Skip to main content

Senior Java DevSecOps Engineer

Job Description

Introduction to the job

We are looking for a hands-on DevSecOps Engineer with Software Development skills to join our central DevSecOps team and help scale security across our software development lifecycle. In this role you will own and evolve shift-left security practices, maintain security scanning pipelines, govern Kubernetes golden images, help product teams stay on top of vulnerabilities through near real-time reporting and remediate 3rd-party dependency vulnerabilities. 

You will work closely with our Senior DevSecOps Engineer and grow your practical security knowledge on the job - deep security expertise upfront is not a prerequisite. What matters most is a strong drive and ability to learn, a DevOps engineering background with software engineering skills, a genuine curiosity about security, and the ability to build and maintain automated tooling.

Role and responsibilities

  • Own and maintain security scanning pipelines for product releases using Atlassian Bamboo with Bitbucket and Azure DevOps.
  • Develop and maintain shift-left security scanning with near real-time vulnerability reporting delivered directly to product teams.
  • Own, maintain, and enforce the use of golden base images in Kubernetes tenants — ensuring they are always up to date, security-hardened, and automatically propagated to consumer microservices.
  • Serve as the administrator and business owner of our Application Security Posture Management (ASPM) tooling.
  • Actively contribute to and maintain our internally developed lifecycle and vulnerability management portal (Python, Docker, Kubernetes, Helm).
  • Integrate and operate SAST, DAST, and SCA tools (e.g., SonarQube, Checkmarx, OWASP ZAP, BlackDuck, Trivy) in CI/CD pipelines.
  • Configure and maintain JFrog Xray as the artifact security scanner - including security scan triggers, scanning policies, and integration with JFrog Artifactory.
  • Ensure best practices in containerized environments (Docker, Kubernetes) including deployment and runtime security configurations.
  • Collaborate with development, operations, and security teams to embed security awareness and share guidance on secure engineering practices.
  • Investigate, remediate, and verify 3rd-party dependency vulnerabilities across the product codebase - including updating Maven dependencies, validating fixes with JUnit tests, and triggering qualification pipelines in Bamboo to confirm nothing is broken.

Education and Experience

  • A Bachelor or Master degree in a technical field, or equivalent professional experience.
  • 4+ years of experience in DevOps, DevSecOps, or a closely related engineering role.
  • Hands-on experience with CI/CD pipelines - Atlassian Bamboo, Bitbucket, and/or Azure DevOps experience is a strong advantage.
  • Python development skills; ability to maintain and extend existing tooling.
  • Working knowledge of Java and Maven - the product codebase is predominantly Java/Maven based. You should be able to update dependencies, resolve version conflicts, and run JUnit test suites to verify security fixes.
  • Familiarity with triggering and interpreting Bamboo qualification pipelines as part of the change verification process.
  • Experience with containerized environments: Docker, Kubernetes, Helm.
  • Comfort working with shell scripting (bash) and version control (git).
  • Hands-on experience or strong interest in AI-assisted development tools — including GitHub Copilot, AI agents, and agentic development workflows.

Nice to have

  • Knowledge of security standards and frameworks (e.g., CIS, MITRE, NIST, ISO 27001, EU CRA).
  • Experience with ASPM platforms or security posture tooling.
  • Familiarity with secrets management tools (e.g., HashiCorp Vault, GitGuardian).
  • Infrastructure-as-code experience (e.g., Terraform, Ansible).
  • Experience with SIEM tools (e.g., Splunk, ELK) for security monitoring.
  • CISSP, Security+, or equivalent certification is a plus but not required.
  • Familiarity with SAST, DAST, and SCA tooling (e.g., SonarQube, Checkmarx, OWASP ZAP, Trivy).
  • Familiarity with JFrog Xray and Artifactory for artifact security scanning and policy management.

Skills

  • Strong collaboration and communication skills - able to work effectively with both technical and non-technical stakeholders.
  • Genuine enthusiasm for combining security with DevOps practices.
  • Open to learning: willing to grow practical security knowledge guided by the team.
  • Curiosity-driven mindset - you keep up with tooling trends, including AI-driven development practices.
  • Good problem solver - able to translate operational security challenges into clear, maintainable automated solutions.
  • Team player with a pragmatic delivery focus

Other information

Please add your complete, recent CV and cover letter for this position to your application. We can't process your application without the above-mentioned documents. Need to know more about applying for a job at ASML? Read our frequently asked questions.


This position requires access to controlled technology, as defined in the United States Export Administration Regulations (15 C.F.R. § 730, et seq.). Qualified candidates must be legally authorized to access such controlled technology prior to beginning work. Business demands may require ASML to proceed with candidates who are immediately eligible to access controlled technology.


Inclusion and diversity

ASML is an Equal Opportunity Employer that values and respects the importance of a diverse and inclusive workforce. It is the policy of the company to recruit, hire, train and promote persons in all job titles without regard to race, color, religion, sex, age, national origin, veteran status, disability, sexual orientation, or gender identity. We recognize that inclusion and diversity is a driving force in the success of our company.


Need to know more about applying for a job at ASML? Read our frequently asked questions.

Optimize Your Resume for This Job

Get a match score and see exactly which keywords you're missing

Optimize Resume

Job Details

Category
Security
Employment Type
Full Time
Location
Veldhoven, Netherlands
Posted

About ASML

ASML is the world leader in lithography systems for the semiconductor industry, manufacturing complex machines critical to the production of integrated circuits.

Found this role interesting?

Senior Java DevSecOps Engineer
ASML
Apply