Cyber Security Engineer - Platform & DevSecOps (m/f/d)
Indexed description
- Design, implementation, and continuous development of the technical security architecture for large Kubernetes-based platform, software, and data infrastructures
- Hands-on analysis, hardening, and security validation of Linux, container, and Kubernetes infrastructures—from the host through the cluster to the application
- Conducting technical security assessments, penetration tests, and adversarial security tests against our own platforms and components to practically demonstrate vulnerabilities and realistic attack vectors
- Security review and hardening of Infrastructure as Code, as well as integration of automated security checks, security gates, and Policy-as-Code mechanisms into CI/CD and DevSecOps processes
- Securing Kubernetes environments, including RBAC, workload isolation, admission policies, network policies, secrets management, and runtime security
- Helping to shape a secure software supply chain, including for dependencies, container images, artifacts, SBOM, signing, provenance, and trusted build and deployment processes
- Analyzing and securing network connections and communication paths between platforms, data centers, external networks, and connected systems, including segmentation, firewalls, gateways, TLS/PKI, APIs, and machine-to-machine communication
- Design and technical validation of identity, authentication, and authorization concepts for users, services, and workloads, as well as secrets, credentials, certificates, and key management
- Ensuring the protection of data at rest, in transit, and during processing in close collaboration with platform and data engineering teams
- Conducting threat modeling, vulnerability analysis, and technical validation of findings; deriving and implementing effective countermeasures
- Further development of security monitoring, audit logging, and detection capabilities, as well as support for the technical analysis and resolution of security incidents
- Participate in the security assessment of AI/machine learning infrastructures and AI-based applications, and implement security proofs of concept through to production-ready solutions
- A degree in computer science, cybersecurity, IT security, software engineering, or a comparable practical qualification
- Several years of hands-on experience in a technically oriented security role, e.g., as a Security Engineer, Platform Security Engineer, DevSecOps Engineer, or Penetration Tester
- Very strong practical knowledge of Linux, networks, containers, and Kubernetes, as well as a solid understanding of modern cloud-native and platform architectures
- Practical experience in securing Infrastructure as Code, CI/CD/DevSecOps processes, and Kubernetes environments
- In-depth knowledge of network segmentation, TLS/PKI, IAM/RBAC, secrets, and credentials, as well as common authentication and authorization concepts
- Experience with vulnerability analysis and penetration testing, as well as the ability to reproduce findings in practice, understand technical root causes, and implement appropriate countermeasures
- Strong scripting or programming skills, e.g., in Python, Bash, Go, or a comparable language, particularly for automation and security testing
- Ability to integrate security architecture with practical implementation and to collaborate effectively with platform, software, network, and data engineering teams
- A structured, responsible work style and strong written and spoken English skills
- Experience with red-team, blue-team, or purple-team approaches and adversarial testing in complex platform environments
- In-depth knowledge of software supply chain security, e.g., SBOM, artifact signing, provenance, dependency security, or trusted build processes
- Experience with Policy as Code, admission control, and runtime security, e.g., with OPA/Gatekeeper, Kyverno, Falco, or comparable solutions
- Knowledge of security monitoring, detection engineering, and incident response in distributed Kubernetes or on-premises environments
- Experience securing large data platforms, object storage, databases, or data-intensive systems
- Knowledge of AI/machine learning security, e.g., protecting AI endpoints, training data, models, ML pipelines, or AI supply chains
- Experience with highly secured, on-premises, edge, or intermittently disconnected infrastructures
What We Offer You
At our location in Bremen, we offer you:
- Company pension scheme
- Share purchase programme
- 30 days of holiday
- Access to corporate benefits
- Deutschlandticket
- Relocation support
- Mobile working
- VIVA family service
- Individual and diverse internal and external development opportunities, including at the Rheinmetall Academy
- Professional induction process supported by digital onboarding
Contact Person: Ms Özge Demirkaya
For questions regarding your application, please use the contact form.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search