Sr Platform Security Engineer (Zero Trust and Platform Security) in Germany - Remote, Thüringen at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr Platform Security Engineer (Zero Trust and Platform Security) based in Germany.
This is a senior security engineering opportunity focused on protecting a high-performance GPU cloud platform at scale.
You will design and implement zero-trust capabilities across identity, networking, infrastructure, platform, and automation layers.
The role combines hands-on engineering with security architecture for complex, distributed, multi-tenant environments.
You will help secure Kubernetes, virtualization, storage, networking fabrics, and high-performance AI infrastructure.
A major focus will be building automation for threat detection, vulnerability remediation, incident response, and security operations.
You will also explore AI-assisted security workflows to improve telemetry analysis, triage, and operational efficiency.
Working remotely across Europe, you will collaborate closely with infrastructure, platform, networking, and security teams.
- Design and implement zero-trust security architecture, identity-aware access controls, least-privilege models, and secure access paths across infrastructure, control planes, orchestration systems, and operational tooling.
- Build and operate secure authentication and authorization capabilities for multi-tenant environments, including IAM integrations, PKI, key management, certificate lifecycle automation, and identity federation.
- Secure Kubernetes clusters, container runtimes, virtualization layers, storage systems, networking fabrics, and other components of the underlying cloud infrastructure.
- Design and implement network security controls covering segmentation, tenant isolation, encrypted transport, EVPN/VXLAN, VRF isolation, and zero-trust networking, including high-performance RDMA and InfiniBand environments.
- Develop security automation that improves vulnerability triage, remediation, detection, incident response, and integration between security and operational systems.
- Support security monitoring and incident response by investigating alerts, analyzing vulnerabilities, improving detection coverage, and contributing to post-incident reviews.
- Establish patch and vulnerability management strategies across operating systems, kernels, container runtimes, and infrastructure fleets, including automated validation and deployment of security updates.
- Build security telemetry pipelines and improve SIEM signal quality through correlation rules, enrichment, automated triage, and integration with broader observability systems.
- Develop AI-assisted security workflows and agents that can summarize alerts, correlate events, identify anomalies, and support operators during investigations.
- Contribute to security governance, compliance requirements, operational procedures, security metrics, and measurable validation of the platform’s security posture.
- 7+ years of experience in cloud security, infrastructure security engineering, or a closely related discipline, with experience securing large-scale distributed platforms.
- Strong understanding of cloud security architecture and practical experience securing Kubernetes and containerized environments.
- Experience designing security models for multi-tenant infrastructure and embedding security controls into platform architecture and deployment practices.
- Hands-on experience with IAM, authentication and authorization systems, PKI, key management, certificates, and secure identity infrastructure.
- Solid knowledge of datacenter and distributed-network security, including segmentation, tenant isolation, encrypted transport, and zero-trust networking principles.
- Experience with SIEM platforms, security telemetry, vulnerability management, incident investigation, and security operations.
- Strong ability to develop security automation and operational tooling, ideally using Python and/or Go.
- Familiarity with technologies such as Wazuh, Snort, TheHive, Cortex, HashiCorp Vault, HashiCorp Boundary, Tailscale, Authentik, Keycloak, and related security platforms is valuable.
- Experience with infrastructure networking technologies such as EVPN/VXLAN, VRF, RDMA, InfiniBand, or comparable high-performance environments is advantageous.
- Strong analytical and problem-solving skills, with the ability to investigate complex security issues and translate them into practical engineering solutions.
- Comfortable collaborating across infrastructure, networking, platform, and security teams, communicating clearly and taking ownership of security outcomes.
- Attractive compensation package aligned with your expertise, experience, transferable skills, and market conditions.
- Remote work opportunity across Europe with a flexible, hybrid-friendly working approach.
- Friendly, international, and diverse work environment.
- Opportunity to join a fast-growing scale-up working on advanced GPU cloud and AI infrastructure.
- Meaningful technical challenges involving zero-trust security, distributed systems, high-performance infrastructure, and AI-assisted security operations.
- Opportunities for career growth, learning, and professional development.
- Inclusive workplace committed to equal opportunity and diversity.
- Full-time permanent or freelance contract options, depending on the engagement.