Senior Security Engineer

isaraerospace

Parsdorf

Vor Ort

EUR 90.000 - 120.000

Vollzeit

Vor 7 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine zielgenaue Bewerbung für diesen Job — ein maßgeschneiderter Lebenslauf und ein Anschreiben, die genau zur Stellenanzeige passen.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Isar Aerospace in Parsdorf, Bavaria, seeks a security engineer to own SASE platform operations, firewall strategy, DNS and WAF protection, and PKI management. You will drive threat modeling, incident response, and MITRE ATT&CK-aligned detections.

Collaborating with infrastructure and network teams, you will raise posture with CIS benchmarks, phishing‑resistant MFA, and automated tooling in PowerShell and Python, ensuring hardened configurations across on‑prem and cloud environments.

Qualifikationen

  • Experience in security engineering and threat modeling.
  • Familiarity with MITRE ATT&CK framework and detections.
  • Strong incident response and security operations skills.
  • Experience implementing SASE, MFA and cloud security configurations.

Aufgaben

  • Own and operate the SASE platform, including policy revamps and access controls.
  • Drive firewall security with the network team and coordinate adjacent controls (IPS, AV, sandboxing, DDoS protection).
  • Manage DNS security and WAF solutions for edge/CDN protections.
  • Apply CIS Benchmarks to raise posture across firewalls, endpoints, and cloud identity platforms.
  • Lead hardening of on-prem and cloud identity directories and drive phishing-resistant MFA and privileged access.
  • Own certificate lifecycle, PKI operations, and automated renewal processes.
  • Develop and tune detections in SIEM and apply MITRE ATT&CK in detection engineering.
  • Act as an L3 incident responder for escalated events and implement fixes and hardened configurations.
  • Script and build internal tooling in PowerShell and Python to automate controls.

Kenntnisse

Security engineering
Incident response
Threat modeling
MITRE ATT&CK
SASE
Cloud security

Tools

PowerShell
Python

Jobbeschreibung

Mission Brief

You are the guardian and the challenger of our security posture. At Isar Aerospace, the systems that build our rockets and the ground systems that launch them are mission critical, and protecting them takes more than good design. It takes someone who will attack their own work to be sure it holds.

Your Role in Our Space Mission
SASE and Network Security

Own and operate our SASE platform , including revamping Internet Security policies and redefining Private Access policies.

Drive firewall security with the network team: own network security engineering and segmentation strategy, analyze rule sets, identify gaps, and see remediation through together with network engineering, who own the devices.

Coordinate firewall-adjacent controls: IPS, AV, sandboxing and DDoS protection.

Manage our DNS security and WAF solutions , including our edge and CDN-based protection services.

Security Posture and Hardening

Apply CIS Benchmarks to raise posture across firewalls, endpoints, our cloud identity platform and our cloud productivity suite.

Lead the clean-up and hardening of our on-premises and cloud identity directories together with the infrastructure team, then keep both hardened on an ongoing basis.

Drive our phishing-resistant MFA and privileged access programme, including just-in-time elevation and the remediation of the attack paths we find.

Own certificate lifecycle and PKI operations: key ceremonies, automated renewal, and input to our post-quantum migration plan.

Detection and Visibility

Manage and tune our IPS/IDS platforms; write and maintain custom IDS signatures, and operate network sensors for NTA appliances.

Build and maintain detections in our SIEM and apply MITRE ATT&CK to detection engineering and use-case design in support of the SOC.

Extend visibility into OT with purpose-built OT monitoring tooling.

Act as an L3 incident responder for escalated security events, and turn every finding into a fix, a new detection or a hardened configuration.

Security Stack and Automation

Own our endpoint detection and response, data protection and CASB platforms as their technical owner.

Script and build internal tooling in PowerShell and Python, so controls and checks run themselves.

Design and Engineering Partnership

Design what you operate: run threat modeling and attack-path analysis on the systems you own, choose the patter

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

Meyandy LLC • Deutschland

Remote
EUR 120.000 - 170.000
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

Isar Aerospace SE • Parsdorf

Vor Ort
EUR 110.000 - 170.000
Virtual company share program
6 weeks vacation
Subsidised lunch
+4
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Riederich

Vor Ort
EUR 80.000 - 120.000
Senior Security Architect
Senior Security Architect

Verimatrix • Ismaning

Vor Ort
EUR 110.000 - 150.000
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

Isar Aerospace • Parsdorf

Vor Ort
EUR 90.000 - 130.000
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

isaraerospace • Parsdorf

Vor Ort
EUR 110.000 - 150.000
Employee Participation Program
6 weeks of vacation
Relocation support
+3
Security Operations Engineer – Europe
Security Operations Engineer – Europe

Jobtailor • Deutschland

Remote
EUR 65.000 - 90.000
Network Security Engineer
Network Security Engineer

Leonardo SpA • Deutschland

Hybrid
EUR 70.000 - 90.000
Security Automation Engineer
Security Automation Engineer

Jobtailor • Leverkusen

Vor Ort
EUR 80.000 - 130.000
Senior Security Architect (m/f/d)
Senior Security Architect (m/f/d)

Blackshark • Bonn

Vor Ort
EUR 120.000 - 180.000
Employee Participation Program
6 weeks of vacation
Subsidised lunch
+4