For us, security isn't an afterthought or a checkbox exercise - it's built right into our DNA. We integrate security exactly where it matters most: into our architectures, pipelines, and operational concepts. Compliance evidence is generated naturally from our day-to-day operations, not from stressful last-minute audit prep. We are looking for someone who can translate security requirements into resilient technical concepts and actively verify their effectiveness.
Tasks
- Drive the evolution of our Secure SDLC side-by-side with our dev teams.
- Lead Threat Modeling and architecture reviews - catching risks early in the design phase, not right before a release.
- Design robust IAM concepts (role models, permission logic, recertification) and define clear cryptographic standards and baselines.
- Take charge of vulnerability and pentest management: scanning, CVSS scoring, prioritizing, and tracking remediations.
- Specify requirements for logging, monitoring, and error handling, and review their implementation across the board.
- Design and evaluate technical Business Continuity (BC) and disaster recovery tests.
- Automate compliance and evidence collection directly within the teams' CI/CD pipelines.
Qualifications
- Well-founded, multi-year practitioner's experience with standardised management systems and certifications, attestations in the cyber security area.
- You have practical experience from two or more certified scopes according to ISO 27001, IT-Grundschutz, BSI C5. More ISO management system experience from privacy standards comes as a plus.
- You have multi-year experience with above standards and certifications in a technical organisation, as in the company offers technical products.
- You are burning for modern tool supported, efficient integration of management systems and certification activities into the daily routine of an organisation.
- You love technology, you do not shy away from documentation but would like to structure it as efficiently as possible.
- You convince through your confident and communicative character when achieving goal oriented results with your international and internal interfaces.
- You proficiently lead discussions in English (CEFR C1 or higher). Completely fluent German (C1 CEFR level is a must).
Nice to Have
- Deep conceptual knowledge of IAM (Role/Permission models, SSO, Federation, PAM, recertification logic).
- Practical experience with applied cryptography (TLS, PKI, Key Management, HSM).
- Familiarity with major frameworks (ISO/IEC 27001 Annex A, BSI IT-Grundschutz, OWASP ASVS & Top 10, CIS Benchmarks, NIST CSF).
- Experience with Policy as Code and Continuous Compliance.
- An understanding of audit logic and how to collaborate smoothly with external auditors.
Benefits
- Hybrid working model with home office option.
- Flexible working hours through trust-based working hours.
- At some locations a subsidized canteen and various free drinks.
- Modern office space with very good transport connections.
- Various employee discounts for activities and products.
- Employee events such as summer and winter parties, as well as workshops.
- Numerous training and development opportunities.
- Various health offers, such as sports and health courses.