Hebe dich für diese Rolle von der Masse ab — erstelle in etwa einer Minute einen maßgeschneiderten Lebenslauf und ein Anschreiben.
Codesphere is seeking a Senior Security & Compliance Engineer to own the platform's security posture across the stack, incident response, and compliance efforts. The role emphasizes DevSecOps, vulnerability management, and secure coding practices within a fast-growing cloud environment.
Based in Germany with offices in Karlsruhe and Munich, the team prioritizes strong security culture, cross-functional collaboration, and continuous improvement through hands-on security work and governance.
Codesphere is a Virtual Cloud Provider from Germany building the future of sovereign cloud infrastructure. Our platform gives enterprises and governments full sovereignty without giving up modern cloud capability – a vision recently validated by a series of multi-million European government tenders.
Since our founding in Karlsruhe in 2020, we’ve expanded into an international team of 60+ experts. Based in Karlsruhe and Munich and backed by top-tier investors, we are chasing a bold vision.
We’re scaling fast and would love for you to join us and grow alongside us
Codesphere runs cloud infrastructure that enterprises and governments depend on – security is not an afterthought, it's a foundation. As a Senior Security & Compliance Engineer (m/f/d), you own the security posture of our platform: from vulnerability management and incident response to compliance frameworks and developer enablement.
You conduct security assessments, penetration testing, and vulnerability scanning – and drive remediation with development teams
You manage security scanning tooling (DAST/SAST) and perform security code reviews
You design and implement security controls across our full technology stack, defining and enforcing standards for development, infrastructure, and data
You integrate security into our CI/CD pipelines and development processes – Shift Left and DevSecOps in practice, not just on paper
You develop and maintain our Security Incident Response Plan, monitor security logs via SIEM, and lead forensic analysis when needed
You ensure compliance with relevant standards and regulations – including GDPR and ISO 27001
You manage IAM systems with a least privilege approach
You develop and deliver security awareness training for the whole company – and specialised secure coding training for engineering teams