AI SDLC Governance Software Engineer

πριν 21 ώρες

Athens, Attica, Ελλάδα code4thought Πλήρης απασχόληση 30.000 € - 45.000 € Σύμβαση
code4thought
Athens (hybrid)
Full-time
€30,000–€45,000 gross/year Reports to: Head of Delivery
Split: ~70% client-facing consulting, ~30% platform engineering

About us
At code4thought we believe that technology doesn’t just support organisations. It shapes them. As such we turn its influence into evidence, insight and better decisions. We do this by analyzing source code and software architecture against ISO 25010 and turn the results into insight both engineers and executives can act on. We are now ramping up our delivery and advisory capabilities by building an Agentic Platform that makes static analysis findings traceable, explainable and actionable — from a single pull request to a whole portfolio. The role You spend most of your week in front of clients: analysing findings from static code analysis, separating signal from noise, tracing issues to root cause, and explaining them to the people who must act — developers in a code walkthrough, managers weighing effort against risk, executives deciding where to invest. The rest of your time you build the Agentic Platform that produces those explanations. The consulting makes the platform good; the platform makes the consulting scale.

What you'll do
Assess static analysis, architecture and security findings across large enterprise codebases — triage them, remove the false positives, trace them to root cause. Run findings walkthroughs with development teams and handle pushback with evidence, not authority. Present to engineering managers and C-level, reframing code-level risk as cost and business exposure. Build remediation roadmaps: what to fix, in what order, at what effort. Contribute to the Agentic Platform — AI-assisted tracing of findings through the code, root-cause hypotheses, and explanations tuned to each audience. Help ensure every claim the platform makes is traceable to evidence in the code. You'll be the one defending its output in front of a client. Assess the risk profile of AI-generated code and help clients define review gates for AI-assisted changes. What you bring 3-5+ years of professional software engineering with real production ownership. Genuine client-facing ability — you can run a workshop, hold a room, and write something a CTO will read. This is the core of the job, not a bonus. Strong Python (or equivalent) and the ability to reason about codebases in languages you've never shipped in. Hands-on experience with static analysis / code quality / security tooling (Sigrid, SonarCube, Checkmarx, Semgrep, SAST/SCA). Practical experience building with LLMs: prompting, tool calling, retrieval, agents — and evaluating whether the output is right. Solid grasp of software quality fundamentals: maintainability, coupling, technical debt, architectural erosion. Excellent English. Based in Athens or — this is not a remote role. Nice to have: consulting or pre-sales (on forming solutions) experience
program analysis internals (ASTs, call graphs, data flow)
application security
agent evaluation
EU AI Act, ISO/IEC 42001 or ISO 29119-11.

What we offer
€30,000–€45,000 gross depending on experience, private health insurance, training and conference budget, hybrid working, TIER-1 clients across Europe, and real ownership on a platform being built from the ground up.