DevSecOps Engineer

Rakuten Symphony — Germany · Posted ~3 hours ago

Skills

DevSecOps security engineering CI/CD security DevOps tooling infrastructure security vulnerability management cloud-native technologies CI/CD DevOps cloud-native OpenRAN

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join a cutting-edge cloud-native telecommunications engineering environment as a DevSecOps Engineer. You will secure development and deployment processes, embed security practices into CI/CD pipelines and DevOps tooling, proactively identify and mitigate vulnerabilities, and work closely with development and platform teams to strengthen infrastructure security.

Highlights

Work on security for a cutting-edge cloud-native telecommunications environment, driving secure development and deployment practices across CI/CD, DevOps tooling, and infrastructure while collaborating with development and platform teams.

Description

About the Company - Rakuten empowers through technology. Rakuten Symphony Germany is building a nationwide mobile network based on the industry-leading Symphony platform developed from Singapore and successfully deployed in Japan. Symphony is a fully virtualized, cloud-native telco platform at the cutting edge of technology: Rakuten partners with research organizations, start-ups, and SMEs through its Network Innovation Lab on the future of OpenRAN and autonomous networks of the future. We are in the process of deploying a nation-wide mobile network in Germany. Your Role: As a Security Engineer within our Lab environment, you will be responsible for ensuring the security integrity of our development and deployment processes. You will drive security practices across CI/CD pipelines, DevOps tooling, and infrastructure while proactively identifying and mitigating vulnerabilities. Working closely with development teams, DevOps, and platform owners, you will play a key role in strengthening our overall security posture through testing, automation, and hands-on security assessments. Your Responsibilities: Own and oversee security testing within CI/CD pipelines, including scanning, validation, and approval of container imagesManage and enforce quarantine processes for high-risk artifacts pending security reviewPerform manual validation of vulnerabilities to reduce false positives and ensure secure deploymentsCollaborate with DevOps teams, Artifactory owners, and project managers to integrate security best practicesConduct vulnerability assessments across infrastructure, applications, and network environmentsDevelop and maintain automation scripts (e.g., Python) to enhance security testing and operationsValidate exploitability of identified vulnerabilities and assess associated risksDrive remediation efforts by defining mitigation strategies and supporting patching and fixes with development teamsHelp Security Assurance team to plan and execute penetration tests (web, internal, external, cloud, and product-focused environments such as object storage systems)Provide actionable recommendations to improve security posture based on findingsHelp Security Assurance team to execute red team exercises to simulate real-world attack scenariosHelp Defensive Security team to evaluate detection and response capabilities and recommend improvementsHelp Security Architecture team to improve security practices Requirements: Proven ability to integrate security controls into the software development lifecycle, with a solid understanding of Shift-Left Security principlesProven experience in security engineering, DevSecOps, penetration testing or a similar roleStrong hands-on experience with CI/CD pipelines, particularly using Jenkins as well as CI/CD security tools and practices (e.g., SAST, DAST, container scanning)Hands-on experience with containerization and orchestration technologies (e.g., Docker, Kubernetes), including securing container images and runtime environmentsExperience with vulnerability assessment and penetration testing tools and methodologiesExperience performing web, infrastructure, and cloud penetration testingFamiliarity with artifact repository security (e.g., Artifactory or similar platforms)Experience in scripting/automation, preferably with PythonAbility to assess and prioritize vulnerabilities based on risk and business impactExperience conducting or participating in red team exercisesSolid understanding of network security, application security, and cloud security conceptsStrong collaboration and communication skills when working with cross-functional teamsExperience with secrets management solutions such as HashiCorp VaultUnderstanding of PKI concepts, including certificate management and secure communications (considered a strong plus)Experience in telecom environments is a plus