I am currently looking for an experienced CI/CD engineer (m/f/d) with expertise in security and compliance.
Tasks:
• Analyzing of the current project status, including of the dependency tree and the dependency management
• Giving recommendations on design and Implementation of a multi-tenant interfaces to interact with security data
• Maintaining of security solutions
• Reviewing of existing documentation and providing updates
• Consulting in generating and managing SBOM generation
• Giving recommendations in reaction to findings, either by planning escalations or setting acknowledgements • Analyzing of the results of penetration test
• Give recommendations on hardening container images
• Providing guidance to the project in implementation of RBAC in Kubernetes based on best practices and in alignment with security standards
Must-have:
• Experience with the implementation of security solutions ensuring integrity, confidentiality, and availability of systems and data (Favored tools: Dependency-Track, DefectDojo, Trivy, knowledge about SBOMs with CycloneDX)
• Experience with Infrastructure-as-Code (IaC) tool Terraform or OpenTofu
• Design and implement security measures for infrastructure in hybrid environments
• Evaluate, select, and implement security tools for cloud and on-premise environments
• Apply networking skills to secure communications, data flows, and networks (firewalls, VPNs, segmentation)
• Develop and document security processes, including vulnerability management and incident response
• Coordination with Engineering, DevOps, and IT teams to integrate security into the development lifecycle
• Deep understanding of asymmetric encryption, particularly certificate hierarchies for establishing trust and secure communication
• Identify, assess, and mitigate security risks in cloud and on-premise environments
• Experience with container security in Kubernetes and Docker environments
• Experience in security design in the critical infrastructure
• Fluent English in speech and writing (at least B2)
Nice-to-have:
• Experience in German language to understand ISO certificate documents
• Familiarity with CI/CD pipeline security and automated security testing
• Experience with logging, monitoring, and alerting tools in cloud environments (e.g., Prometheus, Loki Stack)
• Familiarity with encryption practices (e.g., data-at-rest, data-in-transit, key management systems)
• Familiarity with Software Composition Analysis (SCA) tools and practices
• Proficiency in Static Application Security Testing (SAST)
.png)

