Merck KGaA logo
Merck KGaA

Lead Security Engineer (Full-/Part-time)

NewOnsiteSecurityLeadDarmstadt, Hessen, GermanyDevToolsInfrastructureAI/ML

Our Take

Lead Security Engineer at Merck KGaA responsible for defining and implementing security strategy and standards across products and platforms.

What you’ll do

  • Own the security engineering vision, strategy, standards, and delivery roadmap across products and shared platforms
  • Simplify and harden CI/CD pipelines
  • Establish secure defaults
  • Improve software supply-chain and AWS cloud security
  • Automate controls and audit evidence using GitHub, JFrog, Atlassian, and AWS
  • Translate ISO 27001, SOC 2, the EU Cyber Resilience Act, customer, and internal requirements into practical controls
  • Combine long-term direction with hands-on implementation
  • Enable teams to deliver secure software efficiently

What they’re looking for

  • Extensive hands-on experience in security engineering, platform engineering, application security, cloud security, or related field
  • Technical ownership across multiple teams
  • Defined security strategies and standards and turned them into production-ready implementations
  • Secured CI/CD pipelines, source control, build systems, artifacts, software releases, and cloud platforms using GitHub, JFrog, and AWS
  • Practical experience with identity and access management
  • Practical experience with infrastructure as code
  • Practical experience with vulnerability management
  • Practical experience with security testing

Skills & Focus Areas

  • security engineering
  • platform engineering
  • application security
  • cloud security
  • CI/CD pipelines
  • GitHub
  • JFrog
  • AWS
  • identity and access management
  • infrastructure as code
  • vulnerability management
  • threat modeling

As posted by Merck KGaA


Your role

In your role as Lead Security Engineer in the Platform and Engineering Enablement team, you will own the security engineering vision, strategy, standards, and delivery roadmap across our products and shared platforms. You will simplify and harden CI/CD pipelines, establish secure defaults, improve software supply-chain and AWS cloud security, and automate controls and audit evidence using GitHub, JFrog, Atlassian, and AWS. Working with engineering, enterprise security, legal, privacy, risk, and compliance, you will translate ISO 27001, SOC 2, the EU Cyber Resilience Act, customer, and internal requirements into practical controls. You will combine long-term direction with hands-on implementation and enable teams to deliver secure software efficiently.

 

Who you are

  • You have extensive hands-on experience in security engineering, platform engineering, application security, cloud security, or a related field, with technical ownership across multiple teams.
  • You have defined security strategies and standards and turned them into production-ready implementations.
  • You have secured CI/CD pipelines, source control, build systems, artifacts, software releases, and cloud platforms using tools such as GitHub, JFrog, and AWS.
  • You have practical experience with identity and access management, infrastructure as code, vulnerability management, security testing, threat modeling, secrets, and software supply-chain security.
  • You understand risk-based control design and frameworks such as ISO 27001, SOC 2, or the EU Cyber Resilience Act and can translate requirements into automated controls and evidence.
  • You communicate clearly, influence across teams, and balance security, developer experience, delivery speed, and operational resilience.
  • Experience with software bills of materials, provenance, attestations, artifact signing, release integrity, or security considerations for AI-assisted software development is desirable.
  • Experience with Atlassian tools or relevant certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or ISO 27001 Lead Implementer or Lead Auditor is desirable.

 

Department: LS-TO-DP
Job evaluation: Expert 3
TA: Gap Rattimasakol


Was this listing helpful?