A full-service vendor & affiliate platform with one of the world’s largest affiliate marketplaces. #MoreSalesLessWork
IT Security Engineer
Location
Germany
Posted
21 days ago
Salary
0
Seniority
Mid Level
Job Description
IT Security Engineer
Digistore24 USA
Role Description Do you have IT support experience and enjoy assisting our team with their daily tasks in both German and English? Then this could be your new dream job! - Protect our systems and cloud environments: - You continuously analyze security risks, implement modern security standards, and ensure the protection of our cloud infrastructure and critical business systems. - Establish clear security policies and processes: - You further develop our security policies, standardize security processes, and ensure their adoption across the entire organization. - Drive security awareness and training initiatives: - You strengthen security awareness throughout the company through training sessions, workshops, and proactive communication with all teams. - Ensure structured incident and risk management: - You identify security incidents at an early stage, coordinate their handling, prepare analyses, and continuously improve our incident response procedures. - Ensure compliance with standards and regulations (PCI, ISO, NIS2): - You support the company in meeting external compliance requirements, prepare audits, and guide business units through compliance processes. - Monitor our core security mechanisms: - You analyze security-critical components, support monitoring and audit processes, and ensure transparency regarding security-relevant events. - Collaborate closely with Product, IT, and Engineering teams: - You support other teams in designing secure solutions, reducing risks, simplifying security processes, and contributing to a secure, scalable overall architecture. - Ensure a secure software development lifecycle: - You expand our secure development lifecycle (SSDLC), support teams on security-related topics, and ensure that security reviews are a reliable part of our processes. Qualifications - You identify security risks at an early stage and proactively think in terms of solutions. - You have a strong understanding of how software, infrastructure, and cloud systems interact. - Assessing the security of systems, services, and processes is your passion. - Nice-to-have: Experience with compliance standards such as ISO 27001, PCI DSS, or NIS2. - Nice-to-have: Experience with security testing (e.g., SAST, DAST, vulnerability scans). - Understanding of secure development and infrastructure processes (SSDLC, Cloud Security, IAM, Risk Management). - Strong analytical thinking when evaluating security incidents and vulnerabilities. - Excellent communication skills – able to explain technical risks in a clear and understandable way. - Basic knowledge of cloud environments (GCP/AWS) and automated workflows (e.g., CI/CD). - Nice-to-have: Experience with security tools and standards such as SIEM, SSO/MFA, audits, and policies. Requirements - This position is NOT for you if: - You do not enjoy identifying and minimizing security risks. - You struggle with structured analytical work and forward-thinking planning. - You are not interested in continuously learning about security topics: IT security is constantly evolving. - You do not enjoy working independently on security-critical projects. - You tend to avoid conflicts: security sometimes means addressing clear risks openly and directly. - You do not feel comfortable working in an international team. - You do not identify with our values. Benefits - Work in our partner's coworking spaces (max. 3 days a week) or in your home office, as long as you can guarantee uninterrupted internet access. - Regular further education. - The stability of an extremely successful German high-tech company that is funded by its successful product and not by investors. - Outcome focused teams and a culture of direct feedback. - Modern equipment: MacBook. - International, collaborative team with strong cohesion. - Spectacular team events in various European countries. - Autonomy from day one. - Work in your team on a first-name basis, without a dress code, and at eye level. - Flexible working hours from Mondays to Fridays.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Intermediate Information Security Officer
R&C Request GmbHR&C Request GmbH Matching people since the last decade. Now with a new vision for 2025.
• DORA implementation: You will implement the DORA requirements (Digital Operational Resilience Act) and ensure compliance across the company • Architecture governance: You will review our IT infrastructure for compliance and ensure efficient, appropriate execution of security measures • Subject-matter representation: You will represent our security concepts professionally to clients, partner banks, and supervisory authorities • Risk management: You will advise executive management on strategic IT risks and serve as a competent point of contact for all security-related questions
• **Secure Remote Access Platform: **Identity-bound, MFA-protected access anchored at the OT DMZ / Purdue Level 3, with session brokering, just-in-time privilege, and policy enforcement designed for industrial environments. • **Protocol-Aware Policy Authoring: **A Protocol Registry that maps OT protocol names (Modbus TCP, DNP3, IEC 61850, OPC-UA, EtherNet/IP) to port and transport defaults, making policy authoring OT-aware without changing the underlying enforcement model. • **Evidence and Audit Baseline: **Structured access logs capturing user identity, target, session start/end, and outcome - forwardable to Splunk, Kinesis, Datadog etc. supporting NERC CIP, IEC 62443, NIST SP 800-82, and CMMC audit requirements. • **Session Governance: **Enforced session recording, keystroke logging, step-up authentication, and dual-authorization approval workflows for regulated and defense environments. • **Asset Context Ingestion (Phase 2+): **API-based integration with OT visibility platforms (Dragos, Nozomi, Claroty) normalized into policy-ready attributes, without blocking access in the critical path. • **Design and implement **backend services across AppGate's distributed architecture — Controller, Gateway, and Connector components — with a focus on OT-safe deployment patterns. • **Build and maintain **REST and gRPC APIs supporting policy evaluation, access control, protocol registry management, and OT-specific system integrations. • **Apply Zero Trust principles **to remote access for industrial assets, accounting for the safety, uptime, and determinism constraints of OT environments. • **Integrate **with industrial protocols and OT asset types — PLCs, RTUs, HMIs, historians — running Modbus, DNP3, OPC-UA, Profinet, and EtherNet/IP. • **Own features end-to-end, **from architecture through production deployment in real customer environments. • **(Staff / Principal) **Define technical direction, lead architecture reviews, and support hiring as the OT engineering function scales.
