Summary
Checkmk creates hybrid IT monitoring software for cloud-native and traditional infrastructures and applications. The DevSecOps Cloud Security specialist will lead the evolution of the company’s security practices by hardening and automating AWS, Kubernetes, and CI/CD environments while advising engineering teams on high-assurance security standards.
Responsibilities
- Lead the Security Evolution: Take ownership of our security roadmap, moving from a developer-led security model to a specialized, automated DevSecOps practice
- Advanced AWS Hardening: Deepen our infrastructure security by implementing advanced AWS configurations (e.g., Service Control Policies, refined IAM boundaries, and specialized GuardDuty/Macie integration)
- Automate the "Shift-Left": Integrate sophisticated security gates into our existing CI/CD pipelines, ensuring that hardening is a silent, automated partner to our deployment process
- Kubernetes Security Experience: Enhance our EKS security posture, implementing advanced network policies, runtime security, and automated vulnerability remediation
- Bridge the Gap: Act as the primary consultant for the engineering team, helping to balance rapid feature development with high-assurance security standards
Skills
- The Experience: 4+ years in DevOps/SRE, with a clear specialization in Cloud Security for high-availability SaaS products
- AWS Power User: You have a proven track record of securing complex AWS environments. You know how to leverage AWS-native security tools to their full potential without creating friction for developers
- Infrastructure-as-Code: You are an expert in Terraform, believing that if a security policy isn't in code, it doesn't exist
- Container & K8s Depth: Deep knowledge of the CNCF security landscape - you know how to protect the cluster, the pod, and the code
- Collaborative Leadership: You are a "Security Builder and Enabler," not a "Security Blocker." You enjoy teaching others and building consensus on technical standards
- Analytical Mindset: You enjoy the "chess game" of security - anticipating risks before they manifest and building systems that fail safely
- Language: Business fluent English
- German is a plus
Qualifications
Must Haves
- The Experience: 4+ years in DevOps/SRE, with a clear specialization in Cloud Security for high-availability SaaS products
- AWS Power User: You have a proven track record of securing complex AWS environments. You know how to leverage AWS-native security tools to their full potential without creating friction for developers
- Infrastructure-as-Code: You are an expert in Terraform, believing that if a security policy isn't in code, it doesn't exist
- Container & K8s Depth: Deep knowledge of the CNCF security landscape - you know how to protect the cluster, the pod, and the code
- Collaborative Leadership: You are a "Security Builder and Enabler," not a "Security Blocker." You enjoy teaching others and building consensus on technical standards
- Analytical Mindset: You enjoy the "chess game" of security - anticipating risks before they manifest and building systems that fail safely
- Language: Business fluent English
Nice to Haves
Benefits
- Flexible and family-friendly working conditions in a stable environment
- Workation: opportunity to work 6 weeks within the EU to extend your vacation
- Wide range of sports and wellness offers from Wellpass, with access to over 9,000 sports and wellness offers
- Wide range of education and training opportunities
- Fully remote work or high flexibility between mobile work and an office in one of the most beautiful, central districts of Munich
- Regular onsite events of all sorts, including company outings, team events, the Checkmk Conference, and Conference After Party