Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)

IONOS Group

Karlsruhe

Hybrid

EUR 90.000 - 130.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Erhalte eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Hybrid working model
Flexible working hours
Canteen subsidy at some locations
Modern office with good transport

Zusammenfassung

IONOS Group seeks a hands-on security architect to own the provider-side infrastructure security and the internal AI platforms. You will set standards, validate designs, and work with platform and engineering teams across brands to implement secure, auditable systems.

You will lead pre-deployment reviews, enforce identity controls, and guide risk-based decisions in a multi-tenant environment, ensuring safe AI adoption and strong governance.

Qualifikationen

  • Several years of hands-on experience in infrastructure or platform security.
  • Deep knowledge of Linux, virtualization, containers, networking, and multi-tenant security.
  • Strong background in identity, access management, credentials, and least-privilege access.
  • Experience designing security standards in heterogeneous legacy environments.
  • Familiarity with AI/LLM platforms and agent systems security risks.
  • Ability to defend risk-based decisions and explain technical risk to non-technical stakeholders.
  • Fluent English; German language skills are a strong advantage.

Aufgaben

  • Define and maintain security architecture standards and hardening baselines for provider-side infrastructure.
  • Assess tenant isolation and drive remediation with platform teams.
  • Review infrastructure designs for security impact and escalate security questions.
  • Reduce blast radius via privileged access controls, segmentation, and secrets handling.
  • Support cyber defense and incident response with infrastructure expertise.
  • Own security architecture and baselines for internal AI platforms and agent frameworks.
  • Define how agents are identified, authenticated, and authorized with least-privilege access.
  • Ensure data access/indexing complies with regulatory and certification requirements.
  • Run pre-deployment security reviews for new internal AI platforms.
  • Advise on adopting AI safely with defensible guardrails.

Kenntnisse

Infrastructure security
Linux expertise
Virtualization & container platforms
Networking security
Identity & access management
Security standards & governance
AI/LLM security
Risk assessment & decision-making
Cross-team collaboration
German language advantage

Tools

DNS security
Email infrastructure security

Jobbeschreibung

Both halves of this role are about the same underlying question: which systems can reach our most sensitive infrastructure, and under what controls. You will own the security architecture for our provider-side infrastructure layer, and you will be the subject matter expert for the AI platforms and agents we operate internally, making sure they run in a secure, governed, auditable state rather than accumulating quietly as a new class of privileged access.

This is a hands‑on expert role. You set standards, pressure‑test designs, and work directly with platform and engineering teams across our brands to get them implemented.

Tasks
Internal AI platform and agent security
  • Define and maintain security architecture standards and hardening baselines for provider‑side infrastructure: virtualization and container platforms, control planes and provisioning systems, DNS, mail infrastructure, and backup and recovery systems.
  • Assess and strengthen tenant isolation across shared hosting, virtualization, and container layers, and drive remediation with the responsible platform teams.
  • Review infrastructure designs and major changes for security impact, and act as an escalation point for infrastructure security questions from platform, cloud, and brand engineering teams.
  • Reduce blast radius on the paths that matter most: privileged access to customer‑facing infrastructure, administrative segmentation, secrets handling, and recovery integrity - translated into workable per‑brand implementation plans across our heterogeneous platforms.
  • Support Cyber Defense, Vulnerability Management, and IT Emergency Management with infrastructure expertise during incidents and post‑incident hardening.
Infrastructure security
  • Own the security architecture and baseline standards for the AI platforms we run internally: model gateways and self‑hosted models, agent frameworks, assistant integrations, connectors, and retrieval pipelines over internal data.
  • Define and enforce how agents are identified, authenticated, and authorized: non‑human identity handling, credential and token management, least‑privilege tool and system access, and where autonomous action requires a human in the loop.
  • Establish what data internal AI systems may access and index, and ensure agent activity is logged, attributable, and reviewable to the standard our regulatory and certification obligations require.
  • Run pre‑deployment security reviews for new internal AI platforms and agent use cases, at a pace that fits how fast these are being adopted, and keep a picture of where unsanctioned AI usage is emerging.
  • Advise the security functions and internal engineering teams on adopting AI safely, including the guardrails that make that adoption defensible.
Qualifications
  • Several years of hands‑on experience in infrastructure or platform security, ideally at a hosting provider, cloud provider, telco, or comparably large‑scale multi‑tenant environment.
  • Deep practical knowledge of Linux, virtualization and container platforms, networking, and the security properties of multi‑tenant infrastructure.
  • Strong background in identity and access: privileged access, machine and workload identity, secrets management, authorization models, and infrastructure‑as‑code security.
  • Experience designing and enforcing security standards in a heterogeneous, partly legacy landscape, and getting them adopted by teams you do not manage.
  • Working knowledge of how LLM and agent systems are built and operated, and of the risks specific to them: prompt injection through untrusted data, over-scoped tool access, data exposure via retrieval, unlogged autonomous action, model and provider dependency.
  • Ability to make and defend risk‑based decisions, including blocking a deployment with a clear rationale, and to explain technical risk to non‑technical stakeholders.
  • Fluent English; German is a strong advantage given our regulatory and public‑sector environment.
Nice to have
  • Hands‑on experience deploying or securing internal AI platforms, agent frameworks, or tool‑calling integrations in production.
  • Familiarity with NIS2 / BSIG or ISO 27001
  • Background in DNS, e‑mail infrastructure, or abuse‑adjacent platform security.
  • Experience in a multi‑brand or post‑acquisition environment where the same control has to land in several different implementations.
  • Security engineering or development background (automation, tooling, scripting).
Who fits

