For us, security isn't an afterthought or a checkbox exercise – it's built right into our DNA. We integrate security exactly where it matters most: into our architectures, pipelines, and operational concepts. Compliance evidence is generated naturally from our day-to-day operations, not from stressful last-minute audit prep. We are looking for someone who can translate security requirements into resilient technical concepts and actively verify their effectiveness.
Tasks
- Drive the evolution of our Secure SDLC side-by-side with our dev teams.
- Lead Threat Modeling and architecture reviews – catching risks early in the design phase, not right before a release.
- Design robust IAM concepts (role models, permission logic, recertification) and define clear cryptographic standards and baselines.
- Take charge of vulnerability and pentest management: scanning, CVSS scoring, prioritizing, and tracking remediations.
- Specify requirements for logging, monitoring, and error handling, and review their implementation across the board.
- Design and evaluate technical Business Continuity (BC) and disaster recovery tests.
- Automate compliance and evidence collection directly within the teams' CI/CD pipelines.
Qualifications
- Well-founded, multi-year practitioner’s experience with standardised management systems and certifications, attestations in the cyber security area.
- You have practical experience from two or more certified scopes according to ISO 27001, IT-Grundschutz, BSI C5. More ISO management system experience from privacy standards comes as a plus.
- You have multi-year experience with above standards and certifications in a technical organisation, as in the company offers technical products.
- You are burning for modern tool supported, efficient integration of management systems and certification activities into the daily routine of an organisation.
- You love technology, you do not shy away from documentation but would like to structure it as efficiently as possible.
- You convince through your confident and communicative character when achieving goal oriented results with your international and internal interfaces.
- You proficiently lead discussions in English (CEFR C1 or higher). Completely fluent German (C1 CEFR level is a must).
Nice to Have
- Deep conceptual knowledge of IAM (Role/Permission models, SSO, Federation, PAM, recertification logic).
- Practical experience with applied cryptography (TLS, PKI, Key Management, HSM).
- Familiarity with major frameworks (ISO/IEC 27001 Annex A, BSI IT-Grundschutz, OWASP ASVS & Top 10, CIS Benchmarks, NIST CSF).
- Experience with Policy as Code and Continuous Compliance.
- An understanding of audit logic and how to collaborate smoothly with external auditors.
Benefits
- Hybrid working model with home office option.
- Flexible working hours through trust-based working hours.
- At some locations a subsidized canteen and various free drinks.
- Modern office space with very good transport connections.
- Various employee discounts for activities and products.
- Employee events such as summer and winter parties, as well as workshops.
- Numerous training and development opportunities.
- Various health offers, such as sports and health courses.
#J-18808-Ljbffr
Staff Information Security Manager (f/m/d) in Berlin Arbeitgeber: IONOS Group
Als Arbeitgeber bieten wir Ihnen die Möglichkeit, in einem dynamischen und innovativen Umfeld zu arbeiten, das auf Teamarbeit und kontinuierliche Verbesserung setzt. Unsere flexiblen Arbeitszeiten und das hybride Arbeitsmodell ermöglichen es Ihnen, Beruf und Privatleben optimal zu vereinbaren. Zudem fördern wir Ihre persönliche und berufliche Entwicklung durch zahlreiche Schulungs- und Weiterbildungsmöglichkeiten sowie regelmäßige Mitarbeiterveranstaltungen.