Job Closed
This listing is no longer active.
A full-service vendor & affiliate platform with one of the world’s largest affiliate marketplaces. #MoreSalesLessWork
IT Security Engineer
Location
Germany
Posted
82 days ago
Salary
0
Seniority
Mid Level
Job Description
IT Security Engineer
Digistore24 USA
Role Description Do you have IT support experience and enjoy assisting our team with their daily tasks in both German and English? Then this could be your new dream job! - Protect our systems and cloud environments: - You continuously analyze security risks, implement modern security standards, and ensure the protection of our cloud infrastructure and critical business systems. - Establish clear security policies and processes: - You further develop our security policies, standardize security processes, and ensure their adoption across the entire organization. - Drive security awareness and training initiatives: - You strengthen security awareness throughout the company through training sessions, workshops, and proactive communication with all teams. - Ensure structured incident and risk management: - You identify security incidents at an early stage, coordinate their handling, prepare analyses, and continuously improve our incident response procedures. - Ensure compliance with standards and regulations (PCI, ISO, NIS2): - You support the company in meeting external compliance requirements, prepare audits, and guide business units through compliance processes. - Monitor our core security mechanisms: - You analyze security-critical components, support monitoring and audit processes, and ensure transparency regarding security-relevant events. - Collaborate closely with Product, IT, and Engineering teams: - You support other teams in designing secure solutions, reducing risks, simplifying security processes, and contributing to a secure, scalable overall architecture. - Ensure a secure software development lifecycle: - You expand our secure development lifecycle (SSDLC), support teams on security-related topics, and ensure that security reviews are a reliable part of our processes. Qualifications - You identify security risks at an early stage and proactively think in terms of solutions. - You have a strong understanding of how software, infrastructure, and cloud systems interact. - Assessing the security of systems, services, and processes is your passion. - Nice-to-have: Experience with compliance standards such as ISO 27001, PCI DSS, or NIS2. - Nice-to-have: Experience with security testing (e.g., SAST, DAST, vulnerability scans). - Understanding of secure development and infrastructure processes (SSDLC, Cloud Security, IAM, Risk Management). - Strong analytical thinking when evaluating security incidents and vulnerabilities. - Excellent communication skills – able to explain technical risks in a clear and understandable way. - Basic knowledge of cloud environments (GCP/AWS) and automated workflows (e.g., CI/CD). - Nice-to-have: Experience with security tools and standards such as SIEM, SSO/MFA, audits, and policies. Requirements - This position is NOT for you if: - You do not enjoy identifying and minimizing security risks. - You struggle with structured analytical work and forward-thinking planning. - You are not interested in continuously learning about security topics: IT security is constantly evolving. - You do not enjoy working independently on security-critical projects. - You tend to avoid conflicts: security sometimes means addressing clear risks openly and directly. - You do not feel comfortable working in an international team. - You do not identify with our values. Benefits - Work in our partner's coworking spaces (max. 3 days a week) or in your home office, as long as you can guarantee uninterrupted internet access. - Regular further education. - The stability of an extremely successful German high-tech company that is funded by its successful product and not by investors. - Outcome focused teams and a culture of direct feedback. - Modern equipment: MacBook. - International, collaborative team with strong cohesion. - Spectacular team events in various European countries. - Autonomy from day one. - Work in your team on a first-name basis, without a dress code, and at eye level. - Flexible working hours from Mondays to Fridays.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Intermediate Information Security Officer
R&C Request GmbHR&C Request GmbH Matching people since the last decade. Now with a new vision for 2025.
• DORA implementation: You will implement the DORA requirements (Digital Operational Resilience Act) and ensure compliance across the company • Architecture governance: You will review our IT infrastructure for compliance and ensure efficient, appropriate execution of security measures • Subject-matter representation: You will represent our security concepts professionally to clients, partner banks, and supervisory authorities • Risk management: You will advise executive management on strategic IT risks and serve as a competent point of contact for all security-related questions
Senior Manager, Security GRC
AspenView Technology PartnersAspenView Technology Partners empowers organizations to thrive with agile, expert-staffed, nearshore IT teams.
Role Description The Senior Manager, Security GRC drives the enterprise security governance framework, shaping risk posture, compliance strategy, and policy architecture across global operations. Serving as the primary cyber risk advisor to the CISO and executive leadership, you will translate regulatory requirements and board-level risk appetite into actionable, enterprise-wide programs. - Strategy & Governance Management: - Own the enterprise GRC strategy and program roadmap aligned to business objectives and risk appetite. - Establish and enforce security policies, standards, and the exceptions management process. - Build and develop a high-performing GRC team while partnering with Legal, Internal Audit, and business unit leaders. - Risk Reporting & Compliance: - Govern regulatory compliance across NIST CSF, ISO 27001, SOX, GDPR, and CMMC, while managing audit relationships. - Lead cyber risk reporting to the CISO, Board, and executive stakeholders, and define risk quantification methods. - Supply Chain & Resilience: - Lead Cyber-Supply Chain Risk Management and third-party security assessment programs. - Oversee Business Continuity Planning integration with cybersecurity resilience and drive the Training & Awareness strategy. - Tools & Technologies: - Frameworks: Mastery of NIST CSF, NIST RMF, ISO 27001, and ISO 31000. - Regulations: Expertise in SOX ITGC, GDPR, CMMC, and cross-jurisdictional regulatory compliance. - Methodologies: Advanced understanding of third-party risk, supply chain security, and business continuity methodologies. Qualifications - 12+ years in cybersecurity with 5+ years leading enterprise GRC programs in complex, global organizations. - CISSP or CISM is required; CRISC or CGEIT is highly preferred. - Exceptional skills with a proven ability to translate complex cyber risk into board-level narratives. - Demonstrated ability to build and lead high-performing teams in a transformation or build-out context. Equal Opportunity Employer AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact. Visa Sponsorship Disclaimer USA AspenView does not provide visa sponsorship for this role. Candidates must already be legally authorized to work in their country of residence.
Security Engineer, Vulnerability & Attack Surface Management
AspenView Technology PartnersAspenView Technology Partners empowers organizations to thrive with agile, expert-staffed, nearshore IT teams.
Role Description The Security Engineer, Vulnerability & Attack Surface Management operates across the full vulnerability lifecycle. You will act as the technical engine of the VM program, transforming it from a reactive process into a proactive, intelligence-driven capability. By embedding AI across scanning, triage, and remediation, you will ensure high-risk vulnerabilities are addressed before exploitation across IT, cloud, and OT-adjacent environments. What you will do: - AI-Driven Scanning & Prioritization - Design and operate AI-augmented vulnerability scanning pipelines across IT, cloud, and hybrid environments. - Deploy and tune AI-driven prioritization models combining CVSS, EPSS, CISA KEV, threat intelligence, and asset criticality. - Correlate vulnerability data with live threat intelligence and active exploit activity to keep prioritization models current and accurate. - Automated Remediation & Workflows - Build and maintain automated remediation workflows, including AI-generated ticket creation and resolution tracking through ITSM platforms. - Monitor SLA compliance across workflows using automated alerting and predictive SLA breach detection. - Produce AI-generated operational dashboards and executive reporting to translate raw vulnerability data into clear risk narratives. - Attack Surface & Asset Management - Maintain asset inventory accuracy and CMDB integrations, using AI-assisted asset discovery to identify shadow IT and coverage gaps. - Contribute to attack surface management using AI-powered exposure analysis to map external trends and model risk reduction scenarios. - Support exception documentation and compensating control tracking through structured, audit-ready workflows. Tools & Technologies: - Scanning Platforms: Tenable Nessus, Qualys VMDR, Rapid7 InsightVM, or Microsoft Defender Vulnerability Management. - Risk Scoring: CVSS v3/v4, EPSS, CISA KEV, and asset-criticality-based prioritization frameworks. - ASM Platforms: Cortex Xpanse, Microsoft Defender EASM, or Axonius. - Scripting & ITSM: ServiceNow, Jira, Python, and PowerShell. Qualifications - Experience: 4-6+ years in cybersecurity with a primary focus on vulnerability management, attack surface management, or security operations. - Certification: Security+ or GEVA preferred; vendor certifications (Tenable, Qualys) or AI/ML security coursework are a strong plus. - Communication: Strong analytical skills with the ability to translate AI-generated vulnerability insights into risk narratives for technical teams and executive stakeholders. - Collaboration: Effective at driving remediation velocity across IT, cloud, and application teams using data to influence prioritization. Equal Opportunity Employer AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact. Visa Sponsorship Disclaimer USA AspenView does not provide visa sponsorship for this role. Candidates must already be legally authorized to work in their country of residence.
• **Secure Remote Access Platform: **Identity-bound, MFA-protected access anchored at the OT DMZ / Purdue Level 3, with session brokering, just-in-time privilege, and policy enforcement designed for industrial environments. • **Protocol-Aware Policy Authoring: **A Protocol Registry that maps OT protocol names (Modbus TCP, DNP3, IEC 61850, OPC-UA, EtherNet/IP) to port and transport defaults, making policy authoring OT-aware without changing the underlying enforcement model. • **Evidence and Audit Baseline: **Structured access logs capturing user identity, target, session start/end, and outcome - forwardable to Splunk, Kinesis, Datadog etc. supporting NERC CIP, IEC 62443, NIST SP 800-82, and CMMC audit requirements. • **Session Governance: **Enforced session recording, keystroke logging, step-up authentication, and dual-authorization approval workflows for regulated and defense environments. • **Asset Context Ingestion (Phase 2+): **API-based integration with OT visibility platforms (Dragos, Nozomi, Claroty) normalized into policy-ready attributes, without blocking access in the critical path. • **Design and implement **backend services across AppGate's distributed architecture — Controller, Gateway, and Connector components — with a focus on OT-safe deployment patterns. • **Build and maintain **REST and gRPC APIs supporting policy evaluation, access control, protocol registry management, and OT-specific system integrations. • **Apply Zero Trust principles **to remote access for industrial assets, accounting for the safety, uptime, and determinism constraints of OT environments. • **Integrate **with industrial protocols and OT asset types — PLCs, RTUs, HMIs, historians — running Modbus, DNP3, OPC-UA, Profinet, and EtherNet/IP. • **Own features end-to-end, **from architecture through production deployment in real customer environments. • **(Staff / Principal) **Define technical direction, lead architecture reviews, and support hiring as the OT engineering function scales.



