Job
- Level
- Experienced
- Location
- Berlin
- Working Model
- Hybrid, Onsite
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
Job Summary
In this role, you will be responsible for building the Secure SDLC, conducting threat modeling, developing IAM concepts, and managing vulnerabilities within CI/CD pipelines.
Job Technologies
Your role in the team
- Drive the development and continuous improvement of our Secure SDLC directly alongside the Dev Teams.
- Conduct threat modeling and architecture reviews early in the design phase, not just shortly before release.
- Design modern IAM concepts (role models, permission logic, recertification procedures) and define cryptographic standards and baselines.
- Manage vulnerability and penetration test processes: scanning, CVSS assessment, prioritization, and remediation tracking.
- Specify logging, monitoring, and error handling requirements and oversee their implementation.
- Design and evaluate technical Business Continuity (BC) and disaster recovery tests.
- Automate evidence collection (Compliance as Code) directly within the teams' CI/CD pipelines.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Secure scripting and automation skills (Python, Bash, Infrastructure as Code), ideally already used for automated proof generation.
- A keen eye for Security Design Principles and Threat Modeling.
- Strong consulting and review skills. You successfully enforce security requirements on Dev and Ops teams without taking away their technical responsibility.
- SAST, DAST, and SCA tooling.
- DefectDojo as a vulnerability management platform; SIEM and monitoring platforms.
- IAM/PAM and PKI (operated by partner teams).
- Deep integration into CI/CD pipelines and ticketing systems for automated proof generation.
- Fluent German and English skills (at least C1 level).
Experience
- Several years of solid experience with Linux and modern cloud infrastructure (including containers, orchestration, and networking).
- Practical experience in vulnerability scanning, CVSS assessment, and triage of pentest findings.
This text has been machine translated. Show original
What we offer
- Hybrid work model with the option for remote work.
- Flexible working hours through trust-based working time.
- At some locations, a subsidized canteen and various free beverages.
- Modern office spaces with excellent transportation links.
- Various employee discounts for activities and products.
- Employee events such as summer and winter parties, as well as workshops.
- Numerous opportunities for further training and development.
- Various health offerings, such as sports and health courses.
This text has been machine translated. Show original
Benefits
Health, Fitness & Fun
Work-Life-Integration
Food & Drink
Topics You Will Work On
Job Locations
About Your Employer
1&1 Internet AG
With our strong brands 1&1, GMX, WEB.DE and mail.com, we are the leading provider of consumer applications in Germany with over 30 million active users. We make communication even safer - with up to 500 million incoming e-mails per day! With our advanced security facilities, we ensure that your data is always protected. So you can relax and concentrate on the really important things.
Description
- Company Size
- 250+ Employees
- Company Type
- Established Company
- Working Model
- Full Remote, Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication
Employer reviews
by devworkplaces.com
Total
(1 Review)3.5
Career Growth
3.4Workingconditions
4.4Engineering
2.7Culture
3.5