Cloud & Security Architect (w/m/d)

Jenoptik AG

Monheim

Vor Ort

EUR 110.000 - 150.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Jenoptik AG is seeking a Cloud & Security Architect to lead architecture, resilience, and security for our enterprise platform. You will bridge Azure cloud, security engineering, and modern app development across hybrid environments with Docker, AKS, and on‑prem Kubernetes.

You will design edge protection, zero-trust networking, and secure CI/CD pipelines, mentor teams, and drive security governance with IaC, SAST/DAST, and compliant controls.

Qualifikationen

  • Bachelor’s degree in CS, Cybersecurity, or related field required.
  • Master’s degree in CS, Cybersecurity, or IT strongly recommended.
  • 7+ years of experience in Cloud Architecture, Cybersecurity, and/or DevSecOps roles.
  • Self-motivated, hands-on practitioner with ownership and quality focus.
  • Experience defending public-facing, internet-exposed applications against threats.

Aufgaben

  • Drive security-first and DevOps-oriented culture across software engineering and infrastructure teams.
  • Lead workshops, establish security excellence programs, and mentor developers on secure coding and automated security practices.

Kenntnisse

Azure Cloud Architecture
Security Engineering
DevSecOps
Docker / Kubernetes
Zero-Trust Networking
OAuth2 / OIDC / mTLS
Azure DevOps
IaC / Automation
Secure Coding Practices
Hybrid Cloud

Ausbildung

Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering
Master’s degree in Computer Science, Cybersecurity, or IT

Tools

Docker
AKS
Azure DevOps
Calico/Cilium
Kubernetes

Jobbeschreibung

We create photonic solutions to shape the world of tomorrow, together with people who embrace brilliant ideas with openness and curiosity.With teams in over 80 countries, we offer you the opportunity to reach your full potential.
Cloud & Security Architect (w/m/d)

Job ID: 5288

Location: Monheim, North Rhine-Westphalia, DE

Date: Sep 15, 2026

Job Description:

We are seeking an experienced Cloud & Security Architect to join our team and lead the architecture, resilience, and security posture of our enterprise application platform. In this role, you will bridge the gap between Azure Cloud Architecture, Security Engineering, and Modern Application Development. Our application suite is built with C# and .NET and is deployed across a hybrid environment spanning Microsoft Azure, On-Premises infrastructure, and Docker / Kubernetes (K8s). Because our application is exposed directly to the public internet, ensuring robust security - ranging from edge defense and zero-trust networking to secure coding practices and container hardening - is at the core of this role.

Responsibilities:
  • Drive and cultivate a security-first and DevOps-oriented culture across software engineering and infrastructure teams
  • Lead hands-on workshops, establish security excellence programs, and mentor developers on secure coding and automated operational practices

Public Internet Security & Perimeter Defense:

  • Design and enforce edge protection strategies (Azure Front Door, WAF, Application Gateway, DDoS Protection) for all internet-facing APIs and services
  • Enforce Zero-Trust Network Architecture, strict IP/GEO filtering, rate-limiting, and modern API security protocols (OAuth2, OIDC, mTLS)

DevOps & CI/CD Security Governance:

  • Architect, standardize, and help maintain secure CI/CD pipelines (Azure DevOps)Own automated Infrastructure as Code (IaC) deployment workflows
  • Embed continuous security gates (SAST, DAST, dependency scanning, secret detection) into the build and release lifecycle
  • Architect and maintain cloud infrastructure in Azure aligned with cloud security best practices and the Microsoft Well-Architected Framework
  • Design secure hybrid connectivity between Azure, on-premises data centers, and containerized environments using Azure Arc, ExpressRoute, and VPN gateways
  • Define and enforce security controls across containerized workloads (Docker, AKS, and On-Prem Kubernetes)
  • Implement pod security standards, network policies (Calico/Cilium), image scanning, and container runtime threat detection

Security Operations & Governance Execution:

  • Coordinate and execute recurring security governance best practices, including regular user access reviews (IAM/PIM audits), cloud application security assessments, penetration testing, and automated policy compliance across all hybrid environments

Technical Requirements Ownership & Documentation:

  • Take ownership of translating technologically-heavy business and product goals into detailed technical requirement specifications, system design docs, and architectural decision records (ADRs)
  • Collaborate closely with Product Owners and Developers to define, document, and manage technical user stories and acceptance criteria
Qualifications & Requirements:

Education:

  • Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field required (as the baseline requirement)
  • Master’s degree in Computer Science, Cybersecurity, or Information Technology strongly recommended

Work Experience: 7+ years of experience in Cloud Architecture, Cybersecurity, and/or DevSecOps roles

