6 дней назад
Security Engineer (IT Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Engineer (IT Security) (Cloud Security/Compliance): Evolving the Secure SDLC and embedding security controls into cloud architectures, CI/CD pipelines, and operational concepts with an accent on threat modeling, IAM, cryptography, vulnerability management, and continuous compliance. Focus on designing resilient security concepts, verifying their effectiveness, and automating audit evidence across technical teams.
Location: Berlin, Germany; hybrid working model with a home office option.
Company
provides cloud infrastructure, cloud services, hosting, and digitalization solutions for small and medium-sized businesses and enterprises across Europe and North America.
What you will do
- Drive the evolution of the Secure SDLC in collaboration with development teams.
- Lead threat modeling and architecture reviews to identify risks early in the design phase.
- Design IAM concepts, permission models, cryptographic standards, and security baselines.
- Manage vulnerability scanning, CVSS scoring, prioritization, penetration testing, and remediation tracking.
- Define and review logging, monitoring, error handling, business continuity, and disaster recovery requirements.
- Automate compliance and evidence collection within CI/CD pipelines.
Requirements
- Several years of practical experience with cybersecurity management systems, certifications, and attestations.
- Experience with at least two certified scopes based on ISO 27001, IT-Grundschutz, or BSI C5.
- Several years of experience applying these standards in a technical product organization.
- Strong interest in integrating management systems and certification activities into efficient, tool-supported workflows.
- English at CEFR C1 or higher and German at CEFR C1 are required.
- Confident communication and goal-oriented collaboration with internal and international stakeholders.
Nice to have
- Conceptual knowledge of IAM, SSO, federation, PAM, and recertification logic.
- Practical experience with TLS, PKI, key management, and HSM.
- Familiarity with ISO/IEC 27001 Annex A, BSI IT-Grundschutz, OWASP ASVS and Top 10, CIS Benchmarks, or NIST CSF.
- Experience with Policy as Code, continuous compliance, audit logic, and external auditors.
Culture & Benefits
- Hybrid work with flexible, trust-based working hours.
- Modern offices with convenient transport connections.
- Training and professional development opportunities.
- Health, sports, employee discount, and team event programs.
- Subsidized canteen and free drinks at some locations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →