Logo B. Braun Avitum AG

Security & DevSecOps Engineer

New

Job

  • Level
    Experienced
  • Location
    Melsungen
  • Working Model
    Hybrid, Onsite
  • Job Field
    IT, DevOps, Security
  • Employment Type
    Full Time
  • Contract Type
    Permanent employment

Job Summary

In this role, you implement Security-by-Design principles, conduct threat analyses, and automate security states in software development using modern technologies like Java, Docker, and Azure DevOps.

Job Technologies

Your role in the team

  • Within B. Braun Avitum AG, we are looking for a Security & DevSecOps Engineer for the Center of Excellence Active Medical Devices (CoE AMD) in the Research and Development department as soon as possible.
  • In this role, you will lay the foundation for secure and regulatory-compliant software solutions by integrating Security-by-Design principles early into development and operational processes and sustainably enhancing the security, stability, and traceability of our applications through automation.
  • As part of the strategic initiative "B. Braun - The Next Decade," the Smart Therapy Eco-System offers a variety of digital services and applications that add additional value to our customers' medical products.
  • In the Digital Solutions program, we develop distributed client/server solutions for local server environments using technologies such as Java, Spring Boot, Angular, Docker, and Kafka.
  • For automating our software delivery processes, we rely on Jenkins and Azure DevOps.
  • Thereby, you design and optimize build, test, release, and deployment processes, establish repeatable workflows, and contribute to the development of a scalable software factory for secure and maintainable product development.
  • Development of secure architecture concepts for local server, container, and integration landscapes.
  • Conducting structured threat analyses, e.g., according to STRIDE, for new features and technical concepts.
  • Assessment of technical risks and derivation of specific countermeasures.
  • Assessment of vulnerabilities based on their technical and business risks and derivation of targeted measures to reduce the attack surface.
  • Translation of regulatory and organizational requirements into technical security controls, e.g., ISO 27001, IEC 62304, ISO 14971, IEC 81001-5-1, FDA Cybersecurity Guidance, MDR security requirements, or OWASP recommendations.
  • Integration of automated security checks into Jenkins and Azure DevOps.
  • Integration of SAST, DAST, SCA, Secret Scanning, Container Scanning, and Dependency Checks.
  • Co-creation of reusable pipeline templates, security gates, and proof artifacts.
  • Securing Docker-based build, release, and deployment processes.
  • Support for vulnerability management, security monitoring, and incident response processes.
  • Further development of security concepts for the software supply chain, including SBOMs (Software Bill of Materials), artifact signing, provenance verification, and dependency governance.
  • Sparring partner for development, DevOps, testing, and architecture teams.
  • Supporting teams with secure implementations and practical vulnerability mitigation.
  • Building a culture where safety is integrated early, clearly, and without unnecessary friction.

This text has been machine translated. Show original

Our expectations of you

Education

  • Completed degree in Computer Science, Medical Informatics, Software Engineering, Electrical Engineering, or a comparable qualification.

Qualifications

  • Good understanding of modern software development with Java, Spring Boot, Angular, REST APIs, and Microservices.
  • Experience with CI/CD environments, particularly Jenkins and Azure DevOps.
  • Knowledge in Secure Software Development Lifecycle, Vulnerability Management, and Security Testing.
  • Excellent German and English language skills, both written and spoken.
  • Desirable additional qualifications: knowledge in Container Security, Kubernetes Security, SIEM, Policy as Code, or SBOM/Artifact Signing.
  • Certifications such as CISSP, CCSP, Azure Security Engineer, AWS Security Specialty, or Certified DevSecOps Professional.
  • Scripting skills in Python, Bash, or Go for automating recurring security tasks.

Experience

  • Extensive experience in Security Engineering, Application Security, or DevSecOps.
  • Experience with security architectures, threat modeling, and structured risk analyses.
  • Experience with Docker, Git, and automated security checks in build and release processes.
  • Experience with Azure or AWS as well as Infrastructure as Code, such as Terraform.

This text has been machine translated. Show original

What we offer

  • A key role in building a secure software factory in the digital health environment.
  • Direct influence on product security, architecture, and development processes.
  • Modern technology environment with Java, Spring Boot, Angular, Kafka, Docker, Jenkins, and Azure DevOps.
  • Collaboration in agile, interdisciplinary teams with high technical responsibility.
  • Flexible work models and hybrid working.
  • Individual training and development opportunities.
  • The perspective of an internationally active healthcare company.

This text has been machine translated. Show original

Benefits

Higher Take-Home Pay

Topics You Will Work On

Job Locations

  • Location Melsungen

    34212 Hessen

    Germany

About Your Employer

B. Braun Avitum AG

B. Braun Avitum AG

As one of the world's leading medical technology companies, B. Braun's mission is to protect and improve the health of people around the world. For more than 180 years, we have been shaping healthcare with our pioneering spirit and groundbreaking contributions.

Description

  • Company Size
    50-249 Employees
  • Company Type
    Established Company
  • Working Model
    Hybrid, Onsite
  • Industry
    Pharmaceutical Sector, Chemical Industry, Biotech
Logo B. Braun Avitum AG

Security & DevSecOps Engineer

Location
Melsungen
Working Model
Hybrid, Onsite
Diversity
Open for all genders

More Jobs