Logo SonarSource

Infrastructure Security Engineer

Job

  • Level
    Experienced
  • Job Field
    IT, Security
  • Employment Type
    Full Time
  • Contract Type
    Permanent employment
  • Location
    Bochum
  • Working Model
    Onsite
  • Job Summary

    In this role, you will design and implement security solutions and automation for identity platforms and endpoints, working closely with IT and security teams to ensure security controls are effectively integrated.

    Job Technologies

    Your role in the team

    • We are still at the beginning of our growth journey and are continuously introducing new processes, technologies, and tools. In this role, you will:
    • Be a pivotal engineering contributor to the design, implementation, and operation of security controls and automation across our identity platforms, endpoints, and core IT services.
    • Own key parts of our IdP and access automation stack (e.g., SSO, SCIM, group-based access, JIT access), ensuring that users get the right access at the right time with strong controls and auditability.
    • Design and maintain security monitoring, alerting, and SIEM integrations that give us real-time visibility into identity, endpoint, and SaaS risks.
    • Partner with IT Ops, Information Security, and Infrastructure Engineering to ensure security controls are deeply integrated into operations (incident management, change, and problem processes), not bolted on.
    • Use and champion AI tooling to make security operations more efficient - from alert triage and runbook execution to knowledge retrieval and reporting.
    • Help define and improve how we measure the reliability and effectiveness of our security controls (SLIs/SLOs, error budgets, and dashboards), making risk and performance visible and actionable to stakeholders.
    • Security Monitoring, Alerting & SIEM Ownership: Working with the Information Security team, design, implement, and maintain alerting rules, dashboards, and runbooks across our SIEM and logging platforms, with a focus on identity, access, and SaaS security signals. Continuously tune alerts to reduce noise, improve fidelity, and align with error budgets and SLOs for critical security and identity services.
    • Endpoint Defense In Depth: Architect and implement our multilayer endpoint defence systems (e.g. Crowdstrike, Cyberark, Cloudflare, secure browser policies), balancing risk against usability in coordination with the Information Security team.
    • Identity Platform & Access Automation: Build and maintain automation for our identity platforms (e.g., SSO, SCIM provisioning, group-based access policies, lifecycle workflows) in partnership with Information Security. Implement guardrails and policy-as-code for identity, ensuring changes are reviewed, tested, and auditable before reaching production.
    • Infrastructure as Code & Security Controls as Code: Use IaC and configuration management (e.g., Terraform, Ansible, or similar) plus scripting languages (e.g., Python, Go) to deploy and manage security tooling, integrations, and policies. Treat security controls (e.g., logging, scanning, hardening, secret management) as software artifacts that can be versioned, tested, and rolled back safely.
    • Observability & Integration with Core IT Operations: Ensure that logging, metrics, and tracing for security-relevant systems (IdP, VPN, endpoint protection, critical SaaS) are robust, accurate, and integrated into our observability stack. Integrate security events and automations with ITSM and incident management workflows, enabling fast routing, triage, and resolution.
    • Incident Response & Post-Incident Engineering: Participate in the on-call rotation for relevant security and identity services. Lead or contribute to post-incident reviews, turning root causes into preventative engineering changes (new alerts, automations, guardrails, or documentation) that reduce MTTR and recurrence.
    • AI-Enabled Security Operations: Use AI tooling (e.g., LLM-based assistants, automation platforms) to accelerate alert triage, enrichment, and investigation, while keeping humans in control of decisions. Identify opportunities to embed AI in security and IT operations workflows (e.g., threat intelligence and alert correlation) and help implement these safely and effectively.

    This text has been machine translated. Show original

    Our expectations of you

    Qualifications

    • AI Fluency: Comfortable using modern AI tooling (e.g., LLM-based assistants, automation frameworks) as part of daily work for analysis, content generation, and workflow automation. Ability to reason about where AI is and isn't appropriate in security and operations, balancing speed with risk and control.

    Experience

    • Security Engineering & Operations Background: Significant hands-on experience (4-7 years) in security engineering, security operations, or closely related roles in modern, fast-paced environments (e.g., SaaS, enterprise IT, cloud-native infrastructure).
    • Identity & Access Management Expertise: Practical experience operating IdPs and IAM systems at scale (e.g., Okta, Azure AD, or similar), including SSO, MFA, lifecycle management, and least-privilege policies. Experience designing and implementing automated provisioning and deprovisioning (e.g., SCIM, HRIS integrations, group-based and role-based access models).
    • SIEM, Logging & Observability: Proven experience with SIEM and observability platforms (e.g., ELK/EFK, Splunk, Datadog, or similar), including writing and tuning detection rules, building dashboards, and working with large-scale log ingestion. Comfort working with SLIs/SLOs and error budgets for critical services, and using these to guide priorities for hardening and automation.
    • Automation & Infrastructure as Code: Extensive experience with IaC and configuration management tools (e.g., Terraform, CloudFormation, Ansible, or similar) and with scripting/programming languages (e.g., Python, Go, or equivalent) to automate security and operational tasks. Proven track record of transforming manual, repetitive operational work into reliable automation and self-service capabilities.
    • Security Controls Implementation: Experience implementing and operating security controls as code: vulnerability scanning, configuration baselines, secret management (e.g., HashiCorp Vault), key rotation, and certificate management.
    • Incident Management & Cross-Functional Collaboration: Demonstrated experience participating in or leading incident response, root cause analysis, and post-incident follow-through in partnership with IT Ops, Security, and Engineering. Strong communication skills in English, able to explain complex security and operational topics to both technical and non-technical audiences.

    This text has been machine translated. Show original

    What we offer

    • This role is based in Bochum. We are unable to consider candidates unwilling to be in Bochum, but we are willing to relocate the right candidate.

    This text has been machine translated. Show original

    Topics that you deal with on the job

    Job Locations

    • Location Bochum

      Nordrhein-Westfalen

      Germany

    This is your employer

    SonarSource

    SonarSource

    SonarSource, based in Vernier, Switzerland, develops both open-source and commercial software solutions for the continuous analysis of code quality and security. With products like SonarQube, SonarCloud, and SonarLint, the company supports over 25 programming languages and is used by more than 7 million developers worldwide. Its roots in the open-source community are strong, and the company values transparency and continuous improvement.

    Description

  • Company Type
    Established Company
  • Working Model
    Hybrid, Onsite
  • Industry
    Internet, IT, Telecommunication
  • Logo SonarSource

    Infrastructure Security Engineer

    Location
    Bochum
    Working Model
    Onsite
    Diversity
    Open for all genders
    English Only
    English only required

    More Jobs