Job
- Level
- Experienced
- Job Field
- IT, DevOps, Security
- Employment Type
- Full Time
- Contract Type
- Temporary employment
- Location
- Munich
- Working Model
- Hybrid, Onsite
Job Summary
You are responsible for the security of our AI platform, conducting risk analyses, hardening Kubernetes environments, automating secrets management, and developing security monitoring to ensure safety.
Job Technologies
Your role in the team
- You are responsible for the technical security of our AI platform based on Kubernetes and StackIT.
- You conduct threat modeling and risk analyses for new AI applications.
- You accompany rollouts with security reviews and clear technical recommendations.
- You harden Kubernetes environments, for example through RBAC, Network Policies, Pod Security Standards, Admission Control, and Policy as Code.
- You work with existing Policy-as-Code approaches, particularly Kyverno.
- You secure the software supply chain, for example with signed container images, SBOMs, vulnerability scans, Trivy, and image hardening.
- You manage and automate Secrets Management with Vault, including identities, tokens, and certificate lifecycle management.
- You develop security monitoring further, for example with audit logs, security metrics, Prometheus, Grafana, Loki, and Alertmanager.
- You assist with vulnerability management and security incidents within the platform context.
- You translate requirements from BSI Grundschutz, ISO 27001, and GDPR into concrete technical measures.
- You advise DevOps and development teams to ensure that security is practically implemented in everyday operations.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Very good understanding of Kubernetes Security, especially RBAC, Network Policies, Pod Security Standards, Admission Control, and Policy as Code.
- Experience with Secrets Management, ideally with Vault.
- Good understanding of Kubernetes, Terraform, Helm, and GitOps.
- Knowledge of BSI Basic Protection, ISO 27001, and GDPR.
- Pragmatic security mindset: You want to enable security, not unnecessarily complicate processes.
- Good German language skills (minimum C1 level) so that you can confidently communicate with internal teams, partners, and specialist departments.
Experience
- Several years of experience in the field of Cloud, Platform, or IT Security.
- Experience with container and supply chain security, such as Trivy, CVE management, image hardening, signed images, or SBOMs.
- Experience with Threat Modeling, Risk Analyses, or Security Incident Response.
- Experience with monitoring and logging solutions such as Prometheus, Grafana, Loki, and Alertmanager.
- Experience with C5, KRITIS, or NIS2 is a plus but not a must.
This text has been machine translated. Show original
What we offer
- Approachable, value-driven leadership and corporate culture that support innovative and autonomous working.
- Motivated team and exciting, challenging tasks.
- Secure job with an attractive salary and usually permanent contracts.
- Flexible working hours: flexitime and up to 60% remote work.
- 30 vacation days + 3 paid days off per year.
- Workation: Up to 30 days within the European Economic Area (including Iceland, Liechtenstein, Norway, Switzerland) - with team coordination.
- Part-time studies, targeted further training, and talent management for personal development.
- Modern, centrally located offices with a rooftop terrace, underground parking, and a pleasant working environment.
- Corporate benefits, e.g., discounted Deutschlandticket, subsidized childcare, and rotating employee events.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
More net
Topics that you deal with on the job
Job Locations
This is your employer
AKDB
The Anstalt für Kommunale Datenverarbeitung in Bayern is a leading IT service provider in Germany. As a complete provider, it supplies software solutions and services for all core areas of municipal administration.
Description
- Founding year
- 1971
- Company Type
- Digital Agency
- Working Model
- Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication
Dev Reviews
by devworkplaces.com
Total
(1 Review)3.4
Career Growth
3.2Engineering
3.2Culture
3.5Workingconditions
4.0