Cloud & Security Architect (w/m/d)

Jenoptik AG

Monheim am Rhein

Hybrid

EUR 120.000 - 160.000

Vollzeit

Vor 6 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Jenoptik AG in Germany is seeking an experienced Cloud & Security Architect to lead architecture, resilience, and security of our enterprise application platform across Azure, on-prem, and containerized environments. You will bridge Azure cloud architecture, security engineering, and modern application development.

The role focuses on zero-trust networking, edge protection, secure coding, and container hardening in a hybrid setup with Docker and Kubernetes.

Qualifikationen

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or related field.
  • Master's degree in CS/Cybersecurity/IT strongly recommended.
  • 7+ years of Cloud Architecture, Cybersecurity, and/or DevSecOps experience.

Aufgaben

  • Drive security-first DevSecOps culture across software and infra teams.
  • Lead hands-on workshops, establish security excellence programs, and mentor developers on secure coding and automated operational practices
  • Design and enforce edge protection strategies (Azure Front Door, WAF, Application Gateway, DDoS Protection) for all internet-facing APIs and services
  • Enforce Zero-Trust Network Architecture, strict IP/GEO filtering, rate-limiting, and modern API security protocols (OAuth2, OIDC, mTLS)
  • Architect, standardize, and help maintain secure CI/CD pipelines (Azure DevOps) Own automated Infrastructure as Code (IaC) deployment workflows
  • Embed continuous security gates (SAST, DAST, dependency scanning, secret detection) into the build and release lifecycle
  • Architect and maintain cloud infrastructure in Azure aligned with cloud security best practices and the Microsoft Well-Architected Framework
  • Design secure hybrid connectivity between Azure, on-premises data centers, and containerized environments using Azure Arc, ExpressRoute, and VPN gateways
  • Define and enforce security controls across containerized workloads (Docker, AKS, and On-Prem Kubernetes)
  • Implement pod security standards, network policies (Calico/Cilium), image scanning, and container runtime threat detection
  • Coordinate and execute recurring security governance best practices, including regular user access reviews (IAM/PIM audits), cloud application security assessments, penetration testing, and automated policy compliance across all hybrid environments
  • Take ownership of translating technically-heavy business and product goals into detailed technical requirement specifications, system design docs, and architectural decision records (ADRs)
  • Collaborate closely with Product Owners and Developers to define, document, and manage technical user stories and acceptance criteria

Kenntnisse

Cloud Architecture
Cybersecurity
DevSecOps
Zero Trust
Azure
Kubernetes
Docker
Security Engineering
Edge Security
CI/CD Security
IaC

Ausbildung

Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field
Master's degree in Computer Science, Cybersecurity, or Information Technology

Tools

Azure DevOps
Docker
Kubernetes
Calico/Cilium
Azure Arc
ExpressRoute
WAF

Jobbeschreibung

Jenoptik is an international photonics group with representatives in over 80 countries. Optical technologies are the foundation of our business. We employ around 4,000 people worldwide.

Job Description:

We are seeking an experienced Cloud & Security Architect to join our team and lead the architecture, resilience, and security posture of our enterprise application platform. In this role, you will bridge the gap between Azure Cloud Architecture, Security Engineering, and Modern Application Development. Our application suite is built with C#, .NET and is deployed across a hybrid environment spanning Microsoft Azure, On-Premises infrastructure, and Docker / Kubernetes (K8s). Because our application is exposed directly to the public internet, ensuring robust security - ranging from edge defense and zero-trust networking to secure coding practices and container hardening - is at the core of this role.

Responsibilities:
DevSecOps Culture & Mentorship:
  • Drive and cultivate a security-first and DevOps-oriented culture across software engineering and infrastructure teams
  • Lead hands-on workshops, establish security excellence programs, and mentor developers on secure coding and automated operational practices
Public Internet Security & Perimeter Defense:
  • Design and enforce edge protection strategies (Azure Front Door, WAF, Application Gateway, DDoS Protection) for all internet-facing APIs and services
  • Enforce Zero-Trust Network Architecture, strict IP/GEO filtering, rate-limiting, and modern API security protocols (OAuth2, OIDC, mTLS)
DevOps & CI/CD Security Governance:
  • Architect, standardize, and help maintain secure CI/CD pipelines (Azure DevOps) Own automated Infrastructure as Code (IaC) deployment workflows
  • Embed continuous security gates (SAST, DAST, dependency scanning, secret detection) into the build and release lifecycle
Azure & Hybrid Cloud Architecture:
  • Architect and maintain cloud infrastructure in Azure aligned with cloud security best practices and the Microsoft Well-Architected Framework
  • Design secure hybrid connectivity between Azure, on-premises data centers, and containerized environments using Azure Arc, ExpressRoute, and VPN gateways
Container & Kubernetes Security:
  • Define and enforce security controls across containerized workloads (Docker, AKS, and On-Prem Kubernetes)
  • Implement pod security standards, network policies (Calico/Cilium), image scanning, and container runtime threat detection
Security Operations & Governance Execution:
  • Coordinate and execute recurring security governance best practices, including regular user access reviews (IAM/PIM audits), cloud application security assessments, penetration testing, and automated policy compliance across all hybrid environments
Technical Requirements Ownership & Documentation:
  • Take ownership of translating technologically-heavy business and product goals into detailed technical requirement specifications, system design docs, and architectural decision records (ADRs)
  • Collaborate closely with Product Owners and Developers to define, document, and manage technical user stories and acceptance criteria
Qualifications & Requirements:
Education:
  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field required (as the baseline requirement)
  • Master's degree in Computer Science, Cybersecurity, or Information Technology strongly recommended
Work Experience:
  • 7+ years of experience in Cloud Architecture, Cybersecurity, and/or DevSecOps roles
Execution & Drive:
  • Self-motivated, hands-on practitioner with a "doer" mentality, taking strong personal ownership and pride in the quality, security, and elegance of technical deliverables
Technical Leadership:
  • Proven ability to lead, mentor, and inspire engineering teams to continuously raise the bar and strive for excellence
Public Internet Exposure:
  • Hands-on experience defending public-facing, internet-exposed applications against threats (e.g., volumetric DDoS, credential stuffing, API abuse, SQLi)
Azure Technical Stack:
  • Strong practical knowledge of Microsoft Azure services and security tools (Defender for Cloud, Microsoft Entra ID, Azure Key Vault, Azure Policy, Network Security Groups, Private Endpoints)
DevOps Architecture & Infrastructure as Code (IaC):
  • Experience in driving automated infrastructure provisioning, continuous deployment, and telemetry across hybrid Azure, on-premises, and Kubernetes environments, ensuring zero-downtime deployments, high availability, and operational resilience
Software & Distributed Architecture Expertise:
  • Strong background in software architecture with proven experience designing and securing microservices architectures. Solid understanding of distributed systems, event-driven messaging systems (e.g., RabbitMQ, Kafka, Azure Service Bus), data persistence patterns, and API gateway integrations
Certifications (Associate & Expert level welcome):
  • Microsoft Azure Associate Certifications (Preferred/Targeted): Azure Security Engineer Associate (AZ-500), Azure Administrator Associate (AZ-104), Azure Developer Associate (AZ-204), Azure Network Engineer Associate (AZ-700)
  • Expert / Industry Certifications (A plus): Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Certified: Azure Solutions Architect Expert (AZ-305), Certified Kubernetes Security Specialist (CKS) or CISSP
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cloud & Security Architect (w/m/d)
Cloud & Security Architect (w/m/d)

Jenoptik AG • Monheim

Vor Ort
EUR 110.000 - 150.000
Cloud Architect
Cloud Architect

EPAM Systems • Deutschland

Hybrid
EUR 120.000 - 160.000
Senior Azure Architect (m/f/d)
Senior Azure Architect (m/f/d)

FERCHAU Engineering GmbH • Monheim am Rhein

Hybrid
EUR 110.000 - 140.000
Save money with discounts on travel, e
Service anniversary, marriage or birth
Free stress management and resilience
+3
Senior Cyber Security, Microsoft Ecosystem Engineer
Senior Cyber Security, Microsoft Ecosystem Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 120.000
Principal Azure Cloud Engineer
Principal Azure Cloud Engineer

Jobtailor • Deutschland

Remote
EUR 120.000 - 150.000
Security Architect
Security Architect

Jobtailor • Garching bei München

Vor Ort
EUR 90.000 - 120.000
Senior Security Architect
Senior Security Architect

Verimatrix • Ismaning

Vor Ort
EUR 110.000 - 150.000
Azure Cloud Engineer
Azure Cloud Engineer

Market Cloud Ltd • Deutschland

Vor Ort
EUR 42.000 - 65.000
Senior Security Architect
Senior Security Architect

Verimatrix • München

Vor Ort
EUR 120.000 - 170.000
Cloud Architect (Azure Migration)
Cloud Architect (Azure Migration)

HCLTech • Leipzig

Vor Ort
EUR 90.000 - 130.000