Stageopdracht IT-Architectuuranalyse en hardeningsplan Februari 2027
Key Skills
Job Description
Stageopdracht IT-Architectuuranalyse en hardeningsplan
Doel van de opdracht
Het doel van deze opdracht is om inzicht te krijgen in de huidige IT-architectuur binnen een Azure Cloud-omgeving met Kubernetes, de bestaande hardeningmaatregelen te beoordelen en een verbeterd hardeningsplan op te stellen om de beveiliging en robuustheid van het platform te verhogen.
Opdrachtomschrijving
Inventarisatie van de IT-architectuur
-
- Breng de huidige architectuur van de Azure Cloud-omgeving in kaart.
- Documenteer de gebruikte componenten, zoals:
- Kubernetes clusters (AKS)
- Netwerkarchitectuur (VNETs, NGIX, firewalls)
- Identity & Access Management (Azure AD, Keycloak)
- Storage en databases
- Visualiseer de architectuur in een overzichtelijk diagram.
Beoordeling van huidige hardeningmaatregelen
-
- Analyseer welke beveiligingsmaatregelen momenteel zijn toegepast:
- Netwerksegmentatie
- Secrets management
- Logging & monitoring
- Container image scanning
- Vergelijk deze maatregelen met best practices en standaarden (bijv. CIS Benchmarks, NIST).
- Analyseer welke beveiligingsmaatregelen momenteel zijn toegepast:
Opstellen van een verbeterd hardeningsplan
-
- Identificeer kwetsbaarheden en risico’s op basis van de analyse.
- Stel een concreet plan op met aanbevelingen, inclusief:
- Technische maatregelen (bijv. implementatie van Pod Security Policies, gebruik van Azure Policy)
- Procesmatige verbeteringen (bijv. CI/CD security checks)
- Prioritering van acties (quick wins vs. lange termijn)
Deliverables
- Architectuurdocument met diagrammen en beschrijving van de huidige situatie.
- Hardeninganalyse inclusief gap-analyse ten opzichte van best practices.
- Verbeterplan met aanbevelingen, prioriteiten en implementatiestappen.
Leerdoelen
- Inzicht krijgen in cloud-native architecturen en Kubernetes.
- Leren toepassen van security best practices in Azure en Kubernetes.
- Vaardigheden ontwikkelen in het opstellen van een hardeningsplan.
Randvoorwaarden
- Toegang tot een testomgeving in Azure.
- Gebruik van tools zoals bv:
- Azure Security Center
- Kubectl
- Kubernetes Bench for Security
- Azure Policy
- Documentatie in het Nederlands
Solliciteren
Ben je enthousiast? Solliciteer via jobs.yunextraffic.com of kijk voor meer informatie op nl.yunextraffic.com.
Voor vragen kun je contact opnemen met:
Karolina Kolcun – Corporate Recruiter
📧 [email protected]
📱 06‑49236207
Core Responsibilities
The intern will map the current Azure Cloud and Kubernetes architecture and assess existing security measures. They will then develop and document an improved hardening plan to enhance platform security and robustness.
Requirements
The candidate should have an interest in cloud-native architectures and Kubernetes security. They must be capable of performing gap analyses and documenting technical recommendations in accordance with best practices.
About Yunex Traffic
Industry: Technology, Information and Internet
Company size: 1,001-5,000 employees
It's time for a profound #MobilityRevolution in our cities. It's time for more efficient mobility, sustainable infrastructure and livable urban environments. Yunex Traffic is the innovator that makes it happen through disruptive ideas and digital technologies. As a global leader in intelligent traffic solutions, we develop novel mobility options for cities, highway authorities and mobility providers. Our solutions transform our cities into places where people can live, work and move more freely with better quality of life, less accidents and with cleaner air and contribute to solving our climate crisis. With over 3,500 employees from 58 nations in 24 countries around the world, we help more than 110 cities to make mobility permanently environmentally friendly and more efficient with state-of-the-art digital technology such as artificial intelligence. In doing so, we act as a customer-focused powerhouse that cultivates entrepreneurial and global thinking at all levels. Join #TeamYunexTraffic and apply now: jobs.yunextraffic.com