Назад
Company hidden
обновлено 5 дней назад

Staff Information Security Manager (f/m/d) (Cloud Security)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Germany
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Information Security Manager (Cloud Security): Evolving the Secure SDLC and integrating security into architectures, pipelines, and operational concepts with an accent on threat modeling, IAM, vulnerability management, and compliance automation. Focus on designing resilient security controls, evaluating business continuity and disaster recovery tests, and verifying implementation across technical teams.

Location: Berlin, Germany; hybrid working model with a home office option

Company

hirify.global provides cloud infrastructure, cloud services, hosting, and digitalization solutions for small and medium-sized businesses and enterprise customers across Europe and North America.

What you will do

  • Drive the evolution of the Secure SDLC in collaboration with development teams.
  • Lead threat modeling and architecture reviews to identify risks during the design phase.
  • Design IAM concepts, including role models, permission logic, recertification, and cryptographic standards.
  • Manage vulnerability scanning, CVSS scoring, prioritization, penetration testing, and remediation tracking.
  • Define requirements for logging, monitoring, error handling, business continuity, and disaster recovery testing.
  • Automate compliance and evidence collection within CI/CD pipelines.

Requirements

  • Several years of practical experience with standardized management systems, cybersecurity certifications, and attestations.
  • Practical experience with at least two certified scopes involving ISO 27001, IT-Grundschutz, or BSI C5.
  • Several years of experience applying security standards and certifications in a technical product organization.
  • Strong interest in tool-supported integration of management systems and certification activities into daily operations.
  • Confident communication and goal-oriented collaboration with international and internal stakeholders.
  • English at CEFR C1 or higher and German at CEFR C1 are required.

Nice to have

  • Deep conceptual knowledge of IAM, SSO, federation, PAM, and recertification logic.
  • Practical experience with applied cryptography, including TLS, PKI, key management, and HSM.
  • Familiarity with ISO/IEC 27001 Annex A, BSI IT-Grundschutz, OWASP ASVS and Top 10, CIS Benchmarks, and NIST CSF.
  • Experience with Policy as Code, continuous compliance, audit logic, and external auditors.

Culture & Benefits

  • Hybrid work with a home office option and trust-based flexible working hours.
  • Modern office with convenient transport connections.
  • Training and professional development opportunities.
  • Health programs, sports and health courses, employee discounts, and company events.
  • Subsidized canteen and free drinks at some locations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →