Introduction text
Schwarz Digits creates the technological foundation for digital sovereignty in Europe. As the IT and digital division of the Schwarz Group, we develop and manage the IT infrastructures for the retail divisions Lidl and Kaufland, as well as Schwarz Production and PreZero. At the same time, we operate as an independent provider in the external market to support companies across Europe in their digital transformation. We bundle our core services in the areas of Cloud, Cyber Security, Data & AI, Communication, and Workspace.
Join us and contribute to digital sovereignty in Europe. With us, you will work at the intersection of agility and security: You will benefit from fast decision-making processes, enjoy genuine creative freedom in your projects, and be able to build upon the stable foundation of the Schwarz Group.
Your Tasks
- Drive the architecture and resilient operation of security infrastructure within our high-performance OpenStack and Kubernetes environments.
- Develop scalable automation solutions (in Go and Python) for security processes, enforcing Infrastructure as Code (IaC) as an uncompromising standard for all deployments.
- Design and operate centralized Identity and Secret Management infrastructure (e.g., HashiCorp Vault, PKI, SPIFFE/SPIRE) to provide cryptographic primitives to product teams.
- Engineer and maintain dynamic Kubernetes guardrails using Admission Controllers and Policy-as-Code solutions (e.g., Kyverno, OPA Gatekeeper) to enforce strict Pod Security Standards.
- Conduct proactive threat hunting at the network and host levels (eBPF, Sysmon) and develop deterministic detection use cases (SIEM/SOAR) for the real-time analysis of massive telemetry streams.
- Own the technical evaluation, seamless integration, and lifecycle management of enterprise-grade security solutions in a cloud-native context.
- Act as a technical mentor for platform teams, enabling "Secure-by-Default" deployments through the provision of hardened architectures, paved roads, and APIs.
- Define and strictly monitor Security SLIs/SLOs, guaranteeing rapid degradation and recovery during incidents through rigorous Incident Response Engineering.
- Engage in the full lifecycle of our security services by championing a "you build it, you run it" philosophy and a blameless post-mortem culture to continuously harden our products.
Your Profile
- "Security by Design" is not a buzzword to you, but a measurable architectural principle. You possess a deep understanding of distributed systems, failure domains and security overall.
- Deep, battle-tested expertise one or more of the following: securing Linux kernels and the Kubernetes Control Plane, with extensive experience leveraging primitives like AppArmor, SELinux, Seccomp, and eBPF.
- Strong software development and scripting capabilities, preferably in Go (Golang) and Python, alongside excellent Linux and Bash proficiency.
- Solid experience in designing complex SIEM architectures, performing high-throughput log parsing, and executing forensic network analysis.
- Proven experience with CI/CD pipelines, GitOps workflows, and IaC frameworks (e.g., Terraform, Ansible).
- Fluent English language skills (good German skills are a plus) for effective collaboration in an international engineering environment.