Job
- Level
- Lead
- Job Field
- IT, Security
- Employment Type
- Part Time/Full Time
- Contract Type
- Permanent employment
- Location
- Darmstadt
- Working Model
- Onsite
Job Summary
In this role, you will develop security strategies and standards, improve CI/CD pipelines, automate controls, and implement security requirements to ensure secure software development.
Job Technologies
Your role in the team
- In your role as Lead Security Engineer in the Platform and Engineering Enablement team, you will own the security engineering vision, strategy, standards, and delivery roadmap across our products and shared platforms.
- You will simplify and harden CI/CD pipelines, establish secure defaults, improve software supply chain and AWS cloud security, and automate controls and audit evidence using GitHub, JFrog, Atlassian, and AWS.
- Working with engineering, enterprise security, legal, privacy, risk, and compliance, you will translate ISO 27001, SOC 2, the EU Cyber Resilience Act, customer, and internal requirements into practical controls.
- You will combine long-term direction with hands-on implementation and enable teams to deliver secure software efficiently.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- You have defined security strategies and standards and turned them into production-ready implementations.
- You have secured CI/CD pipelines, source control, build systems, artifacts, software releases, and cloud platforms using tools such as GitHub, JFrog, and AWS.
- You understand risk-based control design and frameworks such as ISO 27001, SOC 2, or the EU Cyber Resilience Act and can translate requirements into automated controls and evidence.
Experience
- You have extensive hands-on experience in security engineering, platform engineering, application security, cloud security, or a related field, with technical ownership across multiple teams.
- You have practical experience with identity and access management, infrastructure as code, vulnerability management, security testing, threat modeling, secrets, and software supply-chain security.
- You communicate clearly, influence across teams, and balance security, developer experience, delivery speed, and operational resilience.
- Experience with software bills of materials, provenance, attestations, artifact signing, release integrity, or security considerations for AI-assisted software development is desirable.
- Experience with Atlassian tools or relevant certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or ISO 27001 Lead Implementer or Lead Auditor is desirable.
This text has been machine translated. Show original
What we offer
- We are committed to creating access and opportunities for all to develop and grow at your own pace.
- Join us in building a culture of inclusion and belonging that impacts millions and empowers everyone to work their magic and champion human progress!
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Topics You Will Work On
Job Locations
About Your Employer
Merck KGaA
At Merck, we are driven by our discoveries and technologies, which are based on our deep scientific research. We are an innovative science and technology company constantly striving to improve and make an impact.
Description
- Founding Year
- 1668
- Language
- English
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Pharmaceutical Sector, Chemical Industry, Biotech
Employer reviews
by devworkplaces.com
Total
(1 Review)3.5
Career Growth
3.2Engineering
3.3Culture
3.5Workingconditions
4.0