Someone comfortable being the only expert in the room on a given question, who prefers fixing root causes over filing findings, and who can operate across security functions and platform teams they do not control. You should be genuinely interested in AI systems as engineering artifacts, not just as a policy topic — much of this practice is still being written, and you will be writing ours.

Benefits
  • Hybrid working model.
  • Flexible working hours through trust‑based working hours.
  • At some locations a subsidized canteen and various free drinks.
  • Modern office space with very good transport connections.
  • Various employee discounts for activities and products.
  • Employee events such as summer and winter parties, as well as workshops.
  • Numerous training and development opportunities.
  • Various health offers, such as sports and health courses.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)

1&1 IONOS SE • Karlsruhe

Hybrid
EUR 90.000 - 120.000
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)

IONOS Group • Berlin

Hybrid
EUR 90.000 - 130.000
Hybrid work
Flexible hours
Canteen subsidy
+5
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)

1&1 IONOS SE • Berlin

Hybrid
EUR 90.000 - 150.000
Hybrid working model
Flexible hours
Subsidized canteen
+5
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)

Greenhouse Software, Inc. • Karlsruhe

Vor Ort
EUR 70.000 - 120.000
Subsidized canteen
Modern office near transport links
Employee discounts
+2
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d)

Greenhouse Software, Inc. • Berlin

Vor Ort
EUR 80.000 - 120.000
Subsidized canteen
Free drinks
Modern office space
+3
Cyber Security Engineer — Infrastructure & AI Platform Security (w/m/d)
Cyber Security Engineer — Infrastructure & AI Platform Security (w/m/d)

1&1 IONOS SE • Berlin

Hybrid
EUR 90.000 - 140.000
Hybrides Arbeitsmodell
Flexible Arbeitszeiten
Kostenlose Getränke an Standorten
+3
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d) (Karlsruhe)
Cyber Security Engineer — Infrastructure & AI Platform Security (f/m/d) (Karlsruhe)

WebHosting • Karlsruhe

Hybrid
EUR 90.000 - 120.000
Cyber Security Engineer — Infrastructure & AI Platform Security (w/m/d)
Cyber Security Engineer — Infrastructure & AI Platform Security (w/m/d)

Greenhouse Software, Inc. • Berlin

Hybrid
EUR 90.000 - 150.000
Hybrides Arbeitsmodell
Flexible Arbeitszeiten
Kantine an einigen Standorten
+3
Senior Platform Engineer (d/f/m)
Senior Platform Engineer (d/f/m)

United States Digital Space LLC • Berlin

Vor Ort
EUR 110.000 - 140.000
Stock options
30 days vacation
Flexible hours
+2
Cyber Security Engineer — Infrastructure & AI Platform Security (w/m/d)
Cyber Security Engineer — Infrastructure & AI Platform Security (w/m/d)

Join • Berlin

Hybrid
EUR 110.000 - 150.000
Hybrides Arbeitsmodell
Flexible Arbeitszeiten
Kantine an Standorten (teilweise)