Job
- Level
- Senior
- Job Field
- IT, DevOps, Back End
- Employment Type
- Full Time
- Contract Type
- Freelancer
- Location
- Bonn
- Working Model
- Hybrid, Onsite
Job Summary
You will develop a secure Software Supply Chain, redesign the artifact gateway, and integrate automated security checks for various artifacts in a Kubernetes environment.
Job Technologies
Your role in the team
- The further development of a secure software supply chain is the focus at our client.
- For the further expansion of the highly secure, physically isolated Multi Cloud platform, software artifacts from the Internet must be transferred automatically, securely, and traceably into the isolated environments.
- The task is to rethink the existing concept of the artifact gate and further develop it into a flexible Secure Supply Chain for the various technology stacks.
- Automated retrieval of artifacts from predefined external sources using tools like ARC.
- Development and operation of Kubernetes operators in Golang and API extensions in the context of Software Supply Chain Security.
- Scalable integration of Kubernetes-compatible antivirus scanners into the artifact import pipeline.
- Support for various formats: OCI Container Images (Docker), Helm Charts, and generic bulk files.
- Verification of artifact integrity.
- Bundling and compression of artifacts into transportable containers/formats.
- Preparation of data for physical or logical media break.
- Operation of a scalable, multi-tenant capable Artefact Registry infrastructure on Kubernetes for delivering artifacts to internal users.
- Further development of Kubernetes operators for automated management of an artifact management, procurement, and testing system.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Good knowledge of SDLC principles, code version control, Git.
- Expertise in Linux know-how, automation, and scripting.
- Infrastructure as Code (IaC), GitOps.
- Solid knowledge of Go (Golang) and Python, and building Kubernetes Operators.
- Knowledge of SBOMs (Software Bill of Materials) and automated security scanners, e.g., based on CNCF Falco.
- Proficient handling of documentation in User Stories and Features in Jira.
Experience
- Proven experience in DevOps or DevSecOps, particularly in the development and utilization of CI/CD pipelines.
- Experience in setting up and operating Kubernetes.
- Experience in operating and utilizing CEPH (and rook), especially Object Storage.
- Practical experience with OCI Registries on Kubernetes, e.g., Harbor, Nexus Repo, Artifactory, Zot.
- Practical experience with artifact signing tools, experience in handling cryptographic hashes (SHA-256/512), and the concept of provenance.
This text has been machine translated. Show original
What we offer
- Project location: Bonn.
- Period: October 12, 2026, to December 31, 2026.
- Work mix: 45 days remote / 5 days on-site.
- Remote only possible within Germany.
- Willingness to SÜ2 according to § 9 SÜG Confidentiality/Sabotage Protection.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
Topics You Will Work On
Job Locations
About Your Employer
virtual7 GmbH
With more than 100 experts, virtual7 is deployed nationwide. We develop solutions around digitalization for federal government, states, ministries and agencies. This creates value for citizens and authorities.
Description
- Company Size
- 1-49 Employees
- Company Type
- Established Company
- Working Model
- Full Remote, Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication