Bastion Talent is retained by a specialist cybersecurity firm working in critical infrastructure to fill this role. Our client works with large organisations — operators, governments and enterprises — to find and fix serious security weaknesses. The client’s identity is shared with shortlisted candidates under NDA.
The role
Embed security into the way the client builds and ships. You will own secure CI/CD, infrastructure-as-code and the guardrails that let engineering and research teams move fast without compromising the security of critical infrastructure.
Key responsibilities
- Build security into CI/CD pipelines: SAST, DAST, dependency and container scanning, and secrets management.
- Harden infrastructure-as-code (Terraform, Ansible) and enforce secure-by-default baselines.
- Automate vulnerability management, patching and compliance across Linux fleets and containers.
- Set up security monitoring, logging and alerting; support detection and incident response.
- Manage secrets, workload identity and least-privilege access (ZTNA).
- Partner with engineering and research teams to ship securely without slowing them down.
What we’re looking for
- Solid DevOps foundation (Linux, Docker, Kubernetes, CI/CD) with a genuine security focus.
- Experience with SAST/DAST/SCA and container and image scanning tooling.
- Infrastructure-as-code (Terraform, Ansible) and pipeline tooling (GitHub Actions, Jenkins or GitLab CI).
- Scripting in Bash, Python or Go.
- Familiarity with cloud and bare-metal security, secrets management and ZTNA.
- Bonus: telecom or core-network exposure.
- Fluent English (mandatory); French optional.
Engagement & location
This position is fully remote within Europe (CET overlap preferred). Unless otherwise stated, it can be structured either as a freelance / contract engagement or as full-time employment — whichever suits you.
About the client
Our client is a specialist cybersecurity firm and a recognised leader in offensive security for critical infrastructure. They help large organisations — operators, governments and major enterprises — find and fix serious weaknesses in the systems that keep essential services running, pairing hands-on security assessment with their own detection and analysis tooling. The team is small, highly technical and fully distributed across Europe.
Hiring process
- Intro call (10–20 min)
- Manager call (30 min)
- Capability exercise
- Leadership call (30 min)