cutting-edge applications to shape the future of tech. Our clients include McLaren, Aviva, Deloitte, Spotify, Disney, ING, UPS, Tesco, Truecaller, AllSaints, Volotea, Schmitz Cargobull, Allegro, InPost, and many, many more.

We value smart tech, real ownership, and continuous growth. We use modern, open-source stacks, and we’re proud to be trusted partners of Databricks, dbt, Snowflake, Azure, GCP, and AWS. Fun fact: we were the first AWS Premier Partner in Poland!

Beyond Projects

What makes Xebia special? Our community. We support tech communities, organize meetups (Software Talks, Data Tech Talks), and have a culture that actively support your growth via Guilds, Labs, and personal development budgets — for both tech and soft skills. It’s not just a job. It’s a place to grow.

What sets us apart? 

Our mindset. Our vibe. Our people. And while that’s hard to capture in text – come visit us and see for yourself.

 

About the role
We are looking for a DevSecOps Lead who will act as a key bridge between platform engineering teams and the CSO organization. You will be shaping how security requirements are translated into engineering practices while ensuring alignment between architecture, risk, and business priorities.

 

You will be:

 

  • developing a deep understanding of platform architecture including infrastructure, services, data flows, and integrations,
  • evaluating platform designs against security requirements and identifying risks and gaps,
  • producing clear and evidence-based security assessments with prioritized remediation recommendations,
  • acting as the primary liaison between platform engineering teams and the CSO organisation,
  • translating security policies into actionable engineering guidance,
  • representing platform constraints and technical realities to inform security decisions,
  • facilitating regular alignment between teams on security priorities, roadmaps, and incident response,
  • partnering with engineering teams during design reviews and feature development to embed security from the start,
  • tracking remediation efforts and ensuring timely resolution of identified security issues,
  • supporting audits, compliance activities, and risk assessments.

 

Your profile:

  • 3 - 6 years of experience in security engineering, platform security, or a closely related discipline,
  • strong understanding of platform and cloud architecture (e.g., AWS, GCP, or Azure), including networking, IAM, and containerized environments,
  • practical experience using AI-powered assistants (e.g. Claude Code, GitHub Copilot, Cursor) to improve productivity, quality, or decision-making in software delivery,
  • demonstrated ability to assess systems against security frameworks (e.g., NIST, CIS, SOC 2, ISO 27001) and identify control gaps,
  • excellent communication skills with the ability to translate technical findings for both engineering and executive audiences,
  • experience working cross-functionally across engineering, security, and leadership teams,
  • relevant certifications such as CISSP, CISM, AWS Security Speciality, or equivalent,
  • experience in a liaison or embedded security role within a product or platform engineering organization,
  • familiarity with DevSecOps practices, CI/CD security integration, and infrastructure-as-code security review,
  • prior exposure to working with or within a CSO or CISO function,
  • at least a B2 level of English proficiency.

    Work from the European Union region and a work permit are required.

Nice to have:

  • experience applying GenAI in a more structured way within the SDLC, including defined workflows, prompt patterns, or tool integrations embedded into daily work,
  • interest in and familiarity with emerging AI-driven practices (e.g. agent-based workflows, automation patterns, AI-augmented development), with a willingness to explore and experiment beyond standard approaches.

 

Recruitment Process:

CV review – HR call – InterviewTeam / Client Interview – Decision

 

Apply for this job

*

indicates a required field

First Name*
Last Name*
Email*
Phone
Country*
Phone*
Resume/CV*
AttachAttach
Dropbox
Google Drive
Enter manuallyEnter manually

Accepted file types: pdf, doc, docx, txt, rtf


Where did you find this job offer?*
Select...
How many years of experience do you have in security engineering or platform security?*
Do you have hands-on experience with at least one cloud platform (AWS, GCP, or Azure)? *
Select...
This role requires daily overlap (3-4 hours) with US East Coast working hours. Are you able and willing to work this schedule regularly?*
Select...
What is your notice period?*
Select...
What is your preferred form of cooperation?*
Select...
Based on your preferred form of cooperation (per hour or monthly) what are your financial expectations?*
What country do you currently reside in?*
Select...
Do you have documents entitling you to work in the European Union (valid work permits to work in the EU)?*
Select...
Do you speak English at a minimum B2 level?*
Select...
I declare that I agree to the processing of my Personal Data contained in the content of documents sent in response to the job/cooperation offer, and Personal Data collected during a possible recruitment interview, in order to participate in future recruitment processes conducted by the Administrator, i.e. Xebia sp. z o.o. with its registered office in Wrocław.*
Select...
I declare that I agree to sending to my e-mail address indicated in the content of recruitment documents, any information about recruitment processes conducted by the Administrator, i.e. Xebia sp. z o.o. with its registered office in Wrocław.*
Select...
The administrator of Personal Data is Xebia sp. z o.o. with its registered office in Wrocław, ul. Sucha 3, 50-086 Wrocław, KRS: 0000978067, NIP: 8971719181, REGON: 020363023 with a share capital of PLN 37 168 600.00. Your data contained in the CV will be processed only for recruitment purposes. The legal basis for the processing of your personal data is art. 221 cl. 1 of the Labour Code. If you provide separate consent, we will process your personal data also for future recruitment purposes. You have the right to access your personal data, to correct them, to remove them, to restrict their processing, to transfer your data, to submit an objection, to withdraw consent to data processing any time without affecting the lawfulness of processing carried out on the basis of the consent before it was withdrawn. In order to exercise the abovementioned rights, please send an e-mail with your request to: [email protected]. If you believe that your data are processed illegally, you can submit a complaint to the supervisory body with its registered office in ul. Stawki 2, Warsaw. We may only disclose your personal data if you provide consent thereto or to authorised bodies, when necessary.*
Select...
Submit application
Apply on company site

How well do you match this role?

Check My Resume