This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Senior Cloud Security Engineer at Aignostics, you will be a key member of our Platform Engineering & IT department, reporting to the Head of Platform Engineering & IT. Working hand in hand with our team and external collaborators in academia and industry, you will safeguard the infrastructure that powers digital pathology innovation. You'll own security end-to-end — from edge deployments at partner sites and workforce endpoint devices through to GKE clusters, Cloud Run, storage services, network architecture, central IAM, and AI training pipelines. You'll be responsible for conceptualizing, leading, and owning security initiatives that protect sensitive healthcare data, ensure compliance with industry standards, and enable our developers to build secure-by-default solutions.
Job Responsibility:
Secure our cloud foundation in GCP and AWS: Design and implement security controls for our GCP and AWS infrastructure, including Kubernetes, storage services, VPCs, Cloud Run, and cloud-native workloads to protect sensitive healthcare data and AI models
Architect central identity management: Evolve our central Identity Provider (IDP) — unifying authentication, authorization, self-service access, and privileged access management across cloud services
Manage vulnerabilities at scale: Strengthen our CVE management processes and automate vulnerability scanning for containers and infrastructure
Automate security at scale: Develop security-as-code solutions using Terraform, create CI/CD security gates using policy-as-code, and build automated remediation workflows to embed security into our development lifecycle
Enable secure development: Partner with engineering and data science teams to provide security consultation, create self-service security patterns, and educate developers on security best practices
Requirements:
5+ years in cloud security or platform security engineering, with a track record of securing complex, cloud-native infrastructure in production environments
Deep experience securing GCP and/or AWS environments, with strong knowledge of IAM, PAM, network security, and container platforms
Proven experience conceptualizing and implementing centralized identity provider solutions, SSO & SCIM, and authentication frameworks
Experience building CVE management programs, implementing automated scanning solutions, and driving remediation processes
Strong programming and scripting abilities (Python, Bash, Go) to automate security processes, build security tools, and integrate security into CI/CD pipelines
Ability to explain complex security concepts to technical and non-technical audiences, drive security decisions, and collaborate across teams (fluent in English, German is a plus)
Understanding of security compliance frameworks (ISO 27001, GDPR, HIPAA) and experience implementing controls to meet regulatory requirements
Nice to have:
GitOps expertise: Experience working with Argo CD, Terraform, GitOps pipelines, and implementing policy-as-code with tools like OPA/Gatekeeper or Kyverno
Security monitoring chops: Hands-on with Prometheus, Grafana (Loki/Tempo), SIEM platforms like OX Security, or GCP Security Command Center to detect and respond to threats
Secrets management experience: Practice with HashiCorp Vault, Google Secret Manager, or similar tools for secure credential management and rotation
DevSecOps mindset: Experience embedding security into CI/CD pipelines, implementing automated security scanning, and creating security gates without blocking developer velocity
Endpoint security knowledge: Familiarity with mobile device security policies, MDM solutions, and endpoint security in healthcare environments
Platform builder mentality: Experience creating internal security platforms or self-service security tools (like Backstage plugins) that enable developers to implement security correctly
Healthcare industry context: Experience in healthcare, life sciences, or regulated industries, with understanding of compliance requirements and data protection needs in medical technology
What we offer:
Cutting-edge AI research and development, with involvement of Charité, TU Berlin and our other partners
Work with a welcoming, diverse and highly international team of colleagues
Opportunity to take responsibility and grow your role within the startup
Expand your skills by benefitting from our Learning & Development yearly budget of 1,000€ (plus 2 L&D days), language classes and internal development programs
Mentoring program, you’ll learn from great experts
Flexible working hours and teleworking policy
Enjoy your well-deserved time off within our 30 paid vacation days per year
We are family & pet friendly and support flexible parental leave options
Pick a subsidized membership of your choice among public transport, sports and well-being
Enjoy our social gatherings, lunches, and off-site events for a fun and inclusive work environment