Senior DevOps / Platform Engineer with DevSecOps and Cloud Architecture focus in Germany
Start: ASAP
Long-term project
Candidate location: EU !!!
Location: Berlin (Hybrid) or fully remote
Department: Technology / Digital Transformation
You'll own the infrastructure, automation, and delivery pipelines that power our internal platforms and integrations — working across cloud (Azure/GCP), containerized workloads, and enterprise systems (SAP, NestJS-based services, and internal tooling). This is a senior, hands-on role with real architectural ownership: you'll shape how we build, secure, and scale our platform, not just maintain what already exists.
What You'll Do
• Own CI/CD and delivery pipelines end-to-end — design, harden, and continuously improve pipelines with built-in security gates (SAST/DAST, dependency and container scanning, IaC compliance checks) rather than bolting security on after the fact.
• Build and evolve infrastructure as code (Terraform, and/or Pulumi) across cloud environments, treating Git as the single source of truth (GitOps) with full auditability and rollback.
• Design and operate Kubernetes-based container platforms — clusters, Helm charts, and where relevant, service mesh (Istio/Linkerd) for multi-service, multi-cluster environments.
• Drive platform engineering initiatives — build internal developer platforms / self-service tooling that reduce cognitive load for application teams (standardized environments, templated deployments, golden paths).
• Own the technical pipeline for the Secure Software Development Lifecycle (SSDLC), including security gates at each stage of build and release.
• Drive vulnerability mitigation — triage findings from scanning tools and coordinate timely remediation across teams.
• Own patch management — track, prioritize, and apply patches across infrastructure and dependencies on a defined cadence.
• Bring AI into operations (AIOps) — apply anomaly detection, intelligent alerting, and automation to reduce noise and enable self-healing pipelines and infrastructure; use AI-assisted engineering tools (e.g., Cursor, Claude Code) daily as a core part of how you build and ship.
• Own observability — instrument systems for metrics, logs, and traces; build dashboards and alerting that reflect real business and system risk, not just infrastructure noise.
• Take responsibility for cost (FinOps) — monitor cloud spend, rightsize resources, and build budget guardrails across environments.
• Support MLOps/AI infrastructure needs as our AI tooling and agentic workflows scale — model/version registries, secure API access patterns (e.g., workload identity federation), and sandboxing for autonomous agents.
• Act as a technical bridge between development, security, operations, and business stakeholders — explain trade-offs clearly, coordinate incidents calmly, and contribute to architecture discussions, not just implementation.
What You Bring
Core technical foundation!!!
• 5+ years in DevOps/SRE/Platform Engineering roles, with at least 2 years operating at a senior/lead level (system design, mentoring, on-call ownership). Strong hands-on DevSecOps experience, including SAST, DAST, SCA, container image scanning, secrets management, vulnerability remediation, security policy enforcement, and Secure Software Development Lifecycle (SSDLC).
• Deep hands-on experience with at least one major cloud provider (Azure or GCP strongly preferred given our stack; AWS a plus), including IAM, networking, and workload identity patterns. Strong understanding of networking fundamentals, including TCP/IP, HTTP/HTTPS, TLS, UDP, DNS, load balancing, ingress, and cloud networking architectures.
• Strong command of containerization and orchestration: Docker, Kubernetes in production, Helm.Strong Linux administration skills, including file permissions, ownership, process management, networking tools, shell scripting, and troubleshooting production systems.
• Proven experience with Infrastructure as Code (Terraform preferred) and GitOps workflows (ArgoCD, Flux, or equivalent).
• Solid scripting/automation skills (Python, Bash, or Go) and comfort reading/writing CI/CD pipeline configs (GitHub Actions, GitLab CI, Jenkins, or Azure DevOps).
• Required: daily hands-on experience with AI-assisted coding tools (Cursor, Claude Code, GitHub Copilot, or similar) as part of your development and infrastructure workflow — this is a must-have, not a nice-to-have. Experience with modern AI platforms or services such as Amazon Bedrock, Azure AI Foundry, Vertex AI, OpenSRE, HolmesGPT, LangChain, MCP, or similar is highly desirable.
Security & compliance
• Practical DevSecOps experience: vulnerability scanning (Snyk, OWASP Dependency-Check or similar), secrets management, and policy-as-code/compliance tooling.
• Understanding of zero-trust network design and enterprise IAM governance (relevant to regulated, multi-entity organizations).
Emerging / 2026-relevant skills
• Familiarity with AIOps concepts and tools — using AI/ML signals for incident detection, capacity planning, or pipeline self-healing.
• Working knowledge of platform engineering principles and building internal developer platforms (IDPs).
• Exposure to MLOps or AI infrastructure (GPU scheduling, model registries, agent sandboxing/network isolation) is a strong plus given our growing AI governance and agentic tooling initiatives.
• Comfort operating in a FinOps mindset — cost visibility and optimization as a shared responsibility, not a separate team's job.
Soft skills (non-negotiable at senior level)
• Strong written and verbal communication — able to explain technical trade-offs to both engineers and non-technical stakeholders.
• Calm, structured incident coordination under pressure.
• A systems-thinking mindset: understanding failure modes and designing for resilience rather than reacting to outages.
• Collaborative, low-ego approach to working across dev, security, QA, and business teams.
Nice to have
• Experience in real estate, financial services, or another regulated, multi-entity enterprise environment.
• Familiarity with SAP-adjacent integration landscapes or large-scale enterprise system migrations.
• Cloud certifications (Azure DevOps Engineer Expert, Google Professional Cloud DevOps Engineer, or equivalent).