HCLTech – Hungary

Senior Engineer - Azure Active Directory

HCLTech – Hungary  •  Onsite  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Job Summary

ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.

Key Responsibilities

ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.

Skill Requirements

ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.

Other Requirements

ROLE SUMMARY Owns vulnerability remediation in libraries used within CI/CD pipelines and build infrastructure. Coordinates with application engineering teams to lift dependency hygiene without breaking the SDLC. KEY RESPONSIBILITIES ■ Identify and remediate vulnerable dependencies across pipeline libraries (Maven, npm, pip, Go modules, etc.). ■ Maintain SCA (Software Composition Analysis) tooling and the upgrade backlog. ■ Coordinate with application engineering teams on breaking-change upgrades. ■ Integrate vulnerability gates into the SDLC where Mythos becomes central authority. ■ Apply runtime mitigations (WAF rules, RASP) for high-risk libraries pending upgrade. ■ Maintain SBOM (Software Bill of Materials) discipline across the estate. REQUIRED TECHNICAL SKILLS ■ Strong understanding of SCA / dependency management across major language ecosystems. ■ Hands-on experience with tools such as Snyk, Black Duck, Sonatype, Dependabot. ■ CI/CD pipeline fluency: Jenkins, GitLab CI, GitHub Actions, Argo. ■ Familiarity with SBOM standards (SPDX, CycloneDX). ■ Coordination with development teams on upgrade and remediation patterns. PREFERRED / NICE TO HAVE ■ Prior experience in DevSecOps or AppSec in a regulated environment. ■ Container security: image scanning, base-image hardening, distroless. ■ Knowledge of supply-chain attack patterns and mitigations (SLSA, in-toto). EXPERIENCE & CERTIFICATIONS ■ 5+ years DevSecOps / AppSec / engineering with security focus. ■ Certifications: GIAC GCSA, CSSLP, or equivalent. SOFT SKILLS ■ Bridge builder between security and engineering. ■ Pragmatic — recognises when to upgrade vs mitigate. ■ Strong written communication to engineering audiences.

HCLTech – Hungary

About HCLTech – Hungary

HCLTech is a global technology company, home to more than 226,600 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending September 2025 totaled $14.2 billion. To learn how we can supercharge progress for you, visit hcltech.com.

Industry
IT & Software
Company Size
51-200 employees
Headquarters
Budapest, HU
Year Founded
2006
Social Media