Senior Software Engineer - EDP

BoehringerPRDOn-siteFull-timeSenior, 5–8 yearsListed 6 hours ago

Apply now

About this role

The Position

At Boehringer Ingelheim, we enable teams across the company to build, secure, deliver, and operate software through the Enterprise Development Platform (EDP). Our platform provides standardized, automated, and compliant capabilities across the software development lifecycle while improving developer experience and accelerating business value.
We apply modern software and platform engineering practices with a strong focus on DevSecOps, automation, secure-by-default delivery, reliability, and continuous improvement. Our goal is to provide paved paths and reusable building blocks that reduce cognitive load for development teams without compromising security, quality, or compliance.
We are looking for a senior software engineer with strong software engineering and DevSecOps capabilities and hands-on experience with modern development platforms. The successful candidate will combine engineering depth, security awareness, and a product mindset to design and evolve platform capabilities used by development teams across the enterprise.

Duties & Responsibilities

- Design, build, test, and operate secure, scalable platform services and automation with full end-to-end ownership.

- Develop and maintain reusable CI/CD workflows, templates, quickstarters, APIs, and self-service capabilities for development teams.

- Embed security throughout the software delivery lifecycle, including code, dependency, secret, container, and infrastructure-as-code scanning.

- Implement supply-chain security controls such as SBOM generation, artifact integrity, provenance, signing, trusted dependencies, and policy enforcement.

- Engineer and govern GitHub Enterprise capabilities, including organizations, repositories, teams, permissions, rulesets, environments, GitHub Apps, Actions, and runners.

- Apply secure identity and secrets-management patterns using least privilege, workload identities, short-lived credentials, and enterprise secret stores.

- Integrate the platform with enterprise services such as OpenShift, AWS, artifact repositories, ServiceNow, CMDB, identity providers, testing services, and observability platforms.

- Improve platform reliability through observability, automated testing, operational runbooks, incident analysis, and measurable engineering outcomes.

- Collaborate with product owners, architects, cybersecurity, infrastructure, quality, and engineering teams to translate needs into pragmatic platform solutions.

Requirements:

- Several years of professional software engineering experience, including ownership of production-grade systems or internal developer platforms.

- Strong programming and scripting skills in one or more languages such as Java, Go, C#, TypeScript, Python, or Bash, with sound knowledge of APIs, testing, clean code, and software design patterns.

- DevOps experience, including secure CI/CD design, automated quality gates, vulnerability management, remediation workflows, and security controls integrated into developer workflows.

- Experience with containerized and cloud-native platforms such as Docker, Kubernetes, and OpenShift, including secure deployment patterns, Helm, networking, identity, and runtime troubleshooting.

- Experience with tools, such as Jenkins, Nexus, SonarQube, Trivy or Aqua, OpenBao, Jira, Confluence, ServiceNow and automated testing frameworks.

- Understanding of enterprise identity and access management, including SSO, Entra ID, RBAC, least privilege, workload identity, secrets management, auditability, and privileged-access controls.

- Strong analytical, collaboration, and communication skills, with the ability to explain complex technical topics to both engineering and non-technical stakeholders.

- A proactive, pragmatic, and accountable mindset, with a strong focus on user needs, product outcomes, continuous learning, and shared success.

- Fluent English, written and spoken.

Nice to have:

- Hands-on experience with GitHub Enterprise.

- Experience with application-security and software-supply-chain practices, including SAST, SCA, secret scanning, container scanning, SBOMs, artifact signing or attestations, dependency governance, and infrastructure-as-code scanning.

- Practical experience with cloud services, preferably AWS, and with infrastructure as code using technologies such as Terraform, Ansible, or equivalent tooling.

- Knowledge of observability and operational engineering, including logs, metrics, traces, alerting, service-level objectives, incident response, and root-cause analysis.

- Experience working in regulated or compliance-sensitive environments, including GxP, validated systems, audit trails, and evidence automation, is an advantage.