Careers

Senior DevSecOps Engineer

Location
Lisbon (Hybrid)
Experience
Min. 4 years

Skills

DevSecOps DevOps JFrog Artifactory Jenkins SonarQube Docker Kubernetes CI/CD
Description

About Us

BySix Engineers the future and drives innovation. We are more than just a standard software engineering company, we believe that true impact comes from combining technical expertise with human values. That's why we reflect that in our approach - technology is not the end goal, but the enabler.

Why Us?

🫸 Multidisciplinary team
📒 Training on demand
💴 Attractive salary and benefits package
📈 Career progression plans
👌 And amazing get together events

What are we looking for?

We are looking for a Senior DevSecOps Engineer with:

  • Proven experience in DevSecOps, application security, or DevOps engineering.
  • Strong hands-on experience with CI/CD pipelines and secure delivery practices.
  • Experience with GitHub Enterprise & GitHub Advanced Security, SonarQube configuration and governance, JFrog Artifactory and Xray
  • Strong understanding of vulnerability management and secure artifact lifecycle.
  • Experience working directly with development teams in remediation efforts.
  • Knowledge of Git workflows, release management, and deployment governance.
  • Experience in regulated or large enterprise environments.
  • Experience with CI/CD & Engineering: GitHub Actions, Azure DevOps, Jenkins, GitLab CI, pipeline-as-code, automated security gates.
  • Experience with application Security: SAST, SCA, secrets management, OWASP Top 10, vulnerability triage and remediation.
  • Cloud & Containers: Docker/OCI, Kubernetes/OpenShift, container registry and image governance.
  • Engineering Practices: GitFlow, branching strategies, pull request governance, artifact immutability and traceability.

What do we expect from you?

  • Define and implement secure DevSecOps architectures and CI/CD security controls (SAST, SCA, secrets, containers, SBOM, quality gates).
  • Integrate and manage security tools (GitHub Advanced Security, SonarQube, JFrog) within development workflows.
  • Establish secure artifact management and controlled promotion across environments.
  • Manage vulnerabilities end-to-end: analysis, prioritization, remediation support, and reporting.
  • Configure GitHub security features and enforce repository and PR governance standards.
  • Maintain code quality and security policies using SonarQube.
  • Secure artifact repositories and dependencies using JFrog Artifactory and Xray.
  • Define branching strategies and enforce secure release and deployment controls.
  • Ensure traceability, auditability, and proper governance across the delivery lifecycle.
  • Support and enable development teams through guidance, training, and practical secure implementations.

Are you ready?

If you're ready to make a real impact by leveraging cutting-edge technology and fostering human-centric solutions, BySix is the place for you. Together, we'll drive innovation and create lasting business value.

Note: BySix is an equal opportunity employer. All applicants will be considered and analyzed regardless of ethnicity, religion, gender identity, sexual orientation, national origin, age, or disability status.

Hey there, apply now
to join our team!
Upload your CV to automatically fill the form below.
Introduction
Professional skills

No skills available

Personal skills

No skill available

Beginner - Basic understanding. Limited ability to use the technology without guidance.
Basic - Able to perform simple tasks and apply foundational concepts with occasional support.
Intermediate - Competent in using the technology for regular tasks. Can troubleshoot common issues independently.
Advanced - Strong proficiency. Capable of handling complex tasks and optimizing workflows effectively.
Expert - Complete mastery. Able to teach, innovate, and implement advanced solutions with the technology.
Languages

No language available

Experience

No experiences available

New experience
Education

No education available

New course
Certifications
Other info