Lead / Staff Embedded Cybersecurity Engineer
Advanced Micro Devices, IncAMD does not accept unsolicited resumes from headhunters, recruitment agencies, or fee-based recruitment services. AMD and its subsidiaries are equal opportunity, inclusive employers and will consider all applicants without regard to age, ancestry, color, marital status, medical condition, mental or physical disability, national origin, race, religion, political and/or third-party affiliation, sex, pregnancy, sexual orientation, gender identity, military or veteran status, or any other characteristic protected by law. We encourage applications from all qualified candidates and will accommodate applicants’ needs under the respective laws throughout all stages of the recruitment and selection process. AMD may use Artificial Intelligence to help screen, assess or select applicants for this position. AMD’s “Responsible AI Policy” is available here. This posting is for an existing vacancy.
Role Description AMD is looking for an influential software engineer who is passionate about improving the performance of key applications and benchmarks. You will be a member of a core team of incredibly talented industry specialists and will work with the very latest hardware and software technology. Key Responsibilities - Develop and drive execution of comprehensive, highly effective security software for sophisticated new technology and new product introduction projects (FPGA/SoC, embedded x86). - Engage in deep technical discussions to define security requirements for next generation products. - Participate in resolution of critical customer support cases. - Review security architectures in support of customer-driven use cases. - Collaborate closely with engineering teams to manage requirements throughout the product lifecycle (architecture, design, test, etc.) using requirement management software and tools. - Participate in the validation of new SW security features before releasing them to customers. - Collaborate closely with multiple teams to deliver key planning solutions and the technology to support them. - Help contribute to the design and implementation of future architecture for a highly scalable, durable, and innovative system. - Work very closely with dev teams and Project Managers to drive results. Support Secure Development Lifecycle activities including Threat Modeling, Penetration Testing, Red Teaming, Code Reviews, etc. - Help contribute to the design and implementation of future architecture for implementing security features such as secure boot, state of the art cryptographic algorithms, and access control policies. Qualifications - Familiarity with potential threats, vulnerabilities, and attack vectors targeting SoC and embedded x86 designs. - Security expertise in the following industries: Aerospace & Defense, Automotive, Datacenter, Test & Measurement. - Knowledge in security concepts & cryptographic algorithms in microelectronics. - Experience with the application of security into products and systems. - Experience with security certifications (e.g. Common Criteria and/or FIPS). - Experience in FPGA or embedded x86 design. - Experience in use of simulation and verification techniques. - Experience in Verilog, VHDL, Python, PERL, C, or other programming languages. - Hands-on experience with lab equipment in a testing environment. - Hands-on experience with HW (FPGA/SoC/embedded x86). - Knowledge of ARM-based Embedded Systems. - Knowledge of other Embedded OS such as RTOS. - Knowledge of Embedded Hypervisors. - Knowledge of Trusted Execution Environment. - Knowledge of ARM Trustzone Technology. Academic Credentials - Bachelor’s, Master’s degree or PhD in Computer Science, Computer Engineering, Electrical Engineering, or equivalent. Location - Germany (Remote) Benefits - AMD benefits at a glance.
• Application security for products and/or features supported by your assigned development teams. • Performing security testing and triaging findings identified by SAST, SCA, IAST, DAST, and penetration tests. • Leverage AI and MCP to create intelligent, context-aware security guidance and automation. • Providing remediation consulting services to assigned development teams. • Assist with vulnerability management reporting and tracking. • Coordinating third-party penetration testing engagements, analyzing reports, and opening tickets for remediation. • Contribute to the configuration and management of security tools.



