Staff Security Engineer, CSIRT

Staff Security Engineer, CSIRT

Vollzeit 49500 - 60500 € / Jahr (geschätzt) Homeoffice (teilweise)
D

Auf einen Blick

  • Aufgaben: Leite kritische Sicherheitsvorfälle und entwickle innovative Lösungen zur Verbesserung der Reaktionsfähigkeit.
  • Unternehmen: Wachsendes Unternehmen im Bereich Cyber-Sicherheit mit einem dynamischen Team.
  • Vorteile: 27 Tage Urlaub, Weiterbildungsmöglichkeiten und Gesundheitsförderung.
  • Weitere Informationen: Hybrid-Arbeitsmodell mit persönlichem Austausch in Berlin und einem unterstützenden Arbeitsumfeld.
  • Warum dieser Job: Gestalte die Zukunft der Cybersicherheit in einer globalen Plattform und mache einen echten Unterschied.
  • Qualifikationen: Mindestens 7 Jahre Erfahrung in der Cybersicherheit und Führungskompetenz in Krisensituationen.

Das prognostizierte Gehalt liegt zwischen 49500 - 60500 € pro Jahr.

  • Staff Security Engineer, CSIRT
  • Cyber-Security-Consultant

As a Staff Security Engineer within our CSIRT Team, you will be accountable for leading our most critical, complex, and high-impact security incidents end-to-end across a global, high-transaction food delivery and quick-commerce platform handling millions of daily orders.

As a business spanning logistics, e-commerce, and Fin Tech, our environment is highly regulated, in this role you will navigate the complexities of global compliance frameworks while ensuring rapid, effective incident mitigation.

You will operate at the intersection of a hands‑on technical practitioner and a strategic leader, making high‑consequence decisions during times of ambiguity.

We are looking for someone with a strong 'builder mindset'.

You don't just respond to security incidents; you approach operational bottlenecks as engineering problems.

You will build systems, develop custom tooling, and architect automated workflows to relentlessly eliminate manual toil and scale our response capabilities, ultimately setting the standard for engineering excellence and fostering a security mindset across the organization.

  • Mission
  • Incident

Commander: Serve as the single accountable leader during active responses for high‑severity incidents, directing investigative focus from detection through recovery while maintaining a calm and decisive demeanor under pressure.

You will ensure our response strategies and forensic evidence gathering align with strict reporting requirements for GDPR, PCI‑DSS, NIS2, DORA, MAS TRM, and other regional mandates.

  • Post‑Incident Reviews & Remediation: Lead blameless post‑incident reviews to ensure continuous improvement, durable engineering solutions, and systemic resilience.
  • Stakeholder

Communication: Serve as the primary interface to stakeholders during critical security incidents, translating complex technical realities into clear risk, impact, and decision frameworks.

  • Engineering‑Led Response & Automation: Design and develop in‑house solutions, automated workflows, and scalable systems to eliminate repetitive processes, reduce triage time, and continuously improve the overall quality and efficiency of our security incident response operations.
  • Mentorship & Leadership: Act as a hands‑on technical leader and role model, actively mentoring teams and individuals within your domain to raise the overall technical bar and share your experience.
  • Metrics & Strategic

Visibility: Have a Data‑Driven Strategic mindset to define, track, and improve core operational metrics (MTTD, MTTR) to identify systemic gaps and propose strategic, long‑term security investments.

  • Organizational Readiness & Tabletop

Exercises: Proactively design and facilitate complex, realistic tabletop simulations and purple team engagements to stress‑test our playbooks, uncover detection blind spots, and train the wider security and engineering organizations.

  • On‑Call: Participate in a predictable on‑call rotation as an Incident Responder, leading the charge on high‑severity, out‑of‑hours escalations.

Qualifications

  • 7+ years of broad cybersecurity experience with a deep understanding of core security fundamentals, coupled with 5+ years of dedicated experience in a SOC or CSIRT environment.
  • Incident
  • Commander

Experience: Proven track record acting as a Security Incident Commander, confidently managing incident timelines, decisions, and cross‑functional communications during complex security events.

  • Deep Security
  • Incident
  • Response

Expertise: Mastery of the full incident lifecycle and hands‑on playbook creation for complex, high‑availability hybrid‑cloud environments, distributed microservices, and platforms processing vast amounts of PII and payment data.

  • Security Tooling Mastery: Operational expertise with SIEM, EDR, Cloud Security platforms, SOAR, and WAF/DDo S protection solutions.
  • Software Engineering & Tooling (Builder Mindset): Advanced proficiency in writing production‑quality code (e. g., Python, Go, Rust) to build scalable in‑house solutions.
  • Cloud‑Native

Security: Hands‑on experience securing and responding to incidents across public cloud platforms (AWS, GCP) and cloud‑native technologies like Kubernetes, Docker, and Infrastructure‑as‑Code (e. g., Terraform).

  • Source Control & CI/CD: Familiarity with Git/Git Hub usage, CI/CD systems, and modern Sec Ops workflows.
  • Strategic

Leadership: An exceptional communicator with the ability to influence cross‑functional stakeholders and simplify complex systems across domains without requiring formal authority.

  • Nice to have
  • Investigative Depth: Digital forensics skills and hands‑on experience integrating Threat Intelligence to anticipate attacks and proactively hunt for threats.
  • Malware Analysis & Reverse

Engineering: Proven skills in static and dynamic (runtime) malware analysis, reverse engineering, and analyzing malicious payloads within isolated sandbox environments.

  • Web/Mobile

Security: Strong background in Web and Mobile application security, understanding complex API architectures, modern authentication frameworks, and defending against high‑volume automated attacks.

  • AI & Next‑Gen

Tooling: Experience integrating AI/LLM capabilities and MCP (Model Context Protocol) usage into Incident Response for automated evidence summarization, data enrichment, or investigation.

  • Regulated
  • Environment

Expertise: Deep operational understanding of global cybersecurity and privacy frameworks (e. g., PCI‑DSS, GDPR, NIS2, DORA, MAS TRM).

You know how to balance aggressive incident containment with the legal and forensic requirements necessary for regulatory compliance and breach notification.

  • Relevant
  • Technical

Certifications: Active or in‑progress industry‑recognized technical certifications focused on incident handling, forensics, or offensive security (e. g., GIAC GCIH/GCFA/GCIA, CISSP, OSCP).

  • Additional Information
  • Make the most of our hybrid working model and join the team for face‑to‑face connection and collaboration in our beautiful Berlin campus 2 days a week
  • We offer 27 days holiday
  • We will support you in developing yourself and your career growth opportunities: 1.000 € Educational Budget, Language Courses, Parental Support, access to the Udemy Business platform to explore a variety of online courses
  • Get moving and release those wonderful, mind‑boosting endorphins: Health Checkups, Mindfulness and Gym & Bicycle Subsidy
  • The power of getting together over some food is unrivalled.

Here are a few ways to help you do that.

All the yum: Digital Meal Vouchers, Food Vouchers, Corporate Discounts.

Courses and access to Internal Housing Hub

Ready to join our team? If you’re excited to grow, collaborate and be part of the world’s leading delivery platform, we’d love to hear from you. Apply today!

We believe diversity and inclusion are key to creating not only an exciting product, but also an amazing customer and employee experience.

Fostering this starts with hiring - therefore we do not discriminate on the basis of racial identities, religious beliefs, color, national origin, gender identities or expressions, sexual orientations, age, marital or disability statuses, or any other aspect that makes you, you.

We encourage you to let us know if you need any accommodations or specific accessibility support to ensure a smooth interview experience—just let us know with an email to our Inclusion Officer at inclusion@deliveryhero. com.

Severely disabled applicants with equal qualifications will be given preferential consideration.

You're welcome to share your pronouns (he/she/they) right from the start so we can address you respectfully from our first contact.

#J-18808-Ljbffr

Staff Security Engineer, CSIRT Arbeitgeber: Delivery Hero SE

Delivery Hero ist ein hervorragender Arbeitgeber, der eine dynamische und unterstützende Arbeitsumgebung in Berlin bietet. Mit einem hybriden Arbeitsmodell, großzügigen Urlaubstagen und einem umfangreichen Bildungsbudget fördert das Unternehmen die persönliche und berufliche Entwicklung seiner Mitarbeiter. Die Kombination aus hoher Leistung, einer starken Gemeinschaft und innovativen Produkten im Bereich Display-Werbung macht Delivery Hero zu einem attraktiven Arbeitsplatz für ambitionierte Fachkräfte.

D

Kontaktdaten:

Delivery Hero SE Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Staff Security Engineer, CSIRT erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Delivery Hero SE kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Delivery Hero SE zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Delivery Hero SE.

Wir glauben, dass du diese Fähigkeiten brauchst, um Staff Security Engineer, CSIRT mit Bravour zu bestehen

Cybersecurity Erfahrung
Incident Commander Erfahrung
Sicherheitsvorfall Reaktionskompetenz
SIEM und EDR Kenntnisse
Cloud-Sicherheit (AWS, GCP)
Software Engineering (Python, Go, Rust)
Kubernetes und Docker Kenntnisse

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei Delivery Hero SE vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Delivery Hero SE könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Delivery Hero SE sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird Delivery Hero SE auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!