Security Engineer - DevSecOps & SDLC Security
Role details
Job location
Tech stack
Job description
Home-Office Ansible CI/CD (Continuous Integration/Delivery) Cloud Computing Developer Kubernetes Microsoft Azure
+4 Top
Join us. Let's care for tomorrow.
At Allianz Global Investors we foster a culture of professionalism, fulfilment, and an inclusive working environment. Do you want to be part of a leading active asset management company? Then join us now!
This position is part of AllianzGI's Development, Test & Transformation (DTT) team, which leads the delivery of secure, resilient, and scalable technology across a global hybrid cloud environment. The role centers on integrating security throughout the software development lifecycle (SDLC), cloud-native infrastructure, and automation platforms. Core responsibilities include implementing robust technical controls, evaluating and integrating security tools into developer workflows, advising engineering teams and security champions, and ensuring alignment with regulatory and internal compliance frameworks. The position places strong emphasis on infrastructure-as-code practices and AI-driven enhancements to developer experience, while also playing a key role in audit preparedness and cross-functional collaboration.
This role is based in our Frankfurt or Munich office.
What you will do
- Implement and oversee security controls across SDLC and infrastructure layers
- Test-drive and evaluate security tools for integration into CI/CD pipelines and developer workflows
- Advise development teams and security champions on the secure use of provided tools and platforms
- Define and enforce secure SDLC practices aligned with DORA, KAIT, BAIT, and AllianzGI's internal frameworks
- Apply security best practices to cloud-native infrastructure, with emphasis on Microsoft's Well-Architected Framework
- Secure and govern Infrastructure as Code (IaC) using Terraform Cloud, Bicep, and Ansible
- Implement policy-as-code using Open Policy Agent (OPA) across infrastructure and pipelines
- Automate security controls, evidence generation, and release promotion workflows
- Champion security-by-design principles across architecture, development, and operations
- Collaborate with governance, application, and infrastructure teams to map technologies to compliance controls
- Contribute to the Security Champion Community of Practice (CoP)
- Apply CIS Benchmarks to harden systems and validate configurations
- Support compliance dashboards and DORA metrics implementation in our IDP
- Optionally contribute to areas such as Kubernetes, Azure role assignments, VM usage, and private endpoint architecture
- Serve as a sparring partner for internal and external auditors, working closely with internal process and application owners to ensure alignment of technical controls with audit and compliance expectations., * We empower our employees by ensuring flexible work arrangements that maintain a balance between performance, productivity, career development and personal priorities (e.g., hybrid model/ flexible working hours)
- Securing your future: Access to company pension/savings plans
- Shared success: Company share purchasing plan
- Support for what matters: Mental health and wellbeing programs
- Investments in your career: Career opportunities within the entire Allianz Group
- Investments in your skills: Comprehensive learning and development offerings, including certifications and professional qualifications
- … and so much more!
Requirements
- 5+ years of experience in SDLC security, application security, or DevSecOps
- Hands-on experience with CI/CD pipelines, GitHub, and JFrog
- Strong knowledge of Terraform Cloud, Bicep, Ansible, and cloud security principles
- Familiarity with Open Policy Agent (OPA), Microsoft's Well-Architected Framework, and CIS Benchmarks
- Experience with security testing tools and vulnerability management
- Proven ability to operate effectively in regulated environments (DORA, KAIT, BAIT)
- Excellent communication skills across technical and business stakeholders
- Fluent in English; additional languages are a plus.
Preferred:
- Degree in Information Technology or a related field
- Certifications such as CSSLP, GCSA, AZ-500, CISSP, CISM, or CISA
- Experience with internal developer platforms (IDPs) and platform engineering
- Exposure to Agile environments and enterprise transformation programs
- Familiarity with AI-enhanced developer workflows and their security implications.