Job Search and Career Advice Platform

Aktiviere Job-Benachrichtigungen per E-Mail!

Security and Compliance Engineer (m/f/d) - Developer Platform

IT-Systemhaus der Bundesagentur für Arbeit

Essen

Hybrid

EUR 70.000 - 90.000

Vollzeit

Heute
Sei unter den ersten Bewerbenden

Erstelle in nur wenigen Minuten einen maßgeschneiderten Lebenslauf

Überzeuge Recruiter und verdiene mehr Geld. Mehr erfahren

Zusammenfassung

A leading technology services provider in Essen is seeking a Security and Compliance Engineer to enhance their Internal Developer Platform. You will design security architecture, drive Zero Trust practices, and ensure compliance throughout the software development lifecycle. The ideal candidate has extensive experience in Security Engineering and a strong understanding of cloud-native security. This role offers remote work options and opportunities to make a significant impact in a tech-focused environment.

Leistungen

Flexible hours
Remote work options
Collaboration with experienced engineers

Qualifikationen

  • Several years of experience in Security Engineering, Platform Security & Compliance, or DevSecOps.
  • Strong understanding of cloud-native architectures and container security.

Aufgaben

  • Design and implement security architecture for the Internal Developer Platform.
  • Drive adoption of Zero Trust principles.
  • Embed security and compliance into the Software Development Lifecycle.
  • Develop and enforce security automation as part of CI/CD pipelines.

Kenntnisse

Security Engineering
Platform Security & Compliance
DevSecOps
Cloud-native architectures
Kubernetes security
CI/CD pipelines
Policy-as-code
Secrets management
Python
Go
Rust

Tools

Terraform
OpenTelemetry
Grafana
OPA/Gatekeeper
Vault
Jobbeschreibung
Security and Compliance Engineer (m/f/d) - Developer Platform
Your Mission

We're building a modern Internal Developer Platform (IDP) to enable secure, scalable, and efficient software delivery -- and security & compliance is a first-class concern from day one. As Security and Compliance Engineer in our Platform team, you'll be responsible for designing, implementing, and evolving the security architecture of our IDP. Your focus will be on embedding security into the entire Software Development Lifecycle (SSDLC), enabling secure‑by‑default development practices, and advancing our Zero Trust approach across infrastructure, tooling, and pipelines. You'll collaborate closely with platform, infrastructure, compliance and application teams to ensure that security and regulatory is not a bottleneck -- but an enabler for safe, fast, and autonomous development.

Our Stack & Environment
  • Nix / NixOS - declarative, reproducible system configuration
  • Rust - used for backend tooling
  • Terraform - Infrastructure as Code
  • GitLab - CI/CD and code lifecycle management
  • OpenStack + Kubernetes + GitOps - our runtime and delivery foundation
  • OpenTelemetry + Grafana Stack (LGTM) - observability
  • Policy-as-code, Secrets Automation, and Security-as-Code everywhere
What You'll Do
  • Design and implement security architecture for our Internal Developer Platform
  • Drive adoption of Zero Trust principles across platform components, networks, identities, and services
  • Embed security and compliance into the SSDLC: from code scanning, SBOM generation, and policy‑as‑code, to runtime and product hardening
  • Develop and enforce security automation, compliance checks, and guardrails as part of CI/CD pipelines and infrastructure‑as‑code
  • Support the implementation of fine‑grained IAM, secrets management, and secure service‑to‑service communication
  • Collaborate with developers and platform engineers to design secure golden paths and self‑service tooling
  • Define, track, and report on key security metrics, risk levels, and compliance posture
  • Stay on top of emerging threats, vulnerabilities, and security best practices -- and translate them into actionable improvements
What You Bring
  • Several years of experience in Security Engineering, Platform Security & Compliance, or DevSecOps
  • Strong understanding of cloud‑native architectures, container security, and security automation as well as regulatory requirements
  • Hands‑on experience with CI/CD pipelines, infrastructure‑as‑code, and Kubernetes security
  • Familiarity with Zero Trust Architecture, including identity‑based access, service mesh, and network segmentation
  • Hands‑on experience with tools such as Policy‑as‑code engines (e.g. OPA/Gatekeeper, Conftest)
  • Knowledge of modern software supply chain security -- e.g., SBOMs, SLSA, Sigstore, SAST/DAST
  • Experience with secrets management (Vault, Sealed Secrets, External Secrets), policy engines (OPA/Gatekeeper), and observability tooling
  • Coding/scripting ability in Python, Go, or Rust is a plus
  • Clear communication skills and a collaborative mindset -- you can work across teams and disciplines
What We Offer
  • A unique opportunity to shape platform security from the ground up
  • Full ownership and real impact in a technically ambitious environment
  • A strong focus on automation, reproducibility, and secure‑by‑default engineering
  • Collaboration with experienced platform and product engineers
  • Remote work options, flexible hours, and modern tools
Get in touch with us

If you are keen to work for a leading company of cyber security in a fair and trusting environment you should immediately get in touch with us. We're looking forward to your application containing your notice period, your salary expectations as well as the job ID 3328/F.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
eine PDF-, DOC-, DOCX-, ODT- oder PAGES-Datei bis zu 5 MB per Drag & Drop ablegen.