Job
- Level
- Lead
- Job Field
- IT, Network, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Augsburg, Munich
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will optimize the cyber security infrastructure, analyze complex technical issues in a hybrid Linux environment, implement CI/CD pipelines, and develop new security projects for an international company.
Job Technologies
Your role in the team
- We are looking for reinforcement for the operation and technical further development of the global infrastructure of the Cyber Defense Center for our internationally active client.
- You work directly within the client's IT environment, operate, analyze, and optimize all components of the infrastructure (e.g., IAM, logging/sensor concepts, firewalls, VM and container infrastructure), and ensure, among other things, compliance with requirements from BCM and information security.
- You are operationally responsible for ensuring that all CDC applications function reliably and resiliently, deliver data of the required quality, and remain stable in operation—including adjustments, coordination, and implementation within a customer environment with clear processes.
- The scope of responsibilities primarily focuses on infrastructure and monitoring.
- Daily operation and further development of the entire Cyber Defense Center infrastructure of an international corporation.
- You operate, debug, and analyze disruptions in a predominantly Linux-based hybrid infrastructure (Private/Public Cloud, On-Premises) - from the operating/operations system level to the application layer.
- Technical leadership: Guidance for the operations team as well as the first point of contact for all technical inquiries.
- Initiation of new projects to further develop the Cyber Defense Center and to drive the implementation of new tools and technologies.
- Debugging and troubleshooting of tools and applications with 1st to 3rd level support as well as engineering of software providers.
- Consulting on the use of new Threat Intelligence sources as well as Attack Patterns.
- Technical implementation of detection mechanisms.
- Planning and technical implementation of CI/CD pipelines, e.g., for Kubernetes deployments.
- Detection and mitigation/mitigation of supply chain attacks for tools and applications used in the Cyber Defense Center.
- Operation and further development of IAM solutions (Identity & Access Management) used within the Cyber Defense Center.
- Responsible for certificate management (e.g., renewals, selection of encryption algorithms, CRLs, etc.).
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Fluent in English, ideally also fluent in German.
- Good ability to understand source code of programming languages such as Rust, Go, Java.
- Very good understanding of the MITRE ATT&CK framework.
- (Very) good understanding of malware analysis and forensics.
- (Very) good understanding of pentesting tools and techniques for networks and systems.
Experience
- At least 15+ years of experience in enterprise-scale Linux environments, including debugging and a deep understanding of security-critical functions.
- Experience with RedHat Linux and Debian Linux is preferred.
- At least 15+ years of experience with IT networks, protocols (including routing), VPN, VLAN - including debugging.
- At least 5+ years of experience in various types of virtual environments.
- At least 7+ years of experience in network security (firewalls, IDS/IPS, WAF, ...).
- Expertise and extensive experience in scripting/programming with Python and PHP.
- Expert-level knowledge and experience with CI/CD pipelines, preferably with tools such as GitHub Actions and Argo CD for Kubernetes deployments.
- Expert-level knowledge and at least 10 years of experience with encryption techniques: algorithms, certificate management, key exchange, etc.
- At least 7+ years of experience in developing complex Infrastructure-as-Code (IaC) and Configuration-as-Code (CaC) environments on-premises and in the cloud (Azure, AWS).
- At least 10 years of experience working with various databases including debugging (e.g., MySQL, MongoDB, ...) in enterprise-scale architectures.
- At least 5+ years of experience with containers (Docker, ...).
- At least 5+ years of experience in Cloud Security: public and private clouds.
- At least 5+ years of experience in Threat Intelligence: Ability to identify and utilize modern Threat Intelligence sources.
- At least 4+ years of experience with MISP (MISP Intelligence Sharing): installation and operation including debugging.
- At least 5+ years of experience in secure software development, including application pentesting and vulnerability management.
- 3-5 years of experience in Endpoint Security.
- Several years of experience with the following tools in cloud environments (private/public) as well as in large on-premises environments: Docker, Kubernetes, Keycloak, Proxmox.
- Experience with the following additional tools is preferred: Terraform, Ansible, ServiceNow, Jira, Splunk Phantom, Palo Alto Cortex, IBM Resilient.
This text has been machine translated. Show original
What we offer
- Responsible tasks in an international environment.
- Mobile Office Option.
- Structured onboarding phase with mentors.
- Support for your individual development.
- 30 vacation days + option for 2 weeks of unpaid leave, sabbatical & workation.
- Flexible working hours and work time models.
- Corporate Benefits.
- Pizza and Bowl Days at our locations in Munich and Augsburg.
- EGym Wellpass.
- Job Rad.
- Various team events (Oktoberfest, Christmas party, after-work drinks, barbecue events on our rooftop terraces).
- Small tokens of appreciation for birthdays, anniversaries, and special occasions.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Health, Fitness & Fun
Topics that you deal with on the job
Job Locations
This is your employer
Orange Cyberdefense
Orange Cyberdefense is a business unit of the Orange Group specializing in cybersecurity, supporting organizations worldwide with security services. The company offers solutions in the areas of Managed Security, Threat Detection and Response, and Threat Intelligence. With an international network of locations and services, Orange Cyberdefense positions itself as a leading provider of security services.
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication