Introduction text

Schwarz Digits creates the technological foundation for digital sovereignty in Europe. As the IT and digital division of the Schwarz Group, we develop and manage the IT infrastructures for the retail divisions Lidl and Kaufland, as well as Schwarz Production and PreZero. At the same time, we operate as an independent provider in the external market to support companies across Europe in their digital transformation. We bundle our core services in the areas of Cloud, Cyber Security, Data & AI, Communication, and Workspace.

Join us and contribute to digital sovereignty in Europe. With us, you will work at the intersection of agility and security: You will benefit from fast decision-making processes, enjoy genuine creative freedom in your projects, and be able to build upon the stable foundation of the Schwarz Group.

 

The IaaS domain owns the compute, storage and networking primitives customers run their workloads on. We are looking for a skilled DevSecOps Engineer, who will be responsible for securing our software supply chain and automating release management. This role involves implementing robust security standards across our pipelines, managing complex dependency ecosystems, and driving operational excellence through automated release processes and observability.

Your Tasks

  • Software Supply Chain Security (SSCS): Implement full pipeline traceability and transparency, including the generation and enforcement of SBOM and SLSA attestations for all builds.
  • Dependency Hardening: Manage global dependency security by enforcing strict pinning and locking, and utilizing internal proxies/mirrors to verify and secure all components.
  • Vulnerability Management: Establish automated CVE scanning and reporting within the CI/CD pipelines, and implement runtime security scans on clusters.
  • Release Automation: Automate the release rollout process to reduce manual intervention and enhance overall development velocity.
  • Visibility & Traceability: Build comprehensive monitoring and logging systems for releases, ensuring auditability, clear documentation, and visibility of deployed artifact versions.

Your Profile

  • Proven experience in DevSecOps, with a strong focus on software supply chain security.
  • In-depth knowledge of CI/CD pipeline security, including SBOM/SLSA standards and artifact signing.
  • Experience in dependency management, vulnerability scanning (CVE), and securing containerized environments (e.g., Kubernetes).
  • Strong background in automation, infrastructure-as-code, and release management.
  • Analytical mindset with a focus on observability, monitoring, and operational transparency.
4170