Both halves of this role are about the same underlying question: which systems can reach our most sensitive infrastructure, and under what controls. You will own the security architecture for our provider-side infrastructure layer, and you will be the subject matter expert for the AI platforms and agents we operate internally, making sure they run in a secure, governed, auditable state rather than accumulating quietly as a new class of privileged access.
This is a hands-on expert role. You set standards, pressure-test designs, and work directly with platform and engineering teams across our brands to get them implemented.
Tasks
- Define and maintain security architecture standards and hardening baselines for provider-side infrastructure: virtualization and container platforms, control planes and provisioning systems, DNS, mail infrastructure, and backup and recovery systems.
- Assess and strengthen tenant isolation across shared hosting, virtualization, and container layers, and drive remediation with the responsible platform teams.
- Review infrastructure designs and major changes for security impact, and act as an escalation point for infrastructure security questions from platform, cloud, and brand engineering teams.
- Reduce blast radius on the paths that matter most: privileged access to customer-facing infrastructure, administrative segmentation, secrets handling, and recovery integrity — translated into workable per-brand implementation plans across our heterogeneous platforms.
- Support Cyber Defense, Vulnerability Management, and IT Emergency Management with infrastructure expertise during incidents and post-incident hardening.
- Own the security architecture and baseline standards for the AI platforms we run internally: model gateways and self-hosted models, agent frameworks, assistant integrations, connectors, and retrieval pipelines over internal data.
- Define and enforce how agents are identified, authenticated, and authorized: non-human identity handling, credential and token management, least-privilege tool and system access, and where autonomous action requires a human in the loop.
- Establish what data internal AI systems may access and index, and ensure agent activity is logged, attributable, and reviewable to the standard our regulatory and certification obligations require.
- Run pre-deployment security reviews for new internal AI platforms and agent use cases, at a pace that fits how fast these are being adopted, and keep a picture of where unsanctioned AI usage is emerging.
- Advise the security functions and internal engineering teams on adopting AI safely, including the guardrails that make that adoption defensible.
Qualifications
- Several years of hands-on experience in infrastructure or platform security, ideally at a hosting provider, cloud provider, telco, or comparably large-scale multi-tenant environment.
- Deep practical knowledge of Linux, virtualization and container platforms, networking, and the security properties of multi-tenant infrastructure.
- Strong background in identity and access: privileged access, machine and workload identity, secrets management, authorization models, and infrastructure-as-code security.
- Experience designing and enforcing security standards in a heterogeneous, partly legacy landscape, and getting them adopted by teams you do not manage.
- Working knowledge of how LLM and agent systems are built and operated, and of the risks specific to them: prompt injection through untrusted data, over-scoped tool access, data exposure via retrieval, unlogged autonomous action, model and provider dependency.
- Ability to make and defend risk-based decisions, including blocking a deployment with a clear rationale, and to explain technical risk to non-technical stakeholders.
- Fluent English; German is a strong advantage given our regulatory and public-sector environment.
Nice to have
- Hands-on experience deploying or securing internal AI platforms, agent frameworks, or tool-calling integrations in production.
- Familiarity with NIS2 / BSIG or ISO 27001
- Background in DNS, e-mail infrastructure, or abuse-adjacent platform security.
- Experience in a multi-brand or post-acquisition environment where the same control has to land in several different implementations.
- Security engineering or development background (automation, tooling, scripting).
Benefits
- Hybrid working model.
- Flexible working hours through trust-based working hours.
- At some locations a subsidized canteen and various free drinks.
- Modern office space with very good transport connections.
- Various employee discounts for activities and products.
- Employee events such as summer and winter parties, as well as workshops.
- Numerous training and development opportunities.
- Various health offers, such as sports and health courses.