High quality consulting. On demand. Delivered by top professionals.
CI/CD Engineer – Security & Compliance
Location
Germany
Posted
20 days ago
Salary
0
Seniority
Senior
Job Description
CI/CD Engineer – Security & Compliance
Interval Group
• Design, implement, and maintain robust infrastructure solutions while ensuring the highest standards of integrity, confidentiality, and system availability. • Focus on empowering engineering teams by exposing security tools through self-service interfaces and automating complex compliance workflows. • Central role in optimising continuous integration and delivery across a diverse service landscape. • Analyse program requirements to design secure, scalable architectures that address complex integration and compliance needs. • Develop and configure CI/CD pipelines featuring built-in security scanning, compliance checks, and automated validation. • Implement secure configurations, access controls, and encryption for repositories, systems, and deployment workflows. • Automate infrastructure provisioning and management using tools such as Terraform or OpenTofu. • Design user-friendly self-service interfaces and APIs to allow developers to access security tools seamlessly. • Drive automation efforts for the generation and validation of Software Bill of Materials (SBOMs) and KBOMs during build processes. • Conduct continuous vulnerability management, risk assessments, and threat modelling to identify and mitigate potential weaknesses. • Maintain system availability through disaster recovery planning, incident response, and routine audits of system logs and user access. • Create comprehensive documentation, including step-by-step guides, architecture diagrams, and FAQs for internal and external stakeholders. • Collaborate with cross-functional teams to resolve issues, implement new features, and ensure systems run optimally under data protection requirements.
Job Requirements
- Proven experience implementing end-to-end DevSecOps practices and embedding security controls into platform layers.
- Extensive hands-on experience designing, operating, and troubleshooting large-scale Kubernetes platforms, including deep knowledge of CNI, RBAC, and admission controllers.
- Strong proficiency with GitOps workflows using Argo CD or FluxCD in production environments.
- Direct experience with Infrastructure-as-Code (IaC) using Terraform or OpenTofu.
- Hands-on expertise with Google Cloud Platform, specifically GKE operations, IAM workload identity, and VPC networking.
- Operational experience with artifact registries such as Harbor and security tooling like Trivy, Dependency-Track, or DefectDojo.
- Solid understanding of software supply chain security, including artifact signing, provenance, and SBOM standards like CycloneDX.
- Advanced experience building observability stacks centered around Prometheus and Grafana, including custom security-focused dashboards.
- Strong background in operating and scaling GitLab architectures for large CI workloads.
- Deep understanding of encryption mechanisms, asymmetric cryptography, and PKI.
Benefits
- Flexible working hours
- Freedom to choose your own projects
- Access to exciting projects in various industries
- Support for advancing your career
- Competitive pay
- Dedicated team assistance
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
Staff Site Reliability Engineer
Domino Data LabThe Enterprise MLOps platform powering over 20% of the Fortune 100
• Lead the development of Domino's internal AI-assisted reliability tooling, including systems that analyze tickets, logs, traces, and documentation to help teams resolve outages faster with less recurring toil • Improve the observability coverage and signal quality for our most critical customer-facing systems, so engineers have more to work with throughout the development and support lifecycle • Own incident response end-to-end, from detection to remediation, and leave each problem space better documented, better understood, and less likely to recur • Guide the development of customer and user-facing observability tools within our products • Define and mature SLO/SLI frameworks for priority services, turning abstract reliability goals into measurable, actionable standards • Scale cloud operations practices for Domino’s single-tenant SaaS offering, and work with engineering teams to improve the reliability and repeatability of customer deployments and upgrades • Mentor other engineers and shape how SRE is practiced at Domino, including incident response workflows, operational readiness expectations, and post-incident learning culture
Senior Site Reliability Engineer – B2B Contract
futureproof consultingData, analytics and cybersecurity staffing. We connect professionals and companies to deliver successful projects.
