Job
- Level
- Lead
- Location
- Berlin
- Working Model
- Hybrid, Onsite
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
Job Summary
In this role, you will be responsible for the security architecture of our infrastructure and internal AI platforms, developing security standards and coordinating their implementation with various platform teams.
Job Technologies
Your role in the team
- Both halves of this role revolve around the same fundamental question: Which systems can access our most sensitive infrastructure and under what controls.
- You will be responsible for the security architecture of our provider-side infrastructure layer and serve as an expert (m/f/d) for the internally operated AI platforms and agents.
- Thereby, you ensure that these run in a secure, managed, and auditable state, rather than gradually accumulating as a new class of privileged access.
- This is a hands-on expert role.
- You set standards, thoroughly review designs, and work directly with platform and engineering teams across all our brands to implement them.
- Define and maintain security architecture standards and hardening baselines for provider-side infrastructure: virtualization and container platforms, control planes and deployment systems, DNS, mail infrastructure, as well as backup and recovery systems.
- Assessing and strengthening client isolation across shared hosting, virtualization, and container layers, as well as driving remediation measures with the responsible platform teams.
- Reviewing infrastructure designs and significant changes for security implications, as well as acting as an escalation point for infrastructure security questions from platform, cloud, and brand engineering teams.
- Reducing the blast radius to the most critical pathways: privileged access to customer-oriented infrastructure, administrative segmentation, handling of secrets, and recovery integrity - translated into actionable, brand-specific implementation plans for our heterogeneous platforms.
- Supporting cyber defense, vulnerability management, and IT emergency management with infrastructure expertise in incidents and post-incident hardening.
- Responsibility for the security architecture and baseline standards for the internally operated AI platforms: model gateways and self-hosted models, agent frameworks, assistant integrations, connectors, and retrieval pipelines over internal data.
- Define and enforce how agents are identified, authenticated, and authorized: handling non-human identities, credential and token management, least privilege access to tools and systems, as well as establishing where autonomous actions require a human-in-the-loop.
- Determine which data internal AI systems are allowed to access and index, as well as ensure that agent activities are logged, attributable, and auditable — in accordance with the requirements of our regulatory obligations and certifications.
- Conducting pre-deployment security assessments for new internal AI platforms and agent use cases in line with the rapid pace of adoption, as well as overseeing unsecure/unauthorized AI usage (Shadow AI).
- Advising security functions and internal engineering teams on the secure implementation of AI, including guardrails that enable responsible deployment.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Deep practical knowledge of Linux, virtualization and container platforms, networks, and the security features of tenant infrastructures.
- Strong background in Identity & Access: Privileged Access, Machine and Workload Identities, Secrets Management, Authorization Models, and Infrastructure-as-Code Security.
- Practical knowledge in the development and operation of LLM and agent systems, as well as the specific risks: prompt injection through unfamiliar data, overly broad tool access, data exposure through retrieval, unlogged autonomous actions, model and provider dependencies.
- Ability to make and defend risk-based decisions – including blocking deployments with clear justification – as well as explaining technical risks to non-technical stakeholders.
- Fluent English skills; German skills are highly advantageous due to our regulatory environment and the public sector.
- Familiarity with NIS2 / BSIG or ISO 27001.
- Background in DNS, email infrastructure, or platform-related abuse prevention (Abuse).
- Background in security engineering or software development (automation, tooling, scripting).
Experience
- Several years of practical experience in infrastructure or platform security, ideally with a hosting provider, cloud provider, telecommunications company, or in a similarly large client environment.
- Experience in developing and implementing security standards in a heterogeneous, partly historically grown landscape, as well as in gaining acceptance within teams outside one's own leadership line.
- Practical experience in deploying or securing internal AI platforms, agent frameworks, or tool-calling integrations in a production environment.
- Experience in a multi-brand or post-acquisition environment where the same control must be implemented across different implementations.
This text has been machine translated. Show original
What we offer
- Hybrid work model.
- Flexible working hours through trust-based working time.
- At some locations, a subsidized canteen and various free beverages.
- Modern office spaces with excellent transportation links.
- Various employee discounts for activities and products.
- Employee events such as summer and winter parties, as well as workshops.
- Numerous opportunities for further training and development.
- Various health offerings, such as sports and wellness courses.
This text has been machine translated. Show original
Benefits
Health, Fitness & Fun
Work-Life-Integration
Food & Drink
Topics You Will Work On
Job Locations
About Your Employer
1&1 Internet AG
With our strong brands 1&1, GMX, WEB.DE and mail.com, we are the leading provider of consumer applications in Germany with over 30 million active users. We make communication even safer - with up to 500 million incoming e-mails per day! With our advanced security facilities, we ensure that your data is always protected. So you can relax and concentrate on the really important things.
Description
- Company Size
- 250+ Employees
- Company Type
- Established Company
- Working Model
- Full Remote, Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication
Employer reviews
by devworkplaces.com
Total
(1 Review)Career Growth
3.4Workingconditions
4.4Engineering
2.7Culture
3.5