About the role
<p><strong>CAPCO POLAND&nbsp;</strong></p> <p><strong>*We are looking for Poland based candidate.&nbsp;</strong></p> <p>At&nbsp;<strong>Capco Poland,</strong>&nbsp;we’re not just another consultancy - we’re the spark behind digital transformation in the financial world. As a global leader in technology and management consulting, we thrive on helping clients tackle the toughest challenges across banking, payments, capital markets, wealth, and asset management.</p> <p><strong>Role Overview</strong></p> <p></p> <p>We are seeking an experienced <strong>Senior DevSecOps Engineer</strong> with strong AWS and Azure expertise to provide specialist engineering services focused on embedding security throughout the software delivery lifecycle. Within this engagement, you will design and deliver automated security capabilities, integrate security tooling (SAST/DAST, EDR, Vulnerability Management) into CI/CD pipelines, and enable secure software delivery through scalable engineering practices. The engagement focuses on delivering automated security capabilities that enable rapid software delivery while maintaining enterprise security, compliance, and governance.</p> <p><strong>Key Responsibilities</strong></p> <ul> <li><strong>CI/CD Security Automation:</strong>&nbsp;Design, build, and maintain secure deployment pipelines (e.g., GitHub Actions, Azure DevOps, GitLab CI). Integrate automated vulnerability scanning, secret detection, and software supply chain security (SCA) seamlessly into the developer workflow.</li> <li><strong>Policy-as-Code &amp; Guardrails:</strong>&nbsp;Write, test, and deploy automated policy guardrails using Infrastructure as Code (IaC) linting and scanning tools (e.g., Checkov, Tfsec, OPA/Rego) to catch misconfigurations before they reach production.</li> <li><strong>Security Product Deployment:</strong>&nbsp;Automate the baking of&nbsp;<strong>EDR</strong>&nbsp;agents, vulnerability scanners, and monitoring tools into base machine images (AMIs, Azure Golden Images) and containerized base environments.</li> <li><strong>Vulnerability &amp; Remediation Pipelines:</strong>&nbsp;Operationalize vulnerability management by building automated workflows that ingest findings from cloud security tools, prioritize them based on risk, and route them to engineering backlogs (e.g., Jira tracking).</li> <li><strong>Logging &amp; SIEM Integration:</strong>&nbsp;Configure and automate the pipeline delivery of application, container, and infrastructure logs to central logging repositories and&nbsp;<strong>SIEM</strong>&nbsp;systems for real-time threat hunting.</li> <li><strong>D