Summary
✨ AI‑Generated
A cybersecurity-focused engineering role responsible for solving complex application security challenges and supporting development teams with secure engineering practices.
Highlights
Work at the intersection of engineering and security with strong autonomy, technical challenges, and opportunities to shape secure systems.
Description
Schwarz Digits creates the technological foundation for digital sovereignty in Europe.
As the IT and digital division of the Schwarz Group, we develop and manage the IT infrastructures for the retail divisions Lidl and Kaufland, as well as Schwarz Production and PreZero.
At the same time, we operate as an independent provider in the external market to support companies across Europe in their digital transformation.
We bundle our core services in the areas of Cloud, Cyber Security, Data & AI, Communication, and Workspace.
Join us and contribute to digital sovereignty in Europe.
With us, you will work at the intersection of agility and security: You will benefit from fast decision-making processes, enjoy genuine creative freedom in your projects, and be able to build upon the stable foundation of the Schwarz Group.
Your Tasks
You act as the decisive technical security authority, resolving complex SAST/DAST/SCA cases together with our engineering squads.You seamlessly integrate and automate security solutions into our agile processes and CI/CD pipelines.You translate central Threat Models and enterprise security policies into concrete, actionable architecture guidelines.You act as a technical mentor and sparring partner for a group of Security Champions, sharing best practices and localized solutions.You conduct security architecture reviews for RFCs and new design concepts to enforce "Secure-by-Design" principles long before code hits production.
Your Profile
You have several years of professional experience and are confident in coding with modern languages (e.g., Java, Go, JavaScript/TypeScript, or Python).You possess deep expertise in Secure SDLC, the OWASP Top 10, and modern AppSec tools (e.g., Snyk, SonarQube, GitLab Security Suite).You bring a strong technical specialization in Cloud/Container Security (preferably STACKIT, GCP).You have expertise in network security, including the implementation of Zero Trust architectures, API gateways, WAFs, or microsegmentation.You already performed threat modelling for large scale enterprise environments.First experience with Security-Agents, based on AI, integrated into Development Lifecycle Processes.You stand out with a proactive work style, strong coaching abilities, and communicate fluently in German and English.