Security Engineer – Kubernetes

Il y a 2 heures

, Belgique Cloud Power Luxembourg Temps plein

We are looking for an experienced Security Engineer to join a complex IT environment and contribute to securing a large-scale container platform.


You will join a team specialized in container operations and platforms and act as the security reference for topics related to infrastructure, applications, and DevSecOps practices.

This is a technical, operational, and cross-functional role, involving close collaboration with development teams, engineers, architects, and various stakeholders.


Your Responsibilities :


As a Security Engineer, you will be responsible for :

  • Advising teams on the security of container platforms and the applications deployed on them.
  • Defining, implementing, and monitoring security best practices in containerized environments.
  • Conducting threat and risk assessments, preferably using the STRIDE methodology.
  • Integrating security controls into DevSecOps and CI/CD processes.
  • Implementing and using SAST, DAST, vulnerability scanning, and compliance checking tools.
  • Supporting the development and continuous improvement of a Cloud-Native Application Protection approach.
  • Defining, implementing, and monitoring security and runtime policies.
  • Identifying, analyzing, and tracking vulnerabilities in containers and container images.
  • Assessing security risks and proposing appropriate mitigation measures.
  • Supporting and coaching developers and technical teams on Secure Software Development practices and container security.
  • Explaining security requirements and measures to both technical and non-technical stakeholders.
  • Collaborating with various internal and external partners in a multidisciplinary environment.
  • Taking ownership of security-related topics across the container platform and ensuring their end-to-end follow-up.


Your Technical Expertise :


You have solid professional experience in IT Security and ideally have experience with several of the following technologies and concepts :

  • Proven professional experience in cybersecurity / IT security.
  • Strong experience with container technologies and container platforms.
  • Excellent knowledge of Kubernetes.
  • Experience with Red Hat OpenShift 4 is a strong plus.
  • Experience with Cloud-Native Application Protection platforms.
  • Knowledge of Threat Modeling, preferably using STRIDE.
  • Experience with DevSecOps and integrating security into software development processes.
  • Good knowledge of CI/CD pipelines, preferably GitLab CI.
  • Experience with SAST and DAST tools.
  • Knowledge of vulnerability management and tracking.
  • Experience identifying and addressing vulnerabilities in container images.
  • Strong understanding of operating systems, networks, storage, and application technologies.
  • Good knowledge of current cybersecurity risks and experience implementing appropriate mitigation measures.
  • Knowledge of cloud technologies such as Azure, AWS, and/or GCP, including their security risks and key considerations.
  • Practical experience with scripting.
  • Relevant cloud or security certifications are a plus.


Your Profile :


Beyond your technical expertise, you are able to bridge security requirements with operational realities.

You can communicate security recommendations clearly and constructively while working pragmatically with developers, engineers, and other stakeholders to find workable solutions.


You are:

  • Autonomous and able to take ownership of your responsibilities.
  • Comfortable working in a multidisciplinary environment.
  • Proactive and willing to take initiative.
  • A strong communicator with excellent interpersonal skills.
  • Able to explain complex security topics in a clear and understandable way.
  • Comfortable collaborating with different stakeholders and building relationships with internal and external partners.
  • Willing to share knowledge and coach colleagues on security best practices.


Excellent written and spoken Dutch is required.


If you are passionate about cybersecurity, Kubernetes, Cloud, and DevSecOps and would like to work on a large-scale container platform within a complex IT environment, we would be happy to hear from you.