Senior Platform Security / DevSecOps Engineer (m/f/d)
Overview
Senior Platform Security / DevSecOps Engineer (m/f/d)
As Senior Platform Security / DevSecOps Engineer at Meyer Talent Acquisition, you have a unique opportunity to take ownership of Platform Security in a cloud-native environment, helping to build and harden the internal platform that powers modern engineering teams. You'll play a key role in embedding security across the entire software delivery lifecycle while shaping scalable, secure-by-default infrastructure and engineering practices.
Working closely with Platform Engineers, Product Teams, and Engineering Leadership, you'll drive initiatives across CI/CD security, Kubernetes security, software supply chain security, policy-as-code, secrets management, and cloud infrastructure. The role combines hands-on technical execution with strategic ownership, making a direct impact on the company's security posture and long-term platform architecture.
Your Responsibilities
- Embed security across the full CI/CD lifecycle — integrating image scanning, artifact signing, static analysis, and policy gates into every stage of the delivery workflow
- Define and enforce software supply chain security practices, including SBOM generation, container provenance, dependency tracking, and admission control policies
- Own the secrets lifecycle end-to-end across all environments — provisioning, rotation, encryption, revocation, and audit — ensuring no cleartext secrets reach code or CI artifacts
- Write and maintain policy-as-code rules that enforce security baselines across Kubernetes workloads, covering image restrictions, pod security standards, RBAC, and network controls
- Build and maintain security-relevant observability: audit log pipelines, anomaly alerting, failed-auth monitoring, and drift detection to support both operational response and regulatory evidence collection
- Enable development teams to ship securely without friction — provide secure-by-default CI templates, deployment scaffolding, and clear documentation so security is built in from the start
- Investigate and respond to security incidents across infrastructure, delivery, and runtime layers, and continuously improve the platform's security posture across all environments
What You Bring
- Hands-on experience securing CI/CD pipelines, Kubernetes environments, and cloud-native infrastructure (AWS/EKS) in production - you become effective quickly in existing platform setups
- Practical depth in software supply chain security: SBOM generation, image scanning, vulnerability triage, signing, and policy-based promotion workflows
- Strong working knowledge of secrets management, container and OS hardening, Kubernetes security (PSA, RBAC, seccomp), and GitOps-based delivery automation
- Ability to think strategically about security architecture while executing hands-on — writing policy-as-code, automating compliance tasks, and closing gaps pragmatically
- Clear, concise written and spoken English; comfortable communicating with both engineers and non-technical stakeholders in a distributed, async-first environment
- High level of ownership and reliability — you document what you build, take responsibility for what you operate, and raise the baseline without waiting to be asked
Core Competencies
- Security as a habit, not a gate - You integrate security into workflows naturally, building guardrails that enable teams rather than slow them down, with a measurable impact on risk reduction and delivery confidence.
- Engineering judgment - You evaluate tradeoffs pragmatically, choose solutions appropriate to the company's maturity stage, and avoid over-engineering while keeping the long-term architecture sound.
- Operational ownership - You take end-to-end responsibility for what you build — from design and implementation through documentation, incident response, and continuous improvement.
- Compliance awareness - You understand the implications of operating in a regulated financial environment (DORA, MiCA) and translate compliance requirements into concrete, auditable platform controls.
- Collaborative mindset - You work effectively across platform, product, and leadership teams in a distributed setting, communicating clearly and enabling others to work securely without friction.
If you enjoy building secure cloud platforms, automating security controls, and enabling engineering teams to move fast without compromising security, we'd be happy to share further details in a confidential conversation. We look forward to hearing from you.
Apply for this position
Fill out the form below to submit your application.