Job
- Level
- Experienced
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Großburgwedel
- Working Model
- Hybrid, Onsite
Job Summary
In this role, you will shape the security of our identity infrastructure by hardening, automating, and implementing modern authentication methods while advancing privileged access management practices.
Job Technologies
Your role in the team
- Hardening and continuous securing of our identity infrastructure in Active Directory and Entra ID - among other things, by replacing legacy protocols in favor of modern methods such as OpenID Connect.
- Further development and implementation of our AD-Tiering model as well as the concepts for privileged access (Privileged Access, local administrator rights) in accordance with our Zero-Trust strategy.
- Design of the PAM and PKI landscape from a security perspective: definition of security requirements and hardening guidelines, conducting reviews, and participating in architecture and product decisions.
- Analysis and assessment of vulnerabilities and misconfigurations in the identity infrastructure, as well as tracking findings from pentests and audits.
- Identification of dependencies on legacy protocols and old systems – for example through targeted log analysis – and coordination of their decommissioning with the responsible specialist teams to ensure that hardening measures can be implemented consistently.
- Automation of security checks in the identity infrastructure, e.g., for detecting insecure configurations, critical permissions, or the use of outdated protocols.
- Observation of current attack techniques on identity systems and derivation of appropriate protection and detection measures in collaboration with our Cyber Defense Center.
This text has been machine translated. Show original
Our expectations of you
Education
- Completed degree in Computer Science / IT Security, vocational training in the IT field, or a comparable qualification.
Qualifications
- Good knowledge of Active Directory and Entra ID (structure, permission models, Conditional Access, Group Policies, hybrid identity scenarios).
- Proficient handling of authentication protocols - from Kerberos and NTLM to modern methods such as OpenID Connect (OIDC) and OAuth 2.0.
- Understanding of identity security concepts such as tiering and least privilege.
- Understanding of PKI and certificate services (e.g., AD CS) as well as privileged access management concepts and their secure integration into identity environments.
- Ideally, knowledge of common attack techniques on AD and Entra ID (e.g., Kerberoasting, Pass-the-Hash, ESC vulnerabilities) and appropriate hardening measures.
- Structured, self-reliant working style, persistence in following up on open issues, and enjoyment of cross-team collaboration.
- Very good German and good English skills, both written and spoken.
Experience
- Experience in scripting with PowerShell for analysis and automation.
This text has been machine translated. Show original
What we offer
- Flexible working hours.
- 30 days of vacation.
- Christmas and holiday bonuses.
- Comprehensive onboarding.
- Employee discount & shopping vouchers.
- Sports groups & leisure seminars.
- Subsidy for the Germany Ticket.
- Free parking.
- 50% remote work.
- Corporate Benefits.
- Employee-oriented family business.
- ROSSMANN Learning World.
- ROSSMANN onboarding days.
- Exclusive coupons.
This text has been machine translated. Show original
Benefits
Work-Life-Integration
- 🏖️Workation
- 🏠Home Office
- 🚌Excellent Traffic Connections
- 🍼Day Care for Kids
- 🅿️Employee Parking Space
- ⏰Flexible Working Hours
Health, Fitness & Fun
Food & Drink
More net
Topics that you deal with on the job
Job Locations
This is your employer
Rossmann
ROSSMANN is one of the leading drugstore companies in Europe, with 56,500 employees in 4,361 stores. It has been expanding rapidly for years and is highly successful.
Description
- Company Type
- Established Company
- Working Model
- Full Remote, Hybrid, Onsite
- Industry
- Trade