Execution & Drive: Self-motivated, hands-on practitioner with a "doer" mentality, taking strong personal ownership and pride in the quality, security, and elegance of technical deliverables

Technical Leadership: Proven ability to lead, mentor, and inspire engineering teams to continuously raise the bar and strive for excellence

Public Internet Exposure: Hands-on experience defending public-facing, internet-exposed applications against threats (e.g., volumetric DDoS, credential stuffing, API abuse, SQLi)

Azure Technical Stack: Strong practical knowledge of Microsoft Azure services and security tools (Defender for Cloud, Microsoft Entra ID, Azure Key Vault, Azure Policy, Network Security Groups, Private Endpoints)

DevOps Architecture & Infrastructure as Code (IaC): Experience in driving automated infrastructure provisioning, continuous deployment, and telemetry across hybrid Azure, on-premises, and Kubernetes environments, ensuring zero-downtime deployments, high availability, and operational resilience

Software & Distributed Architecture Expertise: Strong background in software architecture with proven experience designing and securing microservices architectures. Solid understanding of distributed systems, event-driven messaging systems (e.g., RabbitMQ, Kafka, Azure Service Bus), data persistence patterns, and API gateway integrations

  • Expert / Industry Certifications (A plus): Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Certified: Azure Solutions Architect Expert (AZ-305), Certified Kubernetes Security Specialist (CKS) or CISSP

Contact:

What we offer:

About Jenoptik

With its Strategic Business Unit (SBU) Smart Mobility Solutions, Jenoptik provides photonics-based, innovative and sustainable solutions, including technology and services for road safety and security. As an end-to-end solution provider, we support our customers with the provision of roadside equipment and software, including integration, installation, maintenance and financing models through to full-service operation of our solutions. Our strong global presence and installation base is supported by a longstanding partner network with tens of thousands systems deployed worldwide. Leveraging 90 years of experience and 40 years in ANPR, Jenoptik is a world-leading enabler for road safety and civil security, with intelligent solutions and services constantly evolving to help make roads, journeys, communities and our environment safer around the globe.

Should you need any further information, please do not hesitate to contact us.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cloud & Security Architect (w/m/d)
Cloud & Security Architect (w/m/d)

Jenoptik AG • Monheim am Rhein

Hybrid
EUR 120.000 - 160.000
Senior Azure Cloud Security Consultant (m/w/d)
Senior Azure Cloud Security Consultant (m/w/d)

United States Digital Space LLC • Frankfurt

Vor Ort
EUR 69.000 - 91.000
Training budget 10000 EUR
30 days vacation
Flexible working hours
+5
Senior Azure Cloud Security Consultant (m/w/d)
Senior Azure Cloud Security Consultant (m/w/d)

United States Digital Space LLC • München

Vor Ort
EUR 69.000 - 91.000
Training budget
Vacation 30 days
Flexible hours
+4
Senior Azure Cloud Security Consultant (m/w/d)
Senior Azure Cloud Security Consultant (m/w/d)

NVISO Security • Frankfurt

Hybrid
EUR 69.000 - 91.000
Training budget 10,000 EUR
30 days vacation
Flexible working hours
+3
Senior Azure Cloud Security Consultant (m/w/d)
Senior Azure Cloud Security Consultant (m/w/d)

NVISO Security • München

Hybrid
EUR 69.000 - 91.000
Training budget and continuing ed
60 days home office within EU
Flexible hours
+2
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

Yoummday GmbH • München

Hybrid
EUR 90.000 - 130.000
30 days vacation
Job lunch allowance (€69/mo)
Givve card (€50/mo)
+5
Senior Azure Cloud Security Consultant (m/w/d)
Senior Azure Cloud Security Consultant (m/w/d)

NVISO • München

Vor Ort
Confidential
Training budget
Flexible work options
Company bike leasing
+2
Senior Azure Cloud Security Consultant (m/w/d)
Senior Azure Cloud Security Consultant (m/w/d)

NVISO • Frankfurt

Hybrid
Confidential
Training budget
Hybrid work model
30 days vacation
+6
Delivery- und Release-Manager (m/w/d)
Delivery- und Release-Manager (m/w/d)

Jenoptik AG • Monheim

Vor Ort
EUR 70.000 - 110.000
Senior Cloud Security Engineer Multi-Cloud (GCP and Azure) f/m/d
Senior Cloud Security Engineer Multi-Cloud (GCP and Azure) f/m/d

PSI Software - Scandinavia • Berlin

Vor Ort
EUR 90.000 - 120.000
Fruts & drinks
Mobility – Public transport subsidy or
Company bike option
+4