Logo Commerzbank AG

Cyber Hygiene SecDevOps Engineer - Toolchain

Job

  • Level
    Senior
  • Job Field
    IT, DevOps, Security
  • Employment Type
    Part Time/Full Time
  • Contract Type
    Permanent employment
  • Location
    Frankfurt
  • Working Model
    Hybrid, Onsite
  • Job Summary

    In this role, you will develop an automated cyber hygiene toolchain, integrate security tools, optimize pipelines for vulnerability management, and ensure ITIL-compliant operation and data-driven compliance checks.

    Job Technologies

    Your role in the team

    • As a (Senior) Cyber Hygiene SecDevOps Engineer - Toolchain, you are responsible for the technical development of the Cyber Hygiene Toolchain into an integrated and as automated as possible platform for asset, vulnerability, exposure, and security data - including compliance checks.
    • The focus is not only on the operation of individual security tools but also on their end-to-end integration, automation, and continuous development within the cyber hygiene landscape, as well as ITIL-compliant operation.
    • You ensure that the platform is stable, scalable, audit-proof, and makes a measurable contribution to risk reduction and compliance with security and regulatory requirements.
    • Engineering and further development of the Cyber Hygiene Toolchain design, setup, and continuous optimization of a modern SecDevOps platform for asset, vulnerability, exposure, and compliance data.
    • Integration and automation of security and vulnerability management technologies development of automated pipelines and workflows for end-to-end processing of findings (from scan to remediation).
    • Further development of solutions for Vulnerability Scanning, Exposure Management, Cloud Security, Code/CI/CD Security, Secret Management, Security Posture Management, Compliance Monitoring of IT Assets and Configurations.
    • Integration of scanners, CMDB, asset data, ServiceNow, and remediation processes. Establishment and maintenance of stable interfaces and data flows between scanners, CMDB, asset inventory, ServiceNow SecOps, and remediation teams.
    • Development of APIs, interfaces, and automated workflows Implementation of robust integrations and automations (e.g., event and ticket automation, CI/CD integrations).
    • Improvement of asset coverage, data quality, and finding correlation ensuring a complete and high-quality data foundation as the basis for effective vulnerability, exposure, and compliance management.
    • Development and integration of compliance checks into the platform Implementation of automated configuration and baseline checks Mapping of policies and standards into technical control mechanisms Support in reporting compliance and non-compliance states.
    • Technical onboarding of new technologies and asset classes Planning and implementation of integrations of new security technologies as well as additional platforms, applications, and infrastructure types.
    • Conducting PoCs and evaluating new security technologies analysis, comparison, and assessment regarding functionality, integration capabilities, compliance features, ITIL-compliant operation, and scalability.
    • ITIL-compliant operation of the Cyber Hygiene Toolchain Participation in the design and implementation of ITIL-compliant processes (e.g., Incident, Change, Problem Management) Ensuring a stable, documented, and audit-proof operation of the deployed solutions Contributing to operational and support concepts, including monitoring, logging, and reporting.
    • Translation of technical requirements into scalable technical SecDevOps solutions.
    • Close collaboration with Architecture, Vulnerability Management, and Cyber Hygiene Excellence to implement requirements in modern, automated platform and pipeline architectures.
    • Close collaboration with Architecture, Vulnerability Management, and Cyber Hygiene. Alignment of target architectures, standards, and roadmaps, as well as ensuring seamless end-to-end process integration.

    This text has been machine translated. Show original

    Our expectations of you

    Education

    • Completed university degree (e.g., Computer Science, Business Informatics, Cybersecurity/IT Security) or equivalent with a strong IT/Security focus.

    Qualifications

    • Practical experience with technologies such as Tenable, Qualys, Rapid7, and/or ServiceNow SecOps, ideally including compliance and policy checks.
    • Very good knowledge of APIs, automation, and system integration, ideally in complex enterprise environments.
    • Understanding of Windows, Linux, network, and cloud environments.
    • Knowledge of Azure, GCP, and/or AWS.
    • In-depth knowledge of Vulnerability, Exposure, and Compliance Management (processes, data models, KPIs).
    • Very good technical understanding of complex, heterogeneous enterprise environments as well as the associated operational, support, and compliance processes.
    • Structured, responsible working approach and the ability to operate technical solutions in a stable, secure, audit- and compliance-compliant manner.
    • Strong communication and teamwork skills, as well as enjoyment of working in interdisciplinary security, IT, DevOps, and compliance teams.

    Experience

    • Several years of experience as a DevOps Engineer, Security Engineer, or in a comparable role with a focus on Security Tooling, Vulnerability Management, Security Operations, or Compliance Monitoring.
    • Proven experience in the implementation and operation of ITIL-compliant software solutions (e.g., incident, change, problem management, service and asset management).
    • Experience with SecDevOps practices, CI/CD pipelines, and the integration of security and compliance controls into development and operational processes.
    • Experience with DevSecOps, CI/CD security, code scanning, or secret management is a plus.

    This text has been machine translated. Show original

    What we offer

    • 30 days of vacation.
    • Flexible working.
    • Professional Training & Development.
    • Capital-forming benefits.
    • Friendly working environment.
    • Diverse tasks.
    • Work-Life Balance.

    This text has been machine translated. Show original

    Benefits

    Work-Life-Integration

    Higher Take-Home Pay

    Health, Fitness & Fun

    Topics You Will Work On

    Job Locations

    • Location Frankfurt

      Hessen

      Germany

    About Your Employer

    Commerzbank AG

    Commerzbank AG

    Commerzbank is an internationally-operating commercial bank with locations in nearly 50 countries and 49,000 employees. It offers a comprehensive range of financial services to private, business, and corporate customers. Commerzbank is a reliable and trusted source for all your banking needs.

    Description

  • Company Size
    250+ Employees
  • Company Type
    Established Company
  • Working Model
    Full Remote, Hybrid, Onsite
  • Industry
    Banking, Finance, Insurance
  • Employer reviews

    by devworkplaces.com

    Total

    (1 Review)
    3.6
    • Workingconditions

      4.4
    • Engineering

      3.2
    • Career Growth

      3.6
    • Culture

      3.5
    Show all reviews
    Logo Commerzbank AG

    Cyber Hygiene SecDevOps Engineer - Toolchain

    Location
    Frankfurt
    Working Model
    Hybrid, Onsite
    Diversity
    Open for all genders

    More Jobs