Hiring.Camp

DevSecOps Specialist (regular/senior) (She/He/They)

Accenture

·

Today

Location
Warsaw, Sienna 39, Poland · Lodz · Krakow · Wroclaw · Katowice
Workplace
Remote
Type
Full-time
Seniority
Senior
Source
Workday

Description

WHO WE ARE: 

The Cyber Security team, part of Accenture Security, supports organizations in building secure, resilient, and scalable security capabilities across complex enterprise technology landscapes — integrating security into software development, cloud adoption, digital transformation, and technology modernization so that security by design and security by default are reflected in how systems are actually built and operated, not only in policy. 

We act as trusted advisors to some of the world's leading organizations, helping them define pragmatic security operating models, improve security maturity, and align cybersecurity capabilities with their business and technology objectives. Working at the forefront of the industry means constant exposure to complex, high-stakes security challenges and the latest technologies — across banking, manufacturing, healthcare, retail, and public sector, each with its own regulatory context and technical scale. 

As part of a global security leader, you work on engagements that span the full breadth of modern enterprise security — from securing AI-enabled systems and cloud-native architectures to embedding security into large-scale digital transformation programmed. The variety of clients, industries, and technology stacks means you are continuously challenged, and the depth of expertise around you means you are never navigating that alone.

THE WORK: 

  • Design, build, and run secure CI/CD pipelines. Automate the security steps so they scale instead of becoming someone's manual chore — with Ansible, Azure DevOps, Jenkins, GitLab, Argo CD — and integrate scanning tooling such as Snyk, Veracode, Checkmarx, OpenText, or WIZ so that results are trusted and acted on rather than muted. 

  • Secure public cloud and container environments. Run security assessments of hybrid solutions, help teams harden Azure, GCP, or AWS and their microservices platforms for compliance and resilience, and support migration and transformation work where security has to move into an entirely new technology layer. 

  • Review APIs, source code, and deployment processes in depth to find what is exploitable and get it fixed — then put API security platforms and real-time monitoring in place so the next problem surfaces without anyone going looking. 

  • Threat-model applications and design the fix. Analyse how a system could be attacked, propose mitigations the team can realistically ship, and work with design and development teams to embed security from the start of the SDLC. 

  • Work on the security of AI-driven systems across their whole lifecycle, from design and development through to deployment — and use AI-driven approaches and tooling to make security work faster than it used to be. 

  • Be the person clients take advice from. Act as a trusted advisor on secure design principles and where cloud and application security is heading, and help clients raise their DevSecOps and AppSec maturity with methods that fit how they actually work. 

Flexible: The work location for this role may include a mix of working remotely, onsite at a client or in an Accenture office - depending on specific project circumstances.

With all our roles, there is some in-person time for collaboration, learning and building relationships with clients, peers, leaders, and communities. As an employer, we will be as flexible as possible to support your specific work/life needs.

WHAT’S IN IT FOR YOU:

  • Work on international cybersecurity transformation programmes for some of the world's leading organisations, on security problems that are genuinely complex and unsolved at their end — with the support of a team of more than 150 cybersecurity specialists in Poland, and thousands more across the world. 

  • Breadth you cannot get in-house. In a single year you see how organisations across banking, manufacturing, healthcare, retail, and public sector approach the same DevSecOps and cloud security challenges — and where they fail. That range takes far longer to accumulate on a single internal team. 

  • Constant exposure to emerging technologies, current tooling, and evolving practice — helping clients securely adopt what is new while managing risk across legacy, hybrid, and modern environments. 

  • Room to set direction and grow as a trusted advisor. On most engagements you are the person defining what good looks like for a client's pipeline or cloud platform — leading security discussions with technical, operational, and senior stakeholders, not implementing someone else's definition. 

  • Collaborate with a diverse team of cybersecurity experts in an environment where ideas are welcome rather than tolerated, focused on innovation, continuous learning, and practical business outcomes. 

  • A wide catalogue of development opportunities: technical, soft-skills, and language training, e-learning platforms, GenAI training, and security certifications — open to everyone who wants to grow. 

HERE’S WHAT YOU’LL NEED: 


We are looking for candidates with a solid foundation across the areas below. Hands-on experience and a working grasp of the core concepts is the baseline — specialization and depth can be developed from there. 

  •  A real engineering or IT background. Several years in IT, DevOps, platform engineering, or a related role. You have built, run, or automated systems, and you know what breaks in production because you have been there when it did. 

  • Security fundamentals you understand rather than memorized. Confidentiality, integrity, and availability — what they mean for a running system and what breaks them. How applications get attacked: SQL injection, XSS, CSRF, and the classes of problem behind the OWASP Top 10. What encryption, hashing, and secrets management are for and how people misuse them. If you can explain to a developer why a control exists, that is what we mean. 

  • Hands-on experience with CI/CD pipelines. At least one system — Azure DevOps, GitLab CI, Jenkins, GitHub Actions, Argo CD, or similar. You have built or maintained pipelines rather than only read about them, and Git is a daily tool rather than a concept. 

  • Experience with one public cloud. Azure, GCP, or AWS. One, used in earnest, is worth more here than three from a slide. 

  • A basic understanding of containers and orchestration. Docker, and Kubernetes or OpenShift at the level of knowing how a workload gets scheduled, exposed, and given credentials. 

  • Enough code to automate and to review. Scripting you can actually write — Python, Bash, or similar — and the ability to read someone else's Java, C#, JavaScript, or Go well enough to reason about what it does and where it goes wrong. You do not need to be a professional developer today. 

  • Language requirements. Professional proficiency in both English and Polish is required. English is the primary language for client-facing work — including findings communication, workshop facilitation, and presentations to senior stakeholders. Polish is the language of day-to-day team operations. Proficiency in both is a non-negotiable requirement for this role. 

