Job
- Level
- Senior
- Job Field
- IT, DevOps, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Monheim
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will design security architectures for a hybrid Azure infrastructure and containerized environments, while securing internet-facing applications against threats like DDoS and API abuse.
Job Technologies
Your role in the team
- We are seeking an experienced Cloud & Security Architect to join our team and lead the architecture, resilience, and security posture of our enterprise application platform.
- In this role, you will bridge the gap between Azure Cloud Architecture, Security Engineering, and Modern Application Development.
- Our application suite is built with C# and .NET and is deployed across a hybrid environment spanning Microsoft Azure, On-Premises infrastructure, and Docker / Kubernetes (K8s).
- Because our application is exposed directly to the public internet, ensuring robust security - ranging from edge defense and zero-trust networking to secure coding practices and container hardening - is at the core of this role.
- Drive and cultivate a security-first and DevOps-oriented culture across software engineering and infrastructure teams.
- Leiten Sie praktische Workshops, etablieren Sie Sicherheits-Exzellenzprogramme und betreuen Sie Entwickler in sicherer Codierung und automatisierten Betriebspraktiken.
- Design and enforce edge protection strategies (Azure Front Door, WAF, Application Gateway, DDoS Protection) for all internet-facing APIs and services.
- Enforce Zero-Trust Network Architecture, strict IP/GEO filtering, rate-limiting, and modern API security protocols (OAuth2, OIDC, mTLS).
- Architect, standardize, and help maintain secure CI/CD pipelines (Azure DevOps).
- Own automated Infrastructure as Code (IaC) deployment workflows.
- Embed continuous security gates (SAST, DAST, dependency scanning, secret detection) into the build and release lifecycle.
- Architect and maintain cloud infrastructure in Azure aligned with cloud security best practices and the Microsoft Well-Architected Framework.
- Design secure hybrid connectivity between Azure, on-premises data centers, and containerized environments using Azure Arc, ExpressRoute, and VPN gateways.
- Define and enforce security controls across containerized workloads (Docker, AKS, and On-Prem Kubernetes).
- Implement pod security standards, network policies (Calico/Cilium), image scanning, and container runtime threat detection.
- Coordinate and execute recurring security governance best practices, including regular user access reviews (IAM/PIM audits), cloud application security assessments, penetration testing, and automated policy compliance across all hybrid environments.
- Übernehmen Sie die Verantwortung für die Übersetzung techniklastiger Geschäfts- und Produktziele in detaillierte technische Anforderungsspezifikationen, Systemdesign-Dokumente und Architekturentscheidungsaufzeichnungen (ADRs).
- Collaborate closely with Product Owners and Developers to define, document, and manage technical user stories and acceptance criteria.
This text has been machine translated. Show original
Our expectations of you
Education
- Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related field required (as the baseline requirement).
- Master's degree in Computer Science, Cybersecurity, or Information Technology strongly recommended.
Qualifications
- Self-motivated, hands-on practitioner with a "doer" mentality, taking strong personal ownership and pride in the quality, security, and elegance of technical deliverables.
- Proven ability to lead, mentor, and inspire engineering teams to continuously raise the bar and strive for excellence.
- Strong practical knowledge of Microsoft Azure services and security tools (Defender for Cloud, Microsoft Entra ID, Azure Key Vault, Azure Policy, Network Security Groups, Private Endpoints).
- Solid understanding of distributed systems, event-driven messaging systems (e.g., RabbitMQ, Kafka, Azure Service Bus), data persistence patterns, and API gateway integrations.
- Microsoft Azure Associate Certifications (Preferred/Targeted): Azure Security Engineer Associate (AZ-500), Azure Administrator Associate (AZ-104), Azure Developer Associate (AZ-204), Azure Network Engineer Associate (AZ-700).
- Expert / Industry Certifications (A plus): Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Certified: Azure Solutions Architect Expert (AZ-305), Certified Kubernetes Security Specialist (CKS), or CISSP.
Experience
- 7+ Jahre Erfahrung in Cloud-Architektur, Cybersicherheit und/oder DevSecOps-Rollen.
- Hands-on experience defending public-facing, internet-exposed applications against threats (e.g., volumetric DDoS, credential stuffing, API abuse, SQLi).
- Experience in driving automated infrastructure provisioning, continuous deployment, and telemetry across hybrid Azure, on-premises, and Kubernetes environments, ensuring zero-downtime deployments, high availability, and operational resilience.
- Starker Hintergrund in Softwarearchitektur mit nachweislicher Erfahrung in der Gestaltung und Absicherung von Microservices-Architekturen.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
- 🧳Relocation Support
- 🚌Excellent Traffic Connections
- 🏝Extra Holidays
- 🍼Day Care for Kids
- 🅿️Employee Parking Space
- 🏠Home Office
- ⏰Flexible Working Hours
Health, Fitness & Fun
Higher Take-Home Pay
- 🚙Company Car
- 📱Company Phone for Private Use
- 🛍Employee Discount
- 💻Company Notebook for Private Use
- 👴🏻Company Retirement Provision
Food & Drink
Topics You Will Work On
Job Locations
About Your Employer
JENOPTIK AG
As a global technology company, we primarily focus on optical technologies and provide our products and services to the photonics market. Our key target markets include the semiconductor industry, medical technology, automotive and machinery engineering, robotics, as well as traffic safety and security. We are also active in the aerospace, defense, and security sectors.
Description
- Company Size
- 250+ Employees
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Industry, Production