Job description

We have set ourselves the goal of positively shaping the complex challenges and opportunities of the digital future for our environment. Our specialisation lies in improving our customers' software development and delivery processes with the aim of Digital sovereignty especially in the Public Sector to strengthen. We advise as equals, continually develop and remain open to everything: new tools and trends, new ways of working, new people.

We have created a transparent and open working environment for our employees that prioritises innovation, efficiency, and satisfaction.

If you also want to have a positive impact on the digital future, we are your room to be.

What you can expect from us

As a DevSecOps Engineer, you'll have the opportunity to actively shape security standards and make our open-source products sustainably more secure. You'll work on modern platform and automation solutions, contribute your ideas to cross-functional security initiatives, continuously develop your expertise, and get the chance to also engage across the industry (in associations).

If you think analytically, take responsibility and bring a real open-source mindset, then Cloudogu is your room to be.

Your tasks include

As a DevSecOps Engineer, you will develop and advise on security matters throughout the entire Software Development Lifecycle. You will work closely with Development, Platform, and Cloud teams, and undertake the following tasks:

  • You are deepening Shift-Left Security practices in our development and deployment processes.
  • You optimise SAST, DAST, container and IaC security checks
  • You continuously develop our DevSecOps practices and security standards.
  • You are working on our Internal Developer Platform and an ops automation tool.
  • You coach agile software development and cloud teams on secure development practices.
  • You support cross-team security initiatives as well as selected customer projects

What you bring with you

You have relevant professional experience in DevSecOps, Cloud Security, or Platform Engineering and possess German language skills at a minimum C1 level. This knowledge will help you get started:

  • Experience with DevSecOps, SAST and DAST scans, and tools such as SonarQube, Checkmarx or Snyk
  • Very good knowledge of Container Security, Kubernetes Security and Pod Security Standards
  • Programming experience in Go or Java
  • Safe handling of monitoring and observability tools like Prometheus, Grafana, Elastic, or OpenTelemetry
  • Experience with IaC security and tools such as TFLint, Checkov, or KICS
  • Secure handling of CI/CD, GitOps, and automation tools
  • Knowledge of OWASP Top Ten, CIS Benchmarks, and ideally SBOM or SLSA

About the company

We have set ourselves the goal of positively shaping the complex challenges and opportunities of the digital future for our environment. Our specialisation lies in improving our customers' software development and delivery processes with the aim of Digital sovereignty especially in the Public Sector to strengthen. We advise on equal terms, constantly develop ourselves and remain open to everything: new tools and trends, new ways of working, new people.

With over 10 years of experience and round 80 employees We are among the leading companies for digitalisation in the public sector. For our employees, we have created a transparent and open working environment that prioritises innovation, efficiency and satisfaction.

We are looking for people to support us in shaping the digital future in Europe. That's exactly what makes us the room to be.

Our benefits

  • Promotion opportunities
  • Vocational training
  • Company pension scheme
  • Financial incentives
  • Company bike
  • Flexible working hours
  • Home office
  • Public transport ticket / subsidy
  • Team building
  • Further training