  • Ways of working. Strong communication skills, including the ability to translate complex technical findings into clear, actionable recommendations for non-technical audiences. Curiosity and adaptability — comfortable reading unfamiliar documentation, prototyping something rough to see if it works, and being the person expected to define what "good" looks like in a domain you met three weeks ago. A proactive, ownership-oriented mindset, given the pace of change in the DevSecOps landscape. 

 

Seniority levels 

Regular (approximately 2–5 years of relevant experience). Candidates at this level are expected to independently deliver defined workstreams — building and securing pipelines, integrating and tuning scanning tools, reviewing deployments and cloud configuration, and communicating findings to client technical teams. A working knowledge of the OWASP Top 10 and secure coding principles is expected, with continued development across the broader requirements list. 

Senior (approximately 5+ years of relevant experience). Candidates at this level are expected to lead workstreams, provide technical direction, and mentor junior colleagues. This requires demonstrated depth in at least one domain — cloud platform security, pipeline and automation engineering, containers, API and application security, or AI security — alongside sufficient breadth to engage credibly across all areas and present confidently to senior client stakeholders. 

 

Research indicates that some candidates, especially the most diverse ones, may hesitate to apply for positions if they don't meet all requirements. If you believe you possess the necessary skills, even if not meeting every requirement, we wholeheartedly encourage you to submit your application.
 

Years of experience are provided as guidance only and are not a strict eligibility criterion. Candidates transitioning from development, platform engineering, SRE, or in-house security roles are encouraged to apply — if you can demonstrate the relevant skills and hands-on experience, we will work out where you fit. Seniority is assessed based on demonstrated capability during the interview process, not determined at the CV screening stage. 

BONUS POINTS IF YOU HAVE: 

Any one of these is a plus, and we value the individual experience you bring over the number of lines you tick. For a Regular role none of them is required. For a Senior role we expect real depth in at least one. 

  • Practical experience with SAST, DAST, and SCA tools and integrating them into CI/CD pipelines so that the pipeline stays fast enough that nobody wants to bypass it. 

  • DevSecOps tooling from vendors such as Snyk, WIZ, IriusRisk, CrowdStrike, Aqua Security, Checkmarx, OpenText, Veracode, or Argo CD. 

  • Authentication, authorisation, and session management — SAML, OAuth, SSO, and how identity actually gets wired into an application. 

  • SSDLC processes end to end, and the ability to integrate security into DevOps pipelines rather than alongside them. 

  • REST API technology and API Gateway concepts, and application and API security principles across secure design, development, and deployment. 

  • Conducting security reviews of API designs, source code, and deployments — and implementing API security platforms and monitoring solutions. 

  • Threat modelling, with mitigation strategies robust enough to survive contact with a delivery schedule. 

  • Web application security frameworks and taxonomies in practice: OWASP Top 10, secure coding practice, and MITRE. 

  • Infrastructure as Code and configuration management: Terraform, Ansible, or similar. 

  • Foundational knowledge of AI model architectures — memory context, prompt engineering, and integration with external services — and awareness of AI-related security risks such as prompt injection, data leakage, and model misuse. 

  • Building and integrating solutions using Large Language Models — Azure OpenAI, LangChain, REST APIs, embeddings, vector databases. 

  • Writing scripts, prototypes, and micro-applications to solve a problem quickly, alongside good working knowledge of at least one programming language — Java, .NET/C#, JavaScript, Go, or Python. 

  • Prior consulting or client-facing experience. 

  • A development, platform engineering, SRE, or in-house security background. 

  • Security or cloud certifications — we care about what you can do, and we co-finance certifications once you are here. 

WHAT WE OFFER:

  • Permanent employment contract.

  • Individual support of a People Lead and a specific path of professional development, as well as the possibility of a session with a Coach.

  • A wide training package (soft, technical, and language training offer, access to the e-learning platforms, Gallup test, GenAI training, possibility of co-financing courses, and certification).

  • Employee Assistance Program - legal, financial, and psychological consultations.

  • Accenture employees eligible for the Employee share purchase plan automatically become eligible for quarterly dividends if they own company shares.

  • Paid employee referral program.

  • Private medical care, life insurance.

  • Access to the Worksmile platform (possibility of using a wide range of products and services, including the Multisport card).

WHAT WE BELIEVE:

Accenture does not discriminate employment candidates on the basis of race, religion, color, sex, age, disability, national origin, political beliefs, trade union membership, ethnicity, denomination, sexual orientation or any other basis impermissible under Polish law.

All our leaders are committed to building a better, stronger and more durable company for future generations to create positive, long-lasting change. Inclusion and diversity are fundamental to our culture and core values. Our rich diversity makes us more innovative and creative, which helps us better serve our clients and our communities.

Our position as partner to many of the world’s leading businesses, organizations and governments affords us both an extraordinary opportunity and a tremendous responsibility to make a difference. Sustainability is one of our greatest responsibilities, which we embed it into everything we do and for everyone we work with.

Clicking apply I hereby express my consent to process my personal data included in my job offer by Accenture Sp. z o.o. or any other entity of the Accenture group for recruitment purposes, and that it is a data controller within the meaning of GDPR. More information about Accenture (and if necessary also its representative) can be found here: https://www.accenture.com/pl-pl/privacy-policy

#LI-EU

#PLSEC

About Accenture

Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.

Visit us at www.accenture.com 

Equal Employment Opportunity Statement

We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, sexual orientation, gender identity or expression, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.

Skills

PythonJavaScriptJavaAWSAzureGCPDockerKubernetesTerraformAnsibleJenkinsCI/CDSQLGitGitHubGitLabCybersecurityRESTOAuthDevOps