Cloud & Security Architect (w/m/d) in Monheim

Cloud & Security Architect (w/m/d) in Monheim

Monheim Vollzeit Kein Homeoffice möglich
J

Job Description:We are seeking an experienced Cloud & Security Architect to join our team and lead the architecture, resilience, and security posture of our enterprise application platform. In this role, you will bridge the gap between Azure Cloud Architecture, Security Engineering, and Modern Application Development.Our application suite is built with C# and .NET and is deployed across a hybrid environment spanning Microsoft Azure, On-Premises infrastructure, and Docker / Kubernetes (K8s). Because our application is exposed directly to the public internet, ensuring robust security - ranging from edge defense and zero-trust networking to secure coding practices and container hardening - is at the core of this role.Responsibilities:DevSecOps Culture & Mentorship:Drive and cultivate a security-first and DevOps-oriented culture across software engineering and infrastructure teamsLead hands-on workshops, establish security excellence programs, and mentor developers on secure coding and automated operational practicesPublic Internet Security & Perimeter Defense:Design and enforce edge protection strategies (Azure Front Door, WAF, Application Gateway, DDoS Protection) for all internet-facing APIs and servicesEnforce Zero-Trust Network Architecture, strict IP/GEO filtering, rate-limiting, and modern API security protocols (OAuth2, OIDC, mTLS)DevOps & CI/CD Security Governance:Architect, standardize, and help maintain secure CI/CD pipelines (Azure DevOps)Own automated Infrastructure as Code (IaC) deployment workflowsEmbed continuous security gates (SAST, DAST, dependency scanning, secret detection) into the build and release lifecycleAzure & Hybrid Cloud Architecture:Architect and maintain cloud infrastructure in Azure aligned with cloud security best practices and the Microsoft Well-Architected FrameworkDesign secure hybrid connectivity between Azure, on-premises data centers, and containerized environments using Azure Arc, ExpressRoute, and VPN gatewaysContainer & Kubernetes Security:Define and enforce security controls across containerized workloads (Docker, AKS, and On-Prem Kubernetes)Implement pod security standards, network policies (Calico/Cilium), image scanning, and container runtime threat detectionSecurity Operations & Governance Execution:Coordinate and execute recurring security governance best practices, including regular user access reviews (IAM/PIM audits), cloud application security assessments, penetration testing, and automated policy compliance across all hybrid environmentsTechnical Requirements Ownership & Documentation:Take ownership of translating technologically-heavy business and product goals into detailed technical requirement specifications, system design docs, and architectural decision records (ADRs)Collaborate closely with Product Owners and Developers to define, document, and manage technical user stories and acceptance criteriaQualifications & Requirements:Education:Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or a related field required (as the baseline requirement)Master’s degree in Computer Science, Cybersecurity, or Information Technology strongly recommendedWork Experience: 7+ years of experience in Cloud Architecture, Cybersecurity, and/or DevSecOps rolesExecution & Drive: Self-motivated, hands-on practitioner with a "doer" mentality, taking strong personal ownership and pride in the quality, security, and elegance of technical deliverablesTechnical Leadership: Proven ability to lead, mentor, and inspire engineering teams to continuously raise the bar and strive for excellencePublic Internet Exposure: Hands-on experience defending public-facing, internet-exposed applications against threats (e.g., volumetric DDoS, credential stuffing, API abuse, SQLi)Azure Technical Stack: Strong practical knowledge of Microsoft Azure services and security tools (Defender for Cloud, Microsoft Entra ID, Azure Key Vault, Azure Policy, Network Security Groups, Private Endpoints)DevOps Architecture & Infrastructure as Code (IaC): Experience in driving automated infrastructure provisioning, continuous deployment, and telemetry across hybrid Azure, on-premises, and Kubernetes environments, ensuring zero-downtime deployments, high availability, and operational resilienceSoftware & Distributed Architecture Expertise: Strong background in software architecture with proven experience designing and securing microservices architectures. Solid understanding of distributed systems, event-driven messaging systems (e.g., RabbitMQ, Kafka, Azure Service Bus), data persistence patterns, and API gateway integrationsCertifications (Associate & Expert level welcome)Microsoft Azure Associate Certifications (Preferred/Targeted): Azure Security Engineer Associate (AZ-500), Azure Administrator Associate (AZ-104), Azure Developer Associate (AZ-204), Azure Network Engineer Associate (AZ-700)Expert / Industry Certifications (A plus): Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Certified: Azure Solutions Architect Expert (AZ-305), Certified Kubernetes Security Specialist (CKS) or CISSPContact:Name: Sophie Krug E-Mail: we offer:

Cloud & Security Architect (w/m/d) in Monheim Arbeitgeber: Jenoptik

Jenoptik ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern nicht nur ein dynamisches und internationales Arbeitsumfeld bietet, sondern auch gezielte Entwicklungsmöglichkeiten im Bereich Vertrieb und Führung. Mit einem starken Fokus auf Teamarbeit und kontinuierlicher Weiterbildung fördert das Unternehmen eine Kultur des Wachstums und der Innovation, insbesondere im zukunftsträchtigen Defense-Sektor. Die Möglichkeit, an internationalen Messen und Konferenzen teilzunehmen, sowie die enge Zusammenarbeit mit strategischen Partnern machen die Position des Head of Sales besonders attraktiv.

J

Kontaktdaten:

Jenoptik Recruiting-Team