Cyber Security Engineer - Platform & DevSecOps

Rheinmetall — Germany · Posted ~4 hours ago

Full-time Visa History ✓

Skills

Cybersecurity Kubernetes Linux Container security Security architecture Infrastructure as Code CI/CD DevSecOps Penetration testing Security hardening Containers RBAC SBOM

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A cybersecurity engineering role focused on securing large Kubernetes-based platforms and cloud-native infrastructure. Responsibilities include architecture, Linux and container hardening, penetration testing, Infrastructure as Code security, CI/CD security gates, Kubernetes policies, secrets management, runtime protection, and software supply-chain security.

Highlights

Advanced cybersecurity role covering security architecture, hands-on infrastructure hardening, penetration testing, Kubernetes security, automated security controls, and software supply-chain protection.

Description

What We Are Looking For Design, implementation, and continuous development of the technical security architecture for large Kubernetes-based platform, software, and data infrastructuresHands-on analysis, hardening, and security validation of Linux, container, and Kubernetes infrastructures—from the host through the cluster to the applicationConducting technical security assessments, penetration tests, and adversarial security tests against our own platforms and components to practically demonstrate vulnerabilities and realistic attack vectorsSecurity review and hardening of Infrastructure as Code, as well as integration of automated security checks, security gates, and Policy-as-Code mechanisms into CI/CD and DevSecOps processesSecuring Kubernetes environments, including RBAC, workload isolation, admission policies, network policies, secrets management, and runtime securityHelping to shape a secure software supply chain, including for dependencies, container images, artifacts, SBOM, signing, provenance, and trusted build and deployment processesAnalyzing and securing network connections and communication paths between platforms, data centers, external networks, and connected systems, including segmentation, firewalls, gateways, TLS/PKI, APIs, and machine-to-machine communicationDesign and technical validation of identity, authentication, and authorization concepts for users, services, and workloads, as well as secrets, credentials, certificates, and key managementEnsuring the protection of data at rest, in transit, and during processing in close collaboration with platform and data engineering teamsConducting threat modeling, vulnerability analysis, and technical validation of findings; deriving and implementing effective countermeasuresFurther development of security monitoring, audit logging, and detection capabilities, as well as support for the technical analysis and resolution of security incidentsParticipate in the security assessment of AI/machine learning infrastructures and AI-based applications, and implement security proofs of concept through to production-ready solutions What Qualifications You Should Have A degree in computer science, cybersecurity, IT security, software engineering, or a comparable practical qualificationSeveral years of hands-on experience in a technically oriented security role, e.g., as a Security Engineer, Platform Security Engineer, DevSecOps Engineer, or Penetration TesterVery strong practical knowledge of Linux, networks, containers, and Kubernetes, as well as a solid understanding of modern cloud-native and platform architecturesPractical experience in securing Infrastructure as Code, CI/CD/DevSecOps processes, and Kubernetes environmentsIn-depth knowledge of network segmentation, TLS/PKI, IAM/RBAC, secrets, and credentials, as well as common authentication and authorization conceptsExperience with vulnerability analysis and penetration testing, as well as the ability to reproduce findings in practice, understand technical root causes, and implement appropriate countermeasuresStrong scripting or programming skills, e.g., in Python, Bash, Go, or a comparable language, particularly for automation and security testingAbility to integrate security architecture with practical implementation and to collaborate effectively with platform, software, network, and data engineering teamsA structured, responsible work style and strong written and spoken English skillsExperience with red-team, blue-team, or purple-team approaches and adversarial testing in complex platform environmentsIn-depth knowledge of software supply chain security, e.g., SBOM, artifact signing, provenance, dependency security, or trusted build processesExperience with Policy as Code, admission control, and runtime security, e.g., with OPA/Gatekeeper, Kyverno, Falco, or comparable solutionsKnowledge of security monitoring, detection engineering, and incident response in distributed Kubernetes or on-premises environmentsExperience securing large data platforms, object storage, databases, or data-intensive systemsKnowledge of AI/machine learning security, e.g., protecting AI endpoints, training data, models, ML pipelines, or AI supply chainsExperience with highly secured, on-premises, edge, or intermittently disconnected infrastructures A solid foundation and practical implementation experience are essential for this role. Additional specialized knowledge is expressly not a requirement. Stärken und Erfahrungen zählen bei Rheinmetall, auch wenn vielleicht nicht alle aufgeführten Anforderungen vollständig erfüllt sind. Wir freuen uns auf Bewerber (m/w/d), die Lust haben, etwas zu bewegen und Verantwortung zu übernehmen. Wir legen Wert auf Individualität und Chancengleichheit. Schwerbehinderte Bewerber (m/w/d) werden bei gleicher Eignung besonders berücksichtigt. What We Offer You At our location in Bremen, we offer you: Company pension schemeShare purchase programme30 days of holidayAccess to corporate benefitsDeutschlandticketRelocation supportMobile workingVIVA family serviceIndividual and diverse internal and external development opportunities, including at the Rheinmetall AcademyProfessional induction process supported by digital onboarding CONTACT INFORMATION Contact Person: Ms Özge Demirkaya For questions regarding your application, please use the contact form.