Senior DevSecOps Engineer
Posted 3hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior DevSecOps Engineer securing Redcare Pharmacy’s Azure and Kubernetes Data & AI platform. Building cloud security controls, protected CI/CD pipelines, and compliant ML/MLOps infrastructure.
Responsibilities:
- Build and maintain secure CI/CD pipelines using Azure DevOps or GitHub Actions
- Implement secrets hygiene, signed artifacts/SBOMs, SAST/DAST/container scanning, least-privilege service connections, and supply-chain hardening
- Automate infrastructure security with Terraform, policy-as-code guardrails, and continuous IaC scanning
- Harden Kubernetes through RBAC, NetworkPolicies, Pod Security Standards, secret management, image signing/scanning, and admission policies
- Protect cloud identities and data using Entra ID roles/Managed Identities, Key Vault, Private Link/NSGs, encryption, and least-privilege access
- Secure ML/MLOps environments, including Databricks, MLflow/model registry, feature stores, model artifact signing, provenance, and runtime isolation
- Connect platform and security telemetry to Microsoft Sentinel and Defender; define alerts and runbooks and support incident response and tabletop exercises
- Manage CVEs and vulnerabilities, publish SBOMs, coordinate mitigations and patches, track exposure windows and SLAs, verify remediation, and report metrics
- Draft and maintain reference architectures, trust-boundary diagrams, data-classification schemes, environment isolation patterns, secret/key-management patterns, and network segmentation
- Contribute to risk assessments, threat modeling, DPIAs, vendor risk reviews, penetration tests, control testing, evidence collection, and audit readiness for ISO 27001, GDPR, EU AI Act, and NIS2 where applicable
- Maintain security baselines and exceptions, own platform security KPIs, ensure retention policies and access reviews, and maintain end-to-end audit trails
Requirements:
- Experience as a DevSecOps / Cloud Security Engineer, or DevOps Engineer with a strong security focus, in Azure and Kubernetes environments
- Hands-on experience with Azure DevOps or GitHub Actions
- Working knowledge of Azure security, including Entra ID, Key Vault, Azure Policy, Defender for Cloud, and Microsoft Sentinel
- Working knowledge of Kubernetes security
- Familiarity with vulnerability management and CVEs, including SBOM creation, dependency/container/IaC scanning, triage and prioritization, remediation workflows, and SLA tracking
- Understanding of Data & AI/ML security, including Databricks, Unity Catalog, SCIM/AAD, MLflow/model registry, secrets, data governance, and privacy-by-design
- Comfortable interfacing with central Security and compliance teams and contributing to audits and group standards
- Ability to translate requirements into practical controls
- Shift-left mindset and ability to collaborate across teams
- Experience with Terraform, policy-as-code, Azure Policy, OPA/Conftest, Checkov/tfsec, RBAC, NetworkPolicies, Pod Security Standards, Gatekeeper/Kyverno, image scanning, CodeQL/Dependabot, and Databricks security is beneficial or relevant to the role
Benefits:
- Work-from-home arrangement, including up to 20 days a year anywhere in the EU
- Regular team events and parties
- Kindergarten grant of €100 per month for employees paying childcare costs
- Anonymous, free professional psychological support
- Internal and external training and career development support
- Fully funded Deutschland Ticket
- Urban Sports Club membership (M package) and sports and health opportunities

















