Logo Berufliche Schulen Potsdam der ASG - Anerkannten Schulgesellschaft mbH

Cyber Security Engineer - Infrastructure & AI Platform Security

New

Job

  • Level
    Lead
  • Location
    Berlin
  • Working Model
    Hybrid, Onsite
  • Job Field
    IT, Security
  • Employment Type
    Full Time
  • Contract Type
    Permanent employment

Job Summary

In this role, you will develop security architectures for multi-tenant infrastructure, review security-impacting changes, and support AI platforms to mitigate risks and ensure compliance.

Job Technologies

Your role in the team

  • Define and maintain security architecture standards and hardening baselines for provider-side infrastructure: virtualization and container platforms, control planes and provisioning systems, DNS, mail infrastructure, and backup and recovery systems.
  • Assess and strengthen tenant isolation across shared hosting, virtualization, and container layers, and drive remediation with the responsible platform teams.
  • Review infrastructure designs and major changes for security impact, and act as an escalation point for infrastructure security questions from platform, cloud, and brand engineering teams.
  • Reduce blast radius on the paths that matter most: privileged access to customer-facing infrastructure, administrative segmentation, secrets handling, and recovery integrity - translated into workable per-brand implementation plans across our heterogeneous platforms.
  • Support Cyber Defense, Vulnerability Management, and IT Emergency Management with infrastructure expertise during incidents and post-incident hardening.
  • Own the security architecture and baseline standards for the AI platforms we run internally: model gateways and self-hosted models, agent frameworks, assistant integrations, connectors, and retrieval pipelines over internal data.
  • Define and enforce how agents are identified, authenticated, and authorized: non-human identity handling, credential and token management, least-privilege tool and system access, and where autonomous action requires a human in the loop.
  • Establish what data internal AI systems may access and index, and ensure agent activity is logged, attributable, and reviewable to the standard our regulatory and certification obligations require.
  • Conduct pre-deployment security reviews for new internal AI platforms and agent use cases at a pace that matches their adoption rate, and maintain an overview of where unsanctioned AI usage is emerging.
  • Beraten Sie die Sicherheitsfunktionen und die internen Engineering-Teams bei der sicheren Einführung von KI, einschließlich der Schutzmaßnahmen, die diese Einführung verteidigungsfähig machen.

This text has been machine translated. Show original

Our expectations of you

Qualifications

  • Deep practical knowledge of Linux, virtualization and container platforms, networking, and the security properties of multi-tenant infrastructure.
  • Starker Hintergrund in Identitäts- und Zugriffsmanagement: privilegierter Zugriff, Maschinen- und Workload-Identität, Geheimnisverwaltung, Autorisierungsmodelle und Infrastructure-as-Code-Sicherheit.
  • Working knowledge of how LLM and agent systems are built and operated, and of the risks specific to them: prompt injection through untrusted data, over-scoped tool access, data exposure via retrieval, unlogged autonomous action, model and provider dependency.
  • Ability to make and defend risk-based decisions, including blocking a deployment with a clear rationale, and to explain technical risk to non-technical stakeholders.
  • Fluent English; German is a strong advantage given our regulatory and public-sector environment.

Experience

  • Several years of hands-on experience in infrastructure or platform security, ideally at a hosting provider, cloud provider, telco, or comparably large-scale multi-tenant environment.
  • Experience designing and enforcing security standards in a heterogeneous, partly legacy landscape, and getting them adopted by teams you do not manage.

This text has been machine translated. Show original

What we offer

  • Hybrid working model.
  • Flexible working hours through trust-based working hours.
  • An einigen Standorten gibt es eine subventionierte Kantine und verschiedene kostenlose Getränke.
  • Modern office space with very good transport connections.
  • Various employee discounts for activities and products.
  • Employee events such as summer and winter parties, as well as workshops.
  • Numerous training and development opportunities.
  • Various health offers, such as sports and health courses.

This text has been machine translated. Show original

Topics You Will Work On

Job Locations

  • Location Berlin

    Germany

About Your Employer

Berufliche Schulen Potsdam der ASG - Anerkannten Schulgesellschaft mbH

Berufliche Schulen Potsdam der ASG - Anerkannten Schulgesellschaft mbH

The Vocational Schools Potsdam of ASG offer a practice-oriented training for educators that closely integrates academic theory with professional practice. A competent team of instructors and regular collaborations with practice partners support the preparation for pedagogical roles in child and youth welfare.

Description

  • Company Type
    Established Company
  • Working Model
    Hybrid, Onsite
  • Industry
    Education System
Logo Berufliche Schulen Potsdam der ASG - Anerkannten Schulgesellschaft mbH

Cyber Security Engineer - Infrastructure & AI Platform Security

Location
Berlin
Working Model
Hybrid, Onsite
Diversity
Open for all genders

More Jobs