Job
- Level
- Experienced
- Location
- Berlin
- Working Model
- Hybrid, Onsite
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
Job Summary
In this role, you will support and enhance the vulnerability management program, engage in security assessments and incident response activities, and configure security tools to improve the overall security posture across the infrastructure.
Job Technologies
Your role in the team
- Support and continuously improve the vulnerability management program - defining processes for identifying, prioritizing, tracking, and driving remediation of security findings across infrastructure and applications. This includes working closely with engineering, operations, and IT teams to ensure findings are understood, assigned, and resolved in a timely manner, and reporting on program health and trends to security leadership.
- Participate in incident response activities, including triage, investigation, containment, and post-incident documentation.
- Support application security initiatives, including automated code scanning, dependency analysis, and working with engineering teams to address security findings early in the development process.
- Help configure, monitor, and improve security tooling across areas such as endpoint protection, email security, identity and access management, and cloud security posture.
- Contribute to security automation and orchestration workflows that reduce manual effort and improve response times.
- Collaborate with engineering, operations, and compliance teams to embed security thinking into development workflows and infrastructure changes.
- Document processes, runbooks, and findings to support team knowledge sharing and continuity.
- Participate in access reviews and support identity and access management processes in line with established policies.
- Bleiben Sie auf dem Laufenden mit der sich entwickelnden Bedrohungslandschaft und bringen Sie Ideen ein, um die Erkennungs- und Reaktionsfähigkeiten des Teams zu verbessern.
This text has been machine translated. Show original
Our expectations of you
Education
- A solid understanding of cybersecurity fundamentals - including networking, operating systems (Linux, macOS, or Windows), and cloud environments - gained through any combination of formal education, self-study, bootcamps, or professional experience.
- Comfort working with some degree of autonomy on assigned tasks and projects, while knowing when to ask for input.
Qualifications
- The ability to communicate clearly in writing and in conversation - our team is globally distributed and works primarily in English (professional working proficiency is sufficient; native fluency is not required).
- A collaborative approach to problem-solving - you ask questions, share what you learn, and support your teammates.
Experience
- Hands-on experience in at least one security domain, such as vulnerability management, incident response, application security, endpoint security, or identity and access management.
- Experience working with security tooling (e.g., vulnerability scanners, endpoint detection and response platforms, SIEM systems, or similar); familiarity with specific tools is a plus, but willingness to learn our stack matters more than exact tool experience.
- Familiarity with AI tools and how they can be applied in a security context - whether for automating workflows, triaging alerts, or improving detection and response. Experience working with AI models or building AI-assisted workflows is a plus.
This text has been machine translated. Show original
What we offer
- Work from (almost) anywhere for up to 20 days per year.
- Focus on mental health and well-being: Company-paid therapy sessions through SpringHealth, company-paid subscription to HeadSpace, company-wide week off a year - the whole team fully recharges (and returns without a pile-up of work!).
- No meeting Fridays.
- Bezahlter Elternurlaub.
- Generous paid vacation + time off for your birthday.
- Paid volunteer time.
- Focus on your career growth: Development Dollars, Leadership development, Access to thousands of on-demand e-learnings.
- Travel Discounts.
- Employee Resource Groups.
- 6 weeks paid vacation.
- Free lunch 2 days per week.
- Pension plan contributions.
- Subventionen für öffentliche Verkehrsmittel.
- Bike leasing program.
- Monthly social events, Thursday happy hours, sports teams.
- An awesome office in Friedrichshain, Berlin.
This text has been machine translated. Show original
Topics You Will Work On
Job Locations
About Your Employer
KAYAK
KAYAK is a renowned metasearch engine for travel services and is part of Booking Holdings. The company processes billions of search queries and provides travelers with a wide range of offers from various sources. With a presence in over 30 countries and AI-powered tools, KAYAK simplifies the search for flights, hotels, and rental cars.
Description
- Company Type
- Established Company
- Working Model
- Hybrid, Onsite
- Industry
- Internet, IT, Telecommunication