Auf einen Blick
- Aufgaben: Integrate security into software development and deployment processes while collaborating with various teams.
- Arbeitgeber: Join a dynamic tech company in North Rhine-Westphalia focused on secure and efficient software solutions.
- Mitarbeitervorteile: Enjoy competitive salary, flexible hours, remote work options, and opportunities for professional growth.
- Warum dieser Job: Be part of a forward-thinking culture that values innovation and security in cutting-edge cloud technologies.
- Gewünschte Qualifikationen: 3+ years in DevSecOps or Cloud Security with strong knowledge of security frameworks and tools.
- Andere Informationen: Fluency in English is required; German is a plus.
Das voraussichtliche Gehalt liegt zwischen 43200 - 72000 € pro Jahr.
2 weeks ago Be among the first 25 applicants
Direct message the job poster from Annapurna
DevOps & Infrastructure Headhunter, keen triathlete!
About Us
We are a dynamic and innovative technology company based in North Rhine-Westphalia, Germany. Our mission is to build secure, scalable, and efficient software solutions while embedding security at the heart of our DevOps culture. Join our team to work with cutting-edge cloud technologies, automation, and security best practices in a collaborative and forward-thinking environment.
Your Role
As a DevSecOps Engineer , you will play a crucial role in integrating security into our software development and deployment processes. You will work closely with development, operations, and security teams to ensure our infrastructure and applications are secure by design, automated, and continuously monitored.
Responsibilities
- Implement and maintain security automation tools across CI/CD pipelines.
- Conduct security assessments, vulnerability scans, and threat modeling for cloud and on-premise environments.
- Develop and enforce security policies, compliance frameworks (ISO 27001, NIST, GDPR), and best practices.
- Collaborate with DevOps teams to embed security within Infrastructure as Code (IaC) and Kubernetes environments.
- Monitor, detect, and respond to security threats using SIEM and other security tools.
- Drive security awareness and best practices among development and operations teams.
- Stay updated with the latest security threats, tools, and trends to improve security strategies.
What You Bring
Experience: 3+ years in DevSecOps, Cloud Security, or a related role.
Security Knowledge: Strong understanding of OWASP, SAST/DAST, IAM, and Zero Trust Architecture.
Cloud & Containers: Hands-on experience with AWS, Azure, or GCP, as well as Kubernetes and Docker security.
Automation & Scripting: Proficiency in Python, Bash, Terraform, or Ansible.
CI/CD & Security Tools: Experience with tools such as GitLab CI/CD, Jenkins, SonarQube, Snyk, or Checkmarx.
Compliance & Governance: Knowledge of security frameworks (ISO 27001, NIST, CIS Benchmarks).
Problem-Solving Mindset: Ability to assess security risks and propose practical solutions.
Language: Fluent in English (German is a plus).
What We Offer
Competitive salary & performance bonuses
Flexible working hours & hybrid/remote work options
Opportunities for professional growth & certifications
A collaborative, innovative, and security-focused culture
Modern tech stack & cutting-edge cloud environments
Seniority level
Mid-Senior level
Employment type
Full-time
Job function
Technology, Information and Media
#J-18808-Ljbffr
DevSecOps Engineer Arbeitgeber: Annapurna
Kontaktperson:
Annapurna HR Team
StudySmarter Bewerbungstipps 🤫
So bekommst du den Job: DevSecOps Engineer
✨Tip Number 1
Make sure to showcase your hands-on experience with cloud platforms like AWS, Azure, or GCP. Highlight specific projects where you implemented security measures in these environments to demonstrate your practical knowledge.
✨Tip Number 2
Familiarize yourself with the latest security tools and practices mentioned in the job description, such as GitLab CI/CD, Jenkins, and Snyk. Being able to discuss these tools in detail during your conversation will show your commitment to staying updated in the field.
✨Tip Number 3
Prepare to discuss your experience with security frameworks like ISO 27001 and NIST. Be ready to provide examples of how you've applied these frameworks in previous roles to ensure compliance and enhance security.
✨Tip Number 4
Since collaboration is key in this role, think of examples where you've successfully worked with cross-functional teams. Emphasizing your ability to communicate effectively with development, operations, and security teams will set you apart.
Diese Fähigkeiten machen dich zur top Bewerber*in für die Stelle: DevSecOps Engineer
Tipps für deine Bewerbung 🫡
Understand the Role: Make sure to thoroughly read the job description for the DevSecOps Engineer position. Understand the key responsibilities and required skills, such as experience with cloud security and automation tools.
Tailor Your CV: Customize your CV to highlight relevant experience in DevSecOps, cloud technologies, and security practices. Use specific examples that demonstrate your expertise in areas like CI/CD pipelines and security assessments.
Craft a Strong Cover Letter: Write a cover letter that reflects your passion for security and DevOps. Mention how your background aligns with the company's mission to embed security into their software solutions and your eagerness to contribute to their innovative culture.
Highlight Relevant Projects: If you have worked on projects involving security automation, vulnerability scanning, or compliance frameworks, be sure to include these in your application. This will showcase your hands-on experience and problem-solving mindset.
Wie du dich auf ein Vorstellungsgespräch bei Annapurna vorbereitest
✨Showcase Your Security Knowledge
Be prepared to discuss your understanding of security principles, especially OWASP, SAST/DAST, and Zero Trust Architecture. Highlight any relevant experiences where you successfully integrated security into DevOps processes.
✨Demonstrate Your Cloud Expertise
Since the role involves working with AWS, Azure, or GCP, make sure to share specific examples of your hands-on experience with these platforms. Discuss how you've secured cloud environments and utilized Kubernetes and Docker.
✨Highlight Automation Skills
Talk about your proficiency in automation and scripting languages like Python, Bash, Terraform, or Ansible. Provide examples of how you've implemented security automation tools within CI/CD pipelines.
✨Stay Updated on Security Trends
Show that you are proactive in keeping up with the latest security threats and tools. Discuss any recent trends you've noticed and how they could impact the company's security strategies.