Job
- Level
- Experienced
- Location
- Melsungen
- Working Model
- Hybrid, Onsite
- Job Field
- IT, DevOps, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
Job Summary
In this role, you implement Security-by-Design principles, conduct threat analyses, and automate security states in software development using modern technologies like Java, Docker, and Azure DevOps.
Job Technologies
Your role in the team
- Within B. Braun Avitum AG, we are looking for a Security & DevSecOps Engineer for the Center of Excellence Active Medical Devices (CoE AMD) in the Research and Development department as soon as possible.
- In this role, you will lay the foundation for secure and regulatory-compliant software solutions by integrating Security-by-Design principles early into development and operational processes and sustainably enhancing the security, stability, and traceability of our applications through automation.
- As part of the strategic initiative "B. Braun - The Next Decade," the Smart Therapy Eco-System offers a variety of digital services and applications that add additional value to our customers' medical products.
- In the Digital Solutions program, we develop distributed client/server solutions for local server environments using technologies such as Java, Spring Boot, Angular, Docker, and Kafka.
- For automating our software delivery processes, we rely on Jenkins and Azure DevOps.
- Thereby, you design and optimize build, test, release, and deployment processes, establish repeatable workflows, and contribute to the development of a scalable software factory for secure and maintainable product development.
- Development of secure architecture concepts for local server, container, and integration landscapes.
- Conducting structured threat analyses, e.g., according to STRIDE, for new features and technical concepts.
- Assessment of technical risks and derivation of specific countermeasures.
- Assessment of vulnerabilities based on their technical and business risks and derivation of targeted measures to reduce the attack surface.
- Translation of regulatory and organizational requirements into technical security controls, e.g., ISO 27001, IEC 62304, ISO 14971, IEC 81001-5-1, FDA Cybersecurity Guidance, MDR security requirements, or OWASP recommendations.
- Integration of automated security checks into Jenkins and Azure DevOps.
- Integration of SAST, DAST, SCA, Secret Scanning, Container Scanning, and Dependency Checks.
- Co-creation of reusable pipeline templates, security gates, and proof artifacts.
- Securing Docker-based build, release, and deployment processes.
- Support for vulnerability management, security monitoring, and incident response processes.
- Further development of security concepts for the software supply chain, including SBOMs (Software Bill of Materials), artifact signing, provenance verification, and dependency governance.
- Sparring partner for development, DevOps, testing, and architecture teams.
- Supporting teams with secure implementations and practical vulnerability mitigation.
- Building a culture where safety is integrated early, clearly, and without unnecessary friction.
This text has been machine translated. Show original
Our expectations of you
Education
- Completed degree in Computer Science, Medical Informatics, Software Engineering, Electrical Engineering, or a comparable qualification.
Qualifications
- Good understanding of modern software development with Java, Spring Boot, Angular, REST APIs, and Microservices.
- Experience with CI/CD environments, particularly Jenkins and Azure DevOps.
- Knowledge in Secure Software Development Lifecycle, Vulnerability Management, and Security Testing.
- Excellent German and English language skills, both written and spoken.
- Desirable additional qualifications: knowledge in Container Security, Kubernetes Security, SIEM, Policy as Code, or SBOM/Artifact Signing.
- Certifications such as CISSP, CCSP, Azure Security Engineer, AWS Security Specialty, or Certified DevSecOps Professional.
- Scripting skills in Python, Bash, or Go for automating recurring security tasks.
Experience
- Extensive experience in Security Engineering, Application Security, or DevSecOps.
- Experience with security architectures, threat modeling, and structured risk analyses.
- Experience with Docker, Git, and automated security checks in build and release processes.
- Experience with Azure or AWS as well as Infrastructure as Code, such as Terraform.
This text has been machine translated. Show original
What we offer
- A key role in building a secure software factory in the digital health environment.
- Direct influence on product security, architecture, and development processes.
- Modern technology environment with Java, Spring Boot, Angular, Kafka, Docker, Jenkins, and Azure DevOps.
- Collaboration in agile, interdisciplinary teams with high technical responsibility.
- Flexible work models and hybrid working.
- Individual training and development opportunities.
- The perspective of an internationally active healthcare company.
This text has been machine translated. Show original
Benefits
Higher Take-Home Pay
Topics You Will Work On
Job Locations
About Your Employer
B. Braun Avitum AG
As one of the world's leading medical technology companies, B. Braun's mission is to protect and improve the health of people around the world. For more than 180 years, we have been shaping healthcare with our pioneering spirit and groundbreaking contributions.
Description
- Company Size
- 50-249 Employees
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Pharmaceutical Sector, Chemical Industry, Biotech