Senior Security Engineer IAM (m/w/d)

Aioi Nissay Dowa Europe

Germany (OH)

On-site

USD 79,636 - 125,142

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

32 days annual leave
Flexible hours
Home office policy ~60%
Employer pension subsidy
Disability pension
Supplementary health insurance
Capital-forming benefits
Job ticket
Car parking spaces
Monthly travel allowance
EGYM Wellpass
Financial subsidy
Free coffee/tea/water/fruit
Health management & family service

Job summary

AND-E in Germany seeks an experienced IT security engineer to own IAM strategy across Entra ID and Active Directory, manage conditional access, PIM/PAM, and identity lifecycle governance. You will develop identity-centric detections, analyze logs, and partner with Infrastructure, Client Services, and Cloud Admin teams to implement controls across endpoints, email, network, and cloud.

You will act as internal advisor for Splunk Cloud SIEM and Cribl Stream/Edge, collaborate with MSSP on detection

Qualifications

  • Bachelor’s degree in IT Security, Cyber Security, or comparable qualification (or equivalent practical experience).
  • 5+ years in IT security engineering or operations, with significant hands‑on IAM responsibility.
  • Deep expertise in Entra ID, Active Directory, MFA/passwordless, SSO protocols (SAML, OIDC, SCIM), and identity governance.
  • Strong foundation in zero‑trust architecture and frameworks such as NIST, ISO 27001, or MITRE ATT&CK.
  • Working knowledge of Splunk Cloud SIEM, CyberArk, SailPoint IdentityIQ, and Cribl Stream/Edge.
  • Familiarity with AWS, Proofpoint, and Zscaler/Cisco/FortiGate.
  • Proficiency in PowerShell, Python, or Microsoft Graph API.
  • Very good English communication skills (German desirable).
  • Certifications such as Microsoft SC-300, SC-100, AZ-500, CISSP, CIDPRO, AWS Security Specialty, GIAC (GCIH, GCIA, GCFA), or Splunk/Cribl are considered a plus.

Responsibilities

  • Own IAM strategy across Entra ID and Active Directory
  • Manage conditional access, PIM/PAM, and identity lifecycle governance
  • Develop identity-centric detections and threat-hunting workflows, analyzing Entra ID logs and privilege escalation paths in alignment with the SOC
  • Partner with Infrastructure, Client Services, and Cloud Admin teams to review and implement controls across endpoint, email, network, and cloud environments
  • Act as internal advisor for Splunk Cloud SIEM and Cribl Stream/Edge, partnering with the MSSP on detection engineering and optimization
  • Oversee vulnerability management and quality-assure penetration tests
  • Serve as senior escalation point for complex SOC investigations
  • Mentor SOC analysts and junior engineers
  • Contribute to the long-term security roadmap
  • Keep leadership informed on risks and developments and maintain clear architecture and process documentation

Skills

IAM
Entra ID
Active Directory
MFA/passwordless
SSO protocols
Zero-trust
NIST
ISO 27001
MITRE ATT&CK
Splunk Cloud SIEM
CyberArk
SailPoint IdentityIQ
Cribl Stream/Edge
PowerShell
Python
Microsoft Graph API
English communication
German desirable

Education

Bachelor’s degree in IT Security

Tools

Splunk Cloud SIEM
CyberArk
SailPoint IdentityIQ
Cribl Stream/Edge
AWS
Proofpoint
Zscaler
Cisco
FortiGate
PowerShell
Python
Microsoft Graph API

Job description

Your heart beats for identity and access management, and you’re driven by the mission to minimize digital risks and build trust? You enjoy turning complex security requirements into practical, actionable controls? A supportive culture, strong teamwork, and continuous development matter just as much to you as technical expertise? Then welcome to AND-E!