• Lead reliability initiatives across production platforms and services • Define and manage SLOs, SLIs, SLAs, error budgets, and availability targets • Design and implement scalable, resilient cloud-native architectures • Automate infrastructure and deployments using IaC and CI/CD best practices • Build and maintain monitoring, logging, tracing, and alerting solutions • Drive incident management, troubleshooting, root cause analysis, and postmortems • Improve operational maturity through automation, runbooks, and best practices • Mentor engineers and support knowledge sharing across teams • Collaborate with product, security, platform, and vendor teams globally • Perform capacity planning, performance optimization, and reliability analysis • Maintain technical documentation and compliance-related artifacts where required
Senior Site Reliability Engineer
ShippoFounded in 2013, Shippo is a logistics and supply company that provides shipping services to retailers, ecommerce platforms, marketplaces, and more. Operating from its headquarters
Role Description - Shipping & handling responsibilities - Design, scale, and secure infrastructure to stay ahead of business needs through: - Fault-tolerant architecture design - Performance testing, profiling, and tuning - Capacity planning - Design, build, deploy, and maintain automation, monitoring, and alerting systems, as well as: - Design, implement, and test disaster recovery solutions - Ensure scalability and maintainability through: - Microservices adoption - Decoupling of concerns and data model - Queuing of jobs and application layering - Enhance and maintain our CI/CD pipeline for smooth and safe production releases via automated testing and verification - Verify and ensure performance and correctness of systems in response time and throughput - Participate in peer reviews and testing and contribute to automated test suites and in design reviews for new features, products, and systems - Participate in an on-call rotation Qualifications - Experience developing, managing, and troubleshooting highly available distributed systems, including operational experience with Kubernetes in a production environment - Extensive expertise with at least one public cloud provider (AWS, GCP, Azure) - Exceptional verbal, written, and interpersonal communication skills - Interest in and understanding of best-in-class security practices, and automation and testing methods - Familiarity with configuration and maintenance of common infrastructure components such as Redis, Elasticsearch, and Hadoop - Deep understanding of customer needs and passion for customer success - BS or MS degree in Computer Science or equivalent experience Requirements - Advanced knowledge of managing and optimizing PostgreSQL server configuration - 3+ years of experience in software development - Experience with: - Managing service meshes (e.g. Istio) - Defining and monitoring Service-Level Objectives (SLOs) and Service-Level Agreements (SLAs) to ensure that systems meet reliability and performance targets - Monitoring Tools like New Relic, Prometheus, Grafana, and/or Datadog - OpenTelemetry knowledge for distributed tracing and metrics collection and experience on using it in production environments - Managing Python and Golang applications in production - Microservices architectures - DevOps tooling such as Docker, Terraform, ArgoCD, ArgoWorkflows, CircleCI, Github Actions, New Relic, PagerDuty, etc. - AWS/Cloud services such as EKS, EC2, S3, Lambda, Route 53, CloudFront, Cloudflare, IAM, etc. Benefits - Here at Shippo, we celebrate inclusivity and are committed to creating equal access to opportunities for people from all backgrounds, perspectives, and geographies. These values define who we are and everything we do. - All qualified individuals are encouraged to apply. If you need assistance, or a reasonable accommodation during the application and recruiting process, please contact us at accommodations@goshippo.com Company Description - Our people, much like the packages we help ship, are all over the world. - Through our remote-first program, “Shippos Everywhere”, our roles can be based anywhere in the US with the exception of Delaware, Nevada, Ohio, Oregon, Hawaii, New Mexico, and West Virginia. - Many roles can be based internationally. - For locations outside of the US and Ireland, the employment contracts are powered by Rippling.com.
• Build, deploy safely and incrementally and operate critical production systems with focus on scalability, reliability, observability, performance and security. • Monitor, support and enhance developer experience across services. • Build automation to remove toil and efficiently operate production systems. • Proactively monitor, respond to, and enhance alerts and set up automated alert handling • Create and maintain the incident response runbooks. • Triage platform/infrastructural issues and help Arista software engineers in their triages. • Engage with 3rd party vendor support. • Write postmortem documents and build solutions to avoid incidents from repeating. • Plan and communicate maintenance windows on production systems. • Work with Arista’s product development teams to identify infrastructural issues that are causing bottlenecks and limitations in their workflows. • Design and implement solutions to resolve them. • Survey and adopt best practices around infrastructure/platform to maintain secure, scalable and fault-tolerant systems. • Study the design and sufficient implementation details of OSS systems for better triage and fix resolution.




