Logo MÜNCHENER VEREIN Versicherungsgruppe

IT Security Specialist Operational IT Security & DevSecOps

New

Job

  • Level
    Experienced
  • Job Field
    IT, Security
  • Employment Type
    Full Time
  • Contract Type
    Permanent employment
  • Location
    Munich
  • Working Model
    Hybrid, Onsite
  • Job Summary

    In this position, you will take responsibility for operative IT security, enhance security tools, integrate log sources, optimize incident response playbooks, and implement security measures in CI/CD pipelines.

    Job Technologies

    Your role in the team

    • Join our 10-member DevOps, Network, and Platform team and take responsibility for operational IT security.
    • You configure and develop our security tools further, identify new threats, prioritize vulnerabilities, and actively drive the security maturity of our company forward - from the SIEM platform to the first internal penetration test.
    • SIEM Operations & Detection Engineering: You administer Elastic Security, integrate log sources (Windows, M365, firewalls), and develop precise detection rules based on the MITRE ATT&CK framework.
    • Vulnerability Management: With Tenable Security Center, you manage risk-based scans across the entire infrastructure, prioritize vulnerabilities, and oversee remediation.
    • DevSecOps & CI/CD Security: You implement security gates in GitLab (SAST/DAST, container scanning) and advise development on security-by-design as well as secure coding.
    • Incident Response & Resilience: You optimize IR playbooks, assist with root cause analysis of security incidents, and derive preventive measures from them.
    • Security processes & pentesting: You develop existing security standards further and establish internal pentesting as a new discipline for targeted identification of hardening potentials.

    This text has been machine translated. Show original

    Our expectations of you

    Qualifications

    • Knowledge of the following technologies will facilitate your entry into our team - you don't have to bring everything, but you should be confident in the core areas:
    • DevSecOps & CI/CD: Knowledge of GitLab Ultimate (CI/CD, Security Scanning, Merge Request Workflows) as well as a basic understanding of SAST/DAST integration, IaC scanning, and container/dependency scanning in development pipelines.
    • Threat landscape & regulation: Understanding current cyber threats and MITRE ATT&CK; basic knowledge of DORA, BSI IT-Grundschutz, or ISO 27001. Python, PowerShell, or Bash for automation.
    • You hold yourself to a standard of proactively taking responsibility for topics and successfully implementing your own ideas with the team.
    • Desirable certifications: CompTIA Security+, CySA+, OSCP, Elastic Certified Analyst, SC-200 or equivalent - not mandatory but welcome.
    • Last but not least: In addition to German, you also speak fluent Meme and Gif.

    Experience

    • Elastic Security/SIEM: Practical experience with KQL, Detection Engineering, and Log Analysis.
    • Vulnerability Management: Experience in operating and analyzing Tenable Security Center, Tenable.io, or comparable vulnerability management tools; basic understanding of SCA and container image scanning is advantageous.
    • Incident Response: Basic understanding of incident response procedures, escalation processes, and technical forensics; experience with playbooks or security runbooks is a plus.
    • Initial experience in Penetration Testing—whether in CTFs, internal labs, or external assessments—is a real plus. More importantly: you are eager to explore this field with us.

    This text has been machine translated. Show original

    What we offer

    • A modern workplace in the heart of Munich (5 minutes from the main train station).
    • Flexibility through a hybrid work model with home office and flexible working hours.
    • Excellent compensation package including holiday and Christmas bonuses.
    • Numerous social benefits - including JobRad, our company canteen, transportation allowance, occupational pension scheme, corporate health insurance, massage services, our exclusive housing exchange, and much more.
    • An exciting role with autonomous task management within the team.
    • We offer ample opportunities for your personal development - including attending industry conferences.

    This text has been machine translated. Show original

    Benefits

    Work-Life-Integration

    Higher Take-Home Pay

    Food & Drink

    Health, Fitness & Fun

    Topics You Will Work On

    Job Locations

    • Location Munich

      Bayern

      Germany

    About Your Employer

    MÜNCHENER VEREIN Versicherungsgruppe

    MÜNCHENER VEREIN Versicherungsgruppe

    Die Münchener Verein Versicherungsgruppe, gegründet 1922, ist ein bundesweit tätiger Versicherer mit den Sparten Kranken-, Pflege-, Lebens-, Renten- sowie Sach- und HUK-Versicherungen. Als Vorsorge- und Pflege-Spezialist bieten wir leistungsstarke und vielfach ausgezeichnete Versicherungsprodukte für den privaten und gewerblichen Bereich.

    Description

  • Founding Year
    1922
  • Company Type
    Established Company
  • Working Model
    Hybrid, Onsite
  • Industry
    Banking, Finance, Insurance
  • Logo MÜNCHENER VEREIN Versicherungsgruppe

    IT Security Specialist Operational IT Security & DevSecOps

    Location
    Munich
    Working Model
    Hybrid, Onsite
    Diversity
    Open for all genders

    More Jobs