Senior, DevSecOps Engineering (m/f/d)
Core
Secure the end-to-end Azure & Kubernetes Data & AI platform by integrating security into CI/CD, infrastructure, data, and ML workloads.
Role type
Senior DevSecOps Engineer (Cloud Security)
Builds
Secure CI/CD pipelines, hardened Kubernetes clusters, protected cloud identities, and secure ML/MLOps environments.
Domain
Cloud Security, DevSecOps, Data & AI/ML Security
Deliverable
production ML models | infrastructure
Required skills
Azure DevOps/GitHub Actions, Terraform, Kubernetes security, Azure security services (Entra ID, Key Vault, Defender, Sentinel), vulnerability management, Databricks security, policy-as-code, container scanning, IaC scanning
Preferred skills
OPA/Gatekeeper/Kyverno, MLflow, Unity Catalog, SBOM management, threat modeling, audit readiness
Technologies
Azure DevOps, GitHub Actions, Terraform, Azure Policy, OPA, Conftest, Checkov, tfsec, Kubernetes, Entra ID, Key Vault, Microsoft Sentinel, Defender for Cloud, Databricks, MLflow, Unity Catalog, Gatekeeper, Kyverno, Trivy, CodeQL, Dependabot
Responsibilities
Build and maintain secure CI/CD pipelines with secrets hygiene and supply-chain hardening; Automate security guardrails in infrastructure using policy-as-code; Harden Kubernetes with RBAC, NetworkPolicies, and secret management; Protect cloud identities and data with encryption and least-privilege access; Secure ML/MLOps workloads including model artifact signing and runtime isolation; Monitor security telemetry and support incident response; Manage CVEs and vulnerabilities including SBOM creation and remediation tracking; Draft and maintain reference architectures for secure AI services; Contribute to compliance efforts including risk assessments, threat modeling, and audit readiness.
Seniority
Senior, hands-on IC