Rejobs

DevSecOps工程师

加入Camlin集团,担任克拉科夫的DevSecOps工程师。该职位负责执行ISMS安全流程,支持嵌入式系统的安全开发、测试与部署。享受混合办公、竞争力薪资及私有医疗和健康计划等福利。

混合 全职 UTC+02:00 3 天前更新

在 ats.rippling.com 申请

检查您的收件箱。

用手机?稍后可以在电脑上申请。

Camlin is a global technology leader that operates with the vision of bringing revolutionary products to life for a wide range of industries, including power and rail, and also has interests in a number of R&D projects in a variety of scientific sectors.

At Camlin we believe in high quality engineering and design, allowing us to develop market leading products and services. In short, we love creating value for our customers by solving difficult problems. As of now, Camlin operates in over 20 countries worldwide.

We are looking for a DevSecOps Engineer (or a DevOps Engineer with a strong security mindset) to strengthen our Embedded Systems Unit.

In this role, you will collaborate closely with embedded development teams and our Information Security Management System (ISMS) team to ensure that our industrial and field‑deployed products meet cybersecurity requirements defined in CRA, RED, and IEC 62443.

You will not be responsible for creating governance processes; instead, you will execute and apply the workflows and policies defined by ISMS, ensuring they are consistently implemented across development, testing, manufacturing, and deployment environments.

You will support the full lifecycle of our embedded systems, toolchains, factory test infrastructure, and backend services.

IMPORTANT NOTE: Although this role is in a hybrid way of working and remote friendly, at least One Interview from selection process will require to be onsite in our Krakow office.

Responsibilities

Secure Development & Compliance

  • Execute secure development workflows defined by ISMS. Support developers in applying secure coding, secure update mechanisms, access‑control, and documentation practices aligned with CRA/RED/IEC 62443.

Vulnerability Scanning & Reporting

  • Run SCA / SAST / DAST tools (e.g., SonarQube, JFrog XRay) within CI/CD pipelines.
  • Prepare actionable vulnerability reports aligned with CRA and IEC 62443 vulnerability‑handling requirements.

Security Testing

  • Perform or coordinate grey‑box or white‑box security tests on firmware and backend releases.
  • Validate system behaviour against RED 3.3(d/e/f) cybersecurity safeguards and IEC 62443 component requirements.

Software License & SBOM Reporting

  • Generate and maintain Software Bills of Materials (SBOMs).
  • Produce OSS license compliance reports to support CRA transparency and supply‑chain documentation.

Security Tooling for Production & Field Devices

  • Operate and maintain firmware signing pipelines.
  • Handle certificate provisioning, key management tools, and secure device onboarding workflows defined by ISMS.
  • Support secure manufacturing workflows such as device identity injection and protected configuration handling.

Factory Test Systems

  • Own and improve factory self‑tests, diagnostics, and manufacturing server infrastructure.
  • Add new dashboards, performance metrics, and manufacturing KPIs.
  • Implement data visualization, alerting, and monitoring in tools such as Grafana.

Database & Backend Infrastructure

  • Maintain and further develop the manufacturing database.
  • Implement structured schema versioning.
  • Develop APIs to replace direct SQL access and improve data integrity.
  • Optimize database structure, queries, and overall performance.

CI/CD & Automated Deployment

  • Maintain secure, reproducible CI/CD build and release pipelines for embedded firmware and backend services.
  • Manage deployment workflows, including environment provisioning, artifact signing, and release traceability.

Required Skills & Qualifications

Technical Skills

  • Familiarity with SCA/SAST/DAST tools such as SonarQube, JFrog XRay, or similar.
  • Understanding of SBOM standards (CycloneDX, SPDX).
  • Programming in Python, Node.js.
  • Experience with SQL databases and API design.
  • Practical knowledge of monitoring and observability tools (Grafana, Prometheus, Loki).
  • Ability to maintain and troubleshoot factory automation systems and backend services.
  • Experience with Embedded Linux and Yocto

Cybersecurity & Standards

  • Understanding of cybersecurity principles relevant to embedded systems.
  • Awareness of CRA, RED cybersecurity requirements, and IEC 62443 concepts (zones, conduits, secure development lifecycle).
  • Willingness for executing ISMS‑defined processes (secure SDLC, vulnerability management, incident support).
  • Familiarity with secure communication protocols (TLS, certificate pinning, encrypted transport layers).

