EnglishWillDo

DevSecOps Engineer - STACKIT (m/f/d)

Schwarz Digits KG · Bad Friedrichshall, Germany

No German requiredPosted 5 days ago
Apply for this job

You apply on the site where the job is posted. I never handle applications.

  • Location

Am Campus 1

74177 Bad Friedrichshall

  • Employment Area

IT - Cloud Services

  • Level

Experienced professional

  • Working Model

Full-time

  • Reference ID

4170 Schwarz Digits creates the technological foundation for digital sovereignty in Europe. As the IT and digital division of the Schwarz Group, we develop and manage the IT infrastructures for the retail divisions Lidl and Kaufland, as well as Schwarz Production and PreZero. At the same time, we operate as an independent provider in the external market to support companies across Europe in their digital transformation. We bundle our core services in the areas of Cloud, Cyber Security, Data & AI, Communication, and Workspace.

Join us and contribute to digital sovereignty in Europe. With us, you will work at the intersection of agility and security: You will benefit from fast decision-making processes, enjoy genuine creative freedom in your projects, and be able to build upon the stable foundation of the Schwarz Group.

The IaaS domain owns the compute, storage and networking primitives customers run their workloads on. We are looking for a skilled DevSecOps Engineer, who will be responsible for securing our software supply chain and automating release management. This role involves implementing robust security standards across our pipelines, managing complex dependency ecosystems, and driving operational excellence through automated release processes and observability.

Your Tasks

  • Software Supply Chain Security (SSCS): Implement full pipeline traceability and transparency, including the generation and enforcement of SBOM and SLSA attestations for all builds.
  • Dependency Hardening: Manage global dependency security by enforcing strict pinning and locking, and utilizing internal proxies/mirrors to verify and secure all components.
  • Vulnerability Management: Establish automated CVE scanning and reporting within the CI/CD pipelines, and implement runtime security scans on clusters.
  • Release Automation: Automate the release rollout process to reduce manual intervention and enhance overall development velocity.
  • Visibility & Traceability: Build comprehensive monitoring and logging systems for releases, ensuring auditability, clear documentation, and visibility of deployed artifact versions.

Your Profile

  • Proven experience in DevSecOps, with a strong focus on software supply chain security.
  • In-depth knowledge of CI/CD pipeline security, including SBOM/SLSA standards and artifact signing.
  • Experience in dependency management, vulnerability scanning (CVE), and securing containerized environments (e.g., Kubernetes).
  • Strong background in automation, infrastructure-as-code, and release management.
  • Analytical mindset with a focus on observability, monitoring, and operational transparency.

Your contact

Heiko Kiefer

Recruiter

  • E-Mail:recruiting@mail.schwarz What happens once you applied?

1

Application

We love simplicity. Apply quickly and easily digitally, even without registration. 2

Checkup

Together with the department, we take a look at your documents. 3

Interview

When you first get to know each other, the focus is on both your personality and your professional suitability. 4

Contract offer

Have we convinced each other? Then your employment contract is on its way to you digitally by e-mail. 5

Welcome

Your first day of work with is about to begin and your individual onboarding in the team begins. We look forward to seeing you!