How you'll make an impact
  • Own IAM strategy across Entra ID and Active Directory
  • Manage conditional access, PIM/PAM, and identity lifecycle governance
  • Develop identity-centric detections and threat-hunting workflows, analyzing Entra ID logs and privilege escalation paths in alignment with the SOC
  • Partner with Infrastructure, Client Services, and Cloud Admin teams to review and implement controls across endpoint, email, network, and cloud environments
  • Act as internal advisor for Splunk Cloud SIEM and Cribl Stream/Edge, partnering with the MSSP on detection engineering and optimization
  • Oversee vulnerability management and quality-assure penetration tests
  • Serve as senior escalation point for complex SOC investigations
  • Mentor SOC analysts and junior engineers
  • Contribute to the long-term security roadmap
  • Keep leadership informed on risks and developments and maintain clear architecture and process documentation
What it takes to succeed in this role
  • Bachelor’s degree in IT Security, Cyber Security, or comparable qualification (or equivalent practical experience)
  • 5+ years in IT security engineering or operations, with significant hands‑on IAM responsibility
  • Deep expertise in Entra ID, Active Directory, MFA/passwordless, SSO protocols (SAML, OIDC, SCIM), and identity governance
  • Strong foundation in zero‑trust architecture and frameworks such as NIST, ISO 27001, or MITRE ATT&CK
  • Working knowledge of Splunk Cloud SIEM, CyberArk, SailPoint IdentityIQ,and Cribl Stream/Edge
  • Familiarity with AWS, Proofpoint, and Zscaler/Cisco/FortiGate
  • Proficiency in PowerShell, Python, or Microsoft Graph API
  • Very good English communication skills (German desirable)
  • Certifications such as Microsoft SC-300, SC-100, AZ-500, CISSP, CIDPRO, AWS Security Specialty, GIAC (GCIH, GCIA, GCFA), or Splunk/Cribl are considered a plus
  • Growth is important to us, that’s why we support your personal and professional development
  • A working environment based on trust, encouragement and constructive feedback
  • Collaboration with people from different countries and cultures
  • 32 days annual leave plus 2 days off
  • Flexible working hours and home office policy (approx. 60% possible)
  • Attractive employee conditions for car insurance
  • Exceptional company benefits: Employer subsidy for occupational pension scheme and disability pension, supplementary company health insurance, capital‑forming benefits
  • Optional: Job ticket, car parking spaces, monthly travel allowance
  • EGYM Wellpass
  • Financial subsidy as a small wish‑fulfiller
  • Free coffee, tea, water and weekly fruit delivery
  • Health management and pme family service

At AND-E, we're redefining the future of mobility insurance. As part of the global MS&AD Group and in close partnership with Toyota, we aim to make tomorrow's journeys simpler, safer, and smarter. Our expertise spans over 30 markets in Europe and South Africa, providing tailored insurance solutions for Toyota and Lexus customers and various white‑label partners. In Germany, our offerings include motor insurance, commercial fleet coverage, payment protection insurance, and support for Japanese businesses operating abroad. Our commitment extends beyond business: at AND-E we support our people to grow, make a difference for customers, and help shape the future of connected mobility protection.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer (m/w/d)
Senior Security Engineer (m/w/d)

Aioi Nissay Dowa Europe • Germany (OH)

Hybrid
USD 102,000 - 149,000
Flexible working hours and home office
Car insurance benefits
Pension and health insurance subsidies
+2
Lead Engineer Infrastructure (Platform Services) (m/f/d)
Lead Engineer Infrastructure (Platform Services) (m/f/d)

Aioi Nissay Dowa Europe • Germany (OH)

Hybrid
USD 104,000 - 162,000
32 days annual leave
Home office policy
Health insurance
+6
Third Party Management Expert (m/w/d)
Third Party Management Expert (m/w/d)

Aioi Nissay Dowa Europe • Germany (OH)

Hybrid
USD 110,000 - 150,000
Flexible hours
Home office (60% work from home)
Career development
+1
Lead Infrastructure Engineer – Backup & Disaster Recovery (m/f/d)
Lead Infrastructure Engineer – Backup & Disaster Recovery (m/f/d)

Aioi Nissay Dowa Europe • Germany (OH)

Hybrid
USD 104,000 - 150,000
Employer pension subsidy
Disability pension
Supplementary health insurance
+1
IT Infrastructure & Security Manager (m/f/d)
IT Infrastructure & Security Manager (m/f/d)

Quantum-Systems GmbH • Germany (OH)

Hybrid
USD 90,000 - 120,000
Company pension scheme
Flexible working hours
Mobile Work option
+6
Senior Technical Consultant - Cyber Security (w/m/d)
Senior Technical Consultant - Cyber Security (w/m/d)

IPG Information Process Group AG • Germany (OH)

On-site
USD 81,000 - 106,000
Senior Security Architect: Threat Hunting & SIEM Lead (Hybrid)
Senior Security Architect: Threat Hunting & SIEM Lead (Hybrid)

Aioi Nissay Dowa Europe • Germany (OH)

Hybrid
USD 102,000 - 149,000
Flexible working hours and home office
Car insurance benefits
Pension and health insurance subsidies
+2
(Senior) Identity Management Engineer (m/w/d)
(Senior) Identity Management Engineer (m/w/d)

s.Oliver Gruppe • Germany (OH)

Hybrid
USD 69,000 - 93,000
Attraktive Personalrabatte
Betriebliche Krankenzusatzversicherung
Flexible Arbeitszeiten
+2
IT Security Consultant w/m/d - Access Management
IT Security Consultant w/m/d - Access Management

Computacenter AG & Co. oHG • Germany (OH)

Hybrid
USD 75,000 - 100,000
Mobile Working
Fortbildungsmöglichkeiten
Familienzuschüsse
+3
System Engineer (m/w/d) IAM
System Engineer (m/w/d) IAM

SIGNAL IDUNA • Germany (OH)

Hybrid
USD 70,000 - 89,000
Flexible Arbeitszeiten
30 Tage Urlaub
Teamevents
+1