Desired Qualifications (Nice‑to‑Have)

  • Familiarity with CI/CD pipeline development in GitLab
  • Understanding of database architecture
  • Experience with Node.js
  • Hands‑on with Grafana

Benefits

  • Employment contract with competitive salary
  • Work in small, self-organized and autonomous development teams with the ability to choose technologies and best practices
  • Hybrid work model (office in Kraków)
  • Company Pension & Life Assurance Schemes
  • On-site parking (car and bike)
  • UoP with 80% author's rights tax relief
  • MyBenefit system with Multisport membership, private healthcare (Medicover)
  • Wellness programmes

Our Values

  • We work together
  • We believe in people
  • We won't accept the 'way it has always been done'
  • We listen to learn
  • We're trying to do the right thing

Equal Employment Opportunity Statement

Individuals seeking employment at Camlin are considered without regards to race, colour, religion, national origin, age, sex, marital states, ancestry, physical or mental disability, gender identity or sexual orientation.

薪资与福利

医疗保险 退休计划 带薪休假 身心健康

职位详情

发布时间
1 10月 2026
更新时间
1 10月 2026
工作类型
全职
工作地点
混合
领域
工作时间
UTC+02:00

关于 Camlin Group

公司概况

名称

Camlin Group

总部

英国利斯本

成立时间

大约25-30年前

规模

全球雇佣约500-1000人(来源: leadiq.com)。

他们的业务

Camlin Group 专注于优化电力网和铁路网络的工程解决方案。公司最初专注于电力网的监测和诊断设备,但随后扩展了其产品,包括低压故障管理、传感技术、数字分析以及针对电力和铁路网络的定制服务。这一演变涉及剥离非核心业务,以专注于高性能电网技术,确保他们在能源行业的创新前沿(来源: emeoutlookmag.com)。他们的产品在多个品牌下运营,包括Kelvatek,提供低压故障管理和网络可视化工具,整合来自Camlin和第三方设备的数据,以增强电网的韧性和性能(来源: emeoutlookmag.com)。目标市场包括电力公用事业和配电网络运营商,重点提供数据驱动的风险管理和运营效率洞察(来源: emeoutlookmag.com)。Camlin的竞争优势在于其长期合作伙伴关系和创新的良好记录,使其在向更具韧性和高效的能源电网转型中处于领先地位(来源: emeoutlookmag.com)。

项目与业绩

Camlin Group 在英国配电网络中部署先进监测和诊断解决方案方面建立了强大的业绩记录。虽然没有详细列出具体项目名称和能力,但公司以开发针对独特客户挑战的定制解决方案而闻名,这些解决方案可以扩展以惠及其他公用事业。他们的持续努力包括在美国专注于资产监测,利用各种传感器和创新软件来支持在劳动力短缺和供应链中断等挑战下的决策(来源: emeoutlookmag.com)。此外,Camlin与英国和美国的主要公用事业建立了长期合作伙伴关系,其中一些关系持续超过二十年,这突显了他们对协作创新和可持续发展的承诺(来源: emeoutlookmag.com)。他们的地理存在主要在英国,并在美国市场有显著扩展,反映了他们对全球公用事业挑战的适应能力(来源: camlingroup.com)。

近期发展

近年来,Camlin Group 积极参与行业活动,如Distributech 2025,展示其在电力系统技术和传感器创新方面的进展。这一参与突显了公司在美国市场的增长轨迹,特别是在资产管理解决方案方面(来源: youtube.com)。此外,公司关键人物Peter Cunningham被列入2023年爱尔兰OMB 100,庆祝Camlin在提供创新工程和客户解决方案方面的25年里程碑(来源: insidermedia.com)。尽管最近没有报告重大合同或收购,但公司已战略性地剥离非核心单位,以更清晰地专注于核心优势,这为员工和客户提供了明确性(来源: emeoutlookmag.com)。

在这里工作

Camlin Group 提供多样化的职位,涵盖研究、工程、制造、客户支持和软件开发等多个部门。公司特别关注与低压设备和资产监测相关的技术职位,反映了其在这些领域的创新和增长承诺(来源: emeoutlookmag.com)。在其利斯本总部和美国业务的招聘似乎都在积极进行,推动公司扩展的努力以及对能源行业熟练专业人士的需求(来源: camlingroup.com)。公司文化强调创新作为核心价值,促进与客户的长期合作关系,并确保内部稳定,特别是在最近的战略变更之后(来源: emeoutlookmag.com)。虽然没有具体的员工福利记录,但对以目标为导向的方法的关注表明了在人员、地球和绩效之间平衡增长的承诺(来源: emeoutlookmag.com)。

您的 LinkedIn 人脉

在 LinkedIn 上查看您在 Camlin Group 的联系人,申请时善用您的人脉。

查看人脉

更多 智能电网 相似职位

DevSecOps工程师
Camlin Group