Twoday Denmark

Senior DevSecOps Engineer – Kubernetes & Software Supply Chain Security

Twoday Denmark Copenhagen, Capital Region of Denmark, Denmark

IT Services and IT Consulting · 1,001-5,000 employees

11 h ago
kubernetes Senior (5-10 yrs) Full-time Denmark
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will implement and automate security controls across CI/CD pipelines, Kubernetes platforms, and production environments. Additionally, you will secure the software supply chain and support runtime threat detection and incident response.

What they look for

Kubernetes DevSecOps CI/CD Software supply chain security SAST SCA Infrastructure as Code Terraform Ansible Python Bash PowerShell Vault Linux hardening Vulnerability management Incident response

Requirements

The ideal candidate has practical DevSecOps experience with a focus on Kubernetes security, CI/CD automation, and software supply chain protection. You must be fluent in both Danish and English and capable of working onsite in Copenhagen.

Benefits

Professional freedom Technical challenges Opportunities for professional development

Full description

Twoday is the leading digital transformation partner in Northern Europe with a global presence. With approximately 3,000 technologies, we collaborate with the most admired private and public organizations to deliver cutting-edge digital solutions. Our deep industry expertise spans Data & AI, software development, digital experiences, and business applications. Operating across the Nordics and Lithuania, our team generated a revenue of 280 million euros in 2023. We serve over 8,000 customers, supporting their digital transformation journeys.

Senior DevSecOps Engineer – Kubernetes & Software Supply Chain Security

Permanent position at Twoday | Copenhagen

Twoday is a leading digital transformation partner in Northern Europe, with approximately 3,000 specialists delivering digital solutions to public and private organisations.

We are looking for an experienced, hands-on DevSecOps Engineer to strengthen security across development pipelines, Kubernetes platforms and production environments for one of our major public-sector clients.

This is a role for someone who implements, automates and maintains security controls – not someone who only advises on them.

Your role

You will work alongside an experienced operations team, embedding security into development, deployment and daily operations while helping the team adopt secure, sustainable engineering practices.

Your responsibilities will include:

  • Implementing automated security controls across CI/CD pipelines, including SAST, SCA, secret scanning, container scanning and Infrastructure as Code (IaC) scanning.
  • Securing the software supply chain through SBOM generation (CycloneDX/SPDX), artefact signing and verification (e.g. Sigstore/cosign), SLSA principles and secure branch, review and release processes.
  • Securing CI/CD pipelines and runners using least-privilege principles.
  • Implementing Kubernetes security controls, including admission control, policy-as-code, Pod Security Standards, RBAC, network policies and secrets management.
  • Hardening Linux and Windows environments and managing vulnerabilities from identification through to remediation.
  • Supporting runtime threat detection, security monitoring, incident response and forensic investigations.
  • Establishing security frameworks for AI-assisted development and autonomous AI agents, including controlled permissions, review gates, traceability and protection against prompt injection.
  • Documenting security controls for compliance and audit purposes, while sharing knowledge and transferring solutions to the internal team.

What we're looking for

You have practical DevSecOps experience and can demonstrate that you have implemented security controls in real development and production environments.

We are particularly interested in experience with:

  • Software supply chain security: SAST, SCA, secret scanning, SBOM, artefact signing and verification, container and IaC scanning.
  • CI/CD and automation: GitLab CI, GitHub Actions or similar, secure pipelines and runners, Terraform, Ansible and scripting with Python, Bash or PowerShell.
  • Kubernetes security: Kyverno, OPA Gatekeeper or similar, admission control, Pod Security Standards, RBAC, network policies and secrets management using Vault, External Secrets or equivalent.
  • Platform security: CIS-based Linux hardening, Windows Server hardening and runtime detection tools such as Falco.
  • Vulnerability management and incident response: Risk-based remediation, logging, SIEM solutions such as ELK or Wazuh, incident handling and forensics.
  • AI security: Security controls for AI-assisted and agentic workflows, including autonomy boundaries, human review, prompt injection protection and secure credential handling.
  • Compliance: NIS2, ISO 27001/27002 and GDPR.

Experience with virtualisation platforms such as Proxmox is useful. Experience from the public sector or organisations subject to NIS2 is an advantage, but not essential.

The environment follows an open-source-first approach with EU-based infrastructure. Experience with US hyperscalers is not relevant to this assignment.

You must be fluent in Danish and English, both written and spoken, and able to work onsite full time in Copenhagen.

Who you are

You are hands-on, security-conscious and pragmatic. You see security as an enabler rather than an obstacle, prioritise risks sensibly and enjoy helping experienced engineers strengthen their security practices. You take ownership, document your work and build solutions that others can maintain.

Why Twoday?

At Twoday, you will work with skilled colleagues on complex, business-critical solutions that make a real difference. We offer a collaborative environment with professional freedom, technical challenges and opportunities to develop your expertise.

Interested?

We would love to hear from you. Apply today and help us build secure, reliable and future-ready digital platforms.

Diversity & inclusion

Do you not meet all the requirements? Studies show that women and minorities are less likely to apply if they don’t meet every qualification. At Twoday, we are committed to building an inclusive workplace where everyone is welcome.

If this role excites you, we encourage you to apply.

Similar roles