Now hiring

Lead Security Engineer (Full-/Part-time) (all genders) @ EMD Group (Merck KGaA / EMD Serono)

DEOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Work Your Magic with us! Ready to explore, break barriers, and discover more? We know you’ve got big plans – so do we! Our colleagues across the globe love innovating with science and technology to enrich people’s lives with our solutions in Healthcare, Life Science, and Electronics. Together, we dream big and are passionate about caring for our rich mix of people, customers, patients, and planet. That's why we are always looking for curious minds that see themselves imagining the unimaginable with us.

Your role In your role as Lead Security Engineer in the Platform and Engineering Enablement team, you will own the security engineering vision, strategy, standards, and delivery roadmap across our products and shared platforms. You will simplify and harden CI/CD pipelines, establish secure defaults, improve software supply-chain and AWS cloud security, and automate controls and audit evidence using GitHub, JFrog, Atlassian, and AWS. Working with engineering, enterprise security, legal, privacy, risk, and compliance, you will translate ISO 27001, SOC 2, the EU Cyber Resilience Act, customer, and internal requirements into practical controls. You will combine long-term direction with hands-on implementation and enable teams to deliver secure software efficiently. Who you are

• You have extensive hands-on experience in security engineering, platform engineering, application security, cloud security, or a related field, with technical ownership across multiple teams. • You have defined security strategies and standards and turned them into production-ready implementations. • You have secured CI/CD pipelines, source control, build systems, artifacts, software releases, and cloud platforms using tools such as GitHub, JFrog, and AWS. • You have practical experience with identity and access management, infrastructure as code, vulnerability management, security testing, threat modeling, secrets, and software supply-chain security. • You understand risk-based control design and frameworks such as ISO 27001, SOC 2, or the EU Cyber Resilience Act and can translate requirements into automated controls and evidence. • You communicate clearly, influence across teams, and balance security, developer experience, delivery speed, and operational resilience. • Experience with software bills of materials, provenance, attestations, artifact signing, release integrity, or security considerations for AI-assisted software development is desirable. • Experience with Atlassian tools or relevant certifications such as CISSP, CCSP, AWS Certified Security - Specialty, or ISO 27001 Lead Implementer or Lead Auditor is desirable.

What we offer: We are curious minds that come from a broad range of backgrounds, perspectives, and life experiences. We believe that this variety drives excellence and innovation, strengthening our ability to lead in science and technology. We are committed to creating access and opportunities for all to develop and grow at your own pace. Join us in building a culture of inclusion and belonging that impacts millions and empowers everyone to work their magic and champion human progress! Apply now and become a part of a team that is dedicated to Sparking Discovery and Elevating Humanity!

Skills

security engineeringsecurity controlssecurity standardscloud securitysecurity testingci/cd pipelinesinfrastructure as codeplatform engineeringatlassianawsidentity and access managementattestationseu cyber resilience actsecurity considerations for ai-assisted software developmentrelease integrity

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores