> Markdown version of [/jobs/ext/2690244-sr-platform-security-engineer-zero-trust-and-platform-security](https://www.wearedevelopers.com/jobs/ext/2690244-sr-platform-security-engineer-zero-trust-and-platform-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Platform Security Engineer (Zero Trust and Platform Security) - **Company:** Jobgether - **Location:** Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Computing Platforms, ARM Architecture, User Authentication, Cloud Computing, Cloud Computing Security, Encodings, Cyber Security, Data Centers, Identity and Access Management, InfiniBand, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Network Security, Public Key Infrastructure, Remote Direct Memory Access, Zero Trust Network Access, Security Information and Event Management, Systems Integration, Software Vulnerability Management, AI Infrastructure, Snort (Software), Cloud Platform System, Okta, Containerization, Kubernetes, Hashicorp, Operational Systems, Security Orchestration, Automation & Response - **Published:** September 3, 2026 - **Apply:** https://www.adzuna.de/details/5864886462 ## About the Role * 7+ years of experience in cloud security, infrastructure security engineering, or a closely related discipline, with experience securing large-scale distributed platforms. * Strong understanding of cloud security architecture and practical experience securing Kubernetes and containerized environments. * Experience designing security models for multi-tenant infrastructure and embedding security controls into platform architecture and deployment practices. * Hands-on experience with IAM, authentication and authorization systems, PKI, key management, certificates, and secure identity infrastructure. * Solid knowledge of datacenter and distributed-network security, including segmentation, tenant isolation, encrypted transport, and zero-trust networking principles. * Experience with SIEM platforms, security telemetry, vulnerability management, incident investigation, and security operations. * Strong ability to develop security automation and operational tooling, ideally using Python and/or Go. * Familiarity with technologies such as Wazuh, Snort, TheHive, Cortex, HashiCorp Vault, HashiCorp Boundary, Tailscale, Authentik, Keycloak, and related security platforms is valuable. * Experience with infrastructure networking technologies such as EVPN/VXLAN, VRF, RDMA, InfiniBand, or comparable high-performance environments is advantageous. * Strong analytical and problem-solving skills, with the ability to investigate complex security issues and translate them into practical engineering solutions. * Comfortable collaborating across infrastructure, networking, platform, and security teams, communicating clearly and taking ownership of security outcomes. ## Description This is a senior security engineering opportunity focused on protecting a high-performance GPU cloud platform at scale. You will design and implement zero-trust capabilities across identity, networking, infrastructure, platform, and automation layers. The role combines hands-on engineering with security architecture for complex, distributed, multi-tenant environments. You will help secure Kubernetes, virtualization, storage, networking fabrics, and high-performance AI infrastructure. A major focus will be building automation for threat detection, vulnerability remediation, incident response, and security operations. You will also explore AI-assisted security workflows to improve telemetry analysis, triage, and operational efficiency. Working remotely across Europe, you will collaborate closely with infrastructure, platform, networking, and security teams. Accountabilities * Design and implement zero-trust security architecture, identity-aware access controls, least-privilege models, and secure access paths across infrastructure, control planes, orchestration systems, and operational tooling. * Build and operate secure authentication and authorization capabilities for multi-tenant environments, including IAM integrations, PKI, key management, certificate lifecycle automation, and identity federation. * Secure Kubernetes clusters, container runtimes, virtualization layers, storage systems, networking fabrics, and other components of the underlying cloud infrastructure. * Design and implement network security controls covering segmentation, tenant isolation, encrypted transport, EVPN/VXLAN, VRF isolation, and zero-trust networking, including high-performance RDMA and InfiniBand environments. * Develop security automation that improves vulnerability triage, remediation, detection, incident response, and integration between security and operational systems. * Support security monitoring and incident response by investigating alerts, analyzing vulnerabilities, improving detection coverage, and contributing to post-incident reviews. * Establish patch and vulnerability management strategies across operating systems, kernels, container runtimes, and infrastructure fleets, including automated validation and deployment of security updates. * Build security telemetry pipelines and improve SIEM signal quality through correlation rules, enrichment, automated triage, and integration with broader observability systems. * Develop AI-assisted security workflows and agents that can summarize alerts, correlate events, identify anomalies, and support operators during investigations. * Contribute to security governance, compliance requirements, operational procedures, security metrics, and measurable validation of the platform's security posture. ## Related Videos - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) - [JSON and Beyond](https://www.wearedevelopers.com/videos/968-json-and-beyond) - [Trust Issues: Because Zero-Trust Isn’t Optional Anymore](https://www.wearedevelopers.com/videos/100089-trust-issues-because-zero-trust-isn-t-optional-anymore) ## Related Articles - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Where to Find German Tech Jobs](https://www.wearedevelopers.com/magazine/366-where-to-find-german-tech-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers)