Job
- Level
- Lead
- Location
- Berlin
- Working Model
- Hybrid, Onsite
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
Job Summary
In this role, you will develop security architectures for multi-tenant infrastructure, review security-impacting changes, and support AI platforms to mitigate risks and ensure compliance.
Job Technologies
Your role in the team
- Define and maintain security architecture standards and hardening baselines for provider-side infrastructure: virtualization and container platforms, control planes and provisioning systems, DNS, mail infrastructure, and backup and recovery systems.
- Assess and strengthen tenant isolation across shared hosting, virtualization, and container layers, and drive remediation with the responsible platform teams.
- Review infrastructure designs and major changes for security impact, and act as an escalation point for infrastructure security questions from platform, cloud, and brand engineering teams.
- Reduce blast radius on the paths that matter most: privileged access to customer-facing infrastructure, administrative segmentation, secrets handling, and recovery integrity - translated into workable per-brand implementation plans across our heterogeneous platforms.
- Support Cyber Defense, Vulnerability Management, and IT Emergency Management with infrastructure expertise during incidents and post-incident hardening.
- Own the security architecture and baseline standards for the AI platforms we run internally: model gateways and self-hosted models, agent frameworks, assistant integrations, connectors, and retrieval pipelines over internal data.
- Define and enforce how agents are identified, authenticated, and authorized: non-human identity handling, credential and token management, least-privilege tool and system access, and where autonomous action requires a human in the loop.
- Establish what data internal AI systems may access and index, and ensure agent activity is logged, attributable, and reviewable to the standard our regulatory and certification obligations require.
- Conduct pre-deployment security reviews for new internal AI platforms and agent use cases at a pace that matches their adoption rate, and maintain an overview of where unsanctioned AI usage is emerging.
- Beraten Sie die Sicherheitsfunktionen und die internen Engineering-Teams bei der sicheren Einführung von KI, einschließlich der Schutzmaßnahmen, die diese Einführung verteidigungsfähig machen.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Deep practical knowledge of Linux, virtualization and container platforms, networking, and the security properties of multi-tenant infrastructure.
- Starker Hintergrund in Identitäts- und Zugriffsmanagement: privilegierter Zugriff, Maschinen- und Workload-Identität, Geheimnisverwaltung, Autorisierungsmodelle und Infrastructure-as-Code-Sicherheit.
- Working knowledge of how LLM and agent systems are built and operated, and of the risks specific to them: prompt injection through untrusted data, over-scoped tool access, data exposure via retrieval, unlogged autonomous action, model and provider dependency.
- Ability to make and defend risk-based decisions, including blocking a deployment with a clear rationale, and to explain technical risk to non-technical stakeholders.
- Fluent English; German is a strong advantage given our regulatory and public-sector environment.
Experience
- Several years of hands-on experience in infrastructure or platform security, ideally at a hosting provider, cloud provider, telco, or comparably large-scale multi-tenant environment.
- Experience designing and enforcing security standards in a heterogeneous, partly legacy landscape, and getting them adopted by teams you do not manage.
This text has been machine translated. Show original
What we offer
- Hybrid working model.
- Flexible working hours through trust-based working hours.
- An einigen Standorten gibt es eine subventionierte Kantine und verschiedene kostenlose Getränke.
- Modern office space with very good transport connections.
- Various employee discounts for activities and products.
- Employee events such as summer and winter parties, as well as workshops.
- Numerous training and development opportunities.
- Various health offers, such as sports and health courses.
This text has been machine translated. Show original
Topics You Will Work On
Job Locations
About Your Employer
Berufliche Schulen Potsdam der ASG - Anerkannten Schulgesellschaft mbH
The Vocational Schools Potsdam of ASG offer a practice-oriented training for educators that closely integrates academic theory with professional practice. A competent team of instructors and regular collaborations with practice partners support the preparation for pedagogical roles in child and youth welfare.
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Education System