75% remote: Infrastructure Security Architect Cloud

Nemensis
Frankfurt am Main, Germany
7 days ago
Apply on www.adzuna.de
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Cloud Computing Cyber Security Software Design Patterns Distributed Data Store Distributed Systems Python (Programming Language) Key Management PostgreSQL Sherwood Applied Business Security Architecture VMware Infrastructure
+6 more
Virtual Machines Virtualization Technology Software Vulnerability Management Fastapi SDN Network Bare Metal

Job description

The architecture group within the Infrastructure Product Line (Infra PL) of the project is responsible for designing and evolving a distributed system that provides basic virtual infrastructure such as object storage or virtual machines to other product lines within the program. The Infra PL stack represents the foundational layer of the platform and covers a wide set of technologies, ranging from bare-metal hardware and multi-vendor networking and storage solutions to in-house developed software services and APIs. We are looking to further improve our overall security posture in this complex environment and are seeking the help of experienced security experts.

Objective: Improve the security posture of Infra PL products, services and applications through the creation of documented security requirements, architecture standards, security assessments and governance artifacts aligned with program requirements and NFRs.

Tasks:

  • Translate threats, organizational policies and NFRs into implementable requirements, design patterns and engineering guardrails.
  • Coordinate and lead security reviews for software and core infrastructure systems.
  • Create and maintain written communication and documentation, including
  • Security standards
  • Risk statements
  • Architecture principles
  • Architecture Decision Records (ADRs)
  • Security control definitions
  • Governance artifacts

Requirements

Skills (must-have):

  • Extensive experience (15+ years) in similar architecture and security roles with broad knowledge across core infrastructure (compute, network, storage) and software
  • Owned or substantially influenced the security architecture of a complex distributed system
  • Demonstrated ability to work with senior engineers, product owners, operations teams, enterprise security functions, vendors, auditors, and architects from other teams.
  • Designed an identity or authorization model spanning multiple services and infrastructure components
  • Resolved difficult security trade-offs involving availability, usability, delivery pressure, or organizational boundaries
  • Worked across multiple infrastructure and software domains
  • Participated in security incidents, major vulnerability remediation, security audits and design reviews
  • Significant experience in leading structured threat-modelling efforts
  • Proven experience integrating platforms with an external identity providers and different protocols
  • Proven experience in designing authentication flows for interactive users, service-to-service calls, administrator and break-glass access.
  • Expert level understanding and hands on experience with secret, certificate and key management systems
  • Professional experience with container and Kubernetes security concepts

Skills (should-have):

  • Experience with virtualization, software-defined networking, distributed storage and bare-metal provisioning technologies
  • Experience with SPIFFE/SPIRE or another workload-identity platform
  • Experience operating in restricted, sovereign, or otherwise highly controlled environments
  • Deep Kubernetes security experience, ideally across self-hosted control planes
  • Hands-on security experience with Python, FastAPI, Pydantic, PostgreSQL, and common Python authentication or authorization libraries
  • Any relevant certifications, such as:
  • CISSP, CCSP, or equivalent broad security certification
  • SABSA or comparable security-architecture training
  • CNCF CKS

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.de
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:33 min

Connecting frontends via a FastAPI proxy backend layer

Saoussen Chaabnia Saoussen Chaabnia · Europe 2026 Virtual

1:11 min

Running high-performance edge computing on bare metal servers

Josip Stuhli Josip Stuhli · Coffee With Developers

5:37 min

Extensibility and programmability features of the PostgreSQL database

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

4:40 min

Assessing common Kubernetes security incidents and misconfigurations

Rico Komenda Rico Komenda · World Congress 2025

1:42 min

Introduction to the fast API web framework

Sebastián Ramírez · World Congress 2022

Videos

See all

Related articles

See all