Назад
Company hidden
3 дня назад

Senior Cyber Security Engineer

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Germany
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Cyber Security Engineer (Cybersecurity): Driving Secure SDLC evolution and designing resilient security concepts for cloud infrastructure and digital services with an accent on threat modeling, IAM, cryptography, vulnerability management, and compliance automation. Focus on reviewing architectures, prioritizing remediation, testing business continuity and disaster recovery, and integrating evidence collection into CI/CD pipelines.

Location: Berlin, Germany; hybrid working model with a home office option.

Company

hirify.global provides cloud infrastructure, cloud services, hosting, and digitalization solutions for small and medium-sized businesses and enterprises across Europe and North America.

What you will do

  • Drive the evolution of the Secure SDLC in collaboration with development teams.
  • Lead threat modeling and architecture reviews to identify risks early in the design phase.
  • Design IAM concepts, permission models, recertification processes, and cryptographic standards.
  • Manage vulnerability scanning, CVSS scoring, penetration testing, prioritization, and remediation tracking.
  • Define requirements for logging, monitoring, error handling, business continuity, and disaster recovery testing.
  • Automate compliance and evidence collection within CI/CD pipelines.

Requirements

  • Several years of practical experience with cybersecurity management systems, certifications, and attestations.
  • Experience with at least two certified scopes under ISO 27001, IT-Grundschutz, or BSI C5.
  • Several years of experience applying these standards in a technical product organization.
  • Strong interest in integrating management systems and certification activities into efficient, tool-supported processes.
  • Confident communication and discussion leadership across international and internal interfaces.
  • English at CEFR C1 or higher and German at CEFR C1 are required.

Nice to have

  • Deep knowledge of IAM, including SSO, federation, PAM, and recertification logic.
  • Practical experience with applied cryptography, TLS, PKI, key management, and HSM.
  • Familiarity with ISO/IEC 27001 Annex A, BSI IT-Grundschutz, OWASP ASVS and Top 10, CIS Benchmarks, or NIST CSF.
  • Experience with Policy as Code, continuous compliance, audit logic, and external auditors.

Culture & Benefits

  • Hybrid work with flexible trust-based working hours.
  • Modern offices with convenient public transport connections.
  • Training and professional development opportunities.
  • Health programs, sports and health courses, employee discounts, and company events.
  • Subsidized canteen and free drinks at selected locations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →