Senior, DevSecOps Engineering (m/f/d)
Redcare Pharmacy11 hours ago
Remote, GermanySenior
Responsibilities
- Build and maintain secure CI/CD pipelines with secrets hygiene, signed artifacts, SBOMs, SAST/DAST, container scanning, least-privilege service connections, and supply-chain hardening.
- Automate Terraform-based security guardrails using policy-as-code, Azure Policy, OPA/Conftest, and continuous IaC scanning.
- Harden Kubernetes with RBAC, NetworkPolicies, Pod Security Standards, secret management, image signing and scanning, and admission policies.
- Protect Azure identities, data, keys, networks, and access through Entra ID, Managed Identities, Key Vault, Private Link, NSGs, encryption, and just-in-time access.
- Secure Databricks and ML/MLOps workloads, including Unity Catalog, secret scopes, MLflow, model registries, feature stores, artifact signing, provenance, and runtime isolation.
- Connect platform and security telemetry to Microsoft Sentinel and Defender, define alerts and runbooks, and support incident response and tabletop exercises.
- Manage SBOMs, vulnerability scans, CVE triage, remediation workflows, exposure windows, SLAs, and security metrics.
- Develop secure reference architectures, trust-boundary diagrams, data-classification schemes, environment isolation patterns, and network segmentation for AI services.
- Support risk assessments, threat modeling, DPIAs, vendor risk reviews, penetration tests, control testing, audit evidence collection, and audit readiness.
- Maintain security baselines and exceptions, platform security KPIs, retention policies, access reviews, and end-to-end audit trails.
Requirements
- Experience as a DevSecOps or Cloud Security Engineer, or as a DevOps Engineer with a strong security focus, in Azure and Kubernetes environments.
- Hands-on experience with Azure DevOps or GitHub Actions and automation of security guardrails and pipeline checks.
- Working knowledge of Azure security services including Entra ID, Key Vault, Azure Policy, Defender for Cloud, and Microsoft Sentinel.
- Knowledge of Kubernetes security, vulnerability management, CVEs, SBOM creation, dependency/container/IaC scanning, prioritization, remediation workflows, and SLA tracking.
- Understanding of Data and AI/ML security, including Databricks, Unity Catalog, SCIM/AAD, MLflow/model registries, secrets, data governance, and privacy-by-design.
- Ability to collaborate with central Security and compliance teams, contribute to audits and group standards, and translate requirements into practical controls.
- Experience with ACR image scanning, Defender, Trivy, OPA/Gatekeeper, Kyverno, CodeQL, Dependabot, Checkov, tfsec, and Databricks security is a plus.
- Understanding of AI-specific security risks such as prompt injection, data exfiltration, and model theft is relevant to the role.
Benefits
- Work-from-home arrangements, including up to 20 days per year working anywhere in the EU when the role does not require office presence.
- Team-building events and regular company celebrations.
- Kindergarten childcare grant of €100 per month.
- Anonymous, free mental-health support from professional psychologists.
- Internal and external training and career-development support.
- Fully funded Deutschland Ticket.
- Urban Sports Club M membership package and other health and sports opportunities.
Tech Stack
About Redcare Pharmacy
Redcare Pharmacy is a publicly listed online pharmacy and healthcare e-commerce company serving consumers across seven European countries. It sells prescription and OTC medicines, health and personal-care products, and operates a marketplace and retail-media platform for brands. Founded in 2001 and headquartered in Sevenum, Netherlands, it runs major distribution centers in Sevenum, Milan, and Pilsen and traces its roots to Shop Apotheke Europe.