Job
- Level
- Experienced
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Munich
- Working Model
- Hybrid, Onsite
Job Summary
In this position, you will take responsibility for operative IT security, enhance security tools, integrate log sources, optimize incident response playbooks, and implement security measures in CI/CD pipelines.
Job Technologies
Your role in the team
- Join our 10-member DevOps, Network, and Platform team and take responsibility for operational IT security.
- You configure and develop our security tools further, identify new threats, prioritize vulnerabilities, and actively drive the security maturity of our company forward - from the SIEM platform to the first internal penetration test.
- SIEM Operations & Detection Engineering: You administer Elastic Security, integrate log sources (Windows, M365, firewalls), and develop precise detection rules based on the MITRE ATT&CK framework.
- Vulnerability Management: With Tenable Security Center, you manage risk-based scans across the entire infrastructure, prioritize vulnerabilities, and oversee remediation.
- DevSecOps & CI/CD Security: You implement security gates in GitLab (SAST/DAST, container scanning) and advise development on security-by-design as well as secure coding.
- Incident Response & Resilience: You optimize IR playbooks, assist with root cause analysis of security incidents, and derive preventive measures from them.
- Security processes & pentesting: You develop existing security standards further and establish internal pentesting as a new discipline for targeted identification of hardening potentials.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Knowledge of the following technologies will facilitate your entry into our team - you don't have to bring everything, but you should be confident in the core areas:
- DevSecOps & CI/CD: Knowledge of GitLab Ultimate (CI/CD, Security Scanning, Merge Request Workflows) as well as a basic understanding of SAST/DAST integration, IaC scanning, and container/dependency scanning in development pipelines.
- Threat landscape & regulation: Understanding current cyber threats and MITRE ATT&CK; basic knowledge of DORA, BSI IT-Grundschutz, or ISO 27001. Python, PowerShell, or Bash for automation.
- You hold yourself to a standard of proactively taking responsibility for topics and successfully implementing your own ideas with the team.
- Desirable certifications: CompTIA Security+, CySA+, OSCP, Elastic Certified Analyst, SC-200 or equivalent - not mandatory but welcome.
- Last but not least: In addition to German, you also speak fluent Meme and Gif.
Experience
- Elastic Security/SIEM: Practical experience with KQL, Detection Engineering, and Log Analysis.
- Vulnerability Management: Experience in operating and analyzing Tenable Security Center, Tenable.io, or comparable vulnerability management tools; basic understanding of SCA and container image scanning is advantageous.
- Incident Response: Basic understanding of incident response procedures, escalation processes, and technical forensics; experience with playbooks or security runbooks is a plus.
- Initial experience in Penetration Testing—whether in CTFs, internal labs, or external assessments—is a real plus. More importantly: you are eager to explore this field with us.
This text has been machine translated. Show original
What we offer
- A modern workplace in the heart of Munich (5 minutes from the main train station).
- Flexibility through a hybrid work model with home office and flexible working hours.
- Excellent compensation package including holiday and Christmas bonuses.
- Numerous social benefits - including JobRad, our company canteen, transportation allowance, occupational pension scheme, corporate health insurance, massage services, our exclusive housing exchange, and much more.
- An exciting role with autonomous task management within the team.
- We offer ample opportunities for your personal development - including attending industry conferences.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
Higher Take-Home Pay
Food & Drink
Health, Fitness & Fun
Topics You Will Work On
Job Locations
About Your Employer
MÜNCHENER VEREIN Versicherungsgruppe
Die Münchener Verein Versicherungsgruppe, gegründet 1922, ist ein bundesweit tätiger Versicherer mit den Sparten Kranken-, Pflege-, Lebens-, Renten- sowie Sach- und HUK-Versicherungen. Als Vorsorge- und Pflege-Spezialist bieten wir leistungsstarke und vielfach ausgezeichnete Versicherungsprodukte für den privaten und gewerblichen Bereich.
Description
- Founding Year
- 1922
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Banking, Finance, Insurance