Job Closed
This listing is no longer active.
R&C Request GmbH Matching people since the last decade. Now with a new vision for 2025.
Intermediate Information Security Officer
Location
Germany
Posted
82 days ago
Salary
€50K - €70K / year
Seniority
Senior
Job Description
Intermediate Information Security Officer
R&C Request GmbH
• DORA implementation: You will implement the DORA requirements (Digital Operational Resilience Act) and ensure compliance across the company • Architecture governance: You will review our IT infrastructure for compliance and ensure efficient, appropriate execution of security measures • Subject-matter representation: You will represent our security concepts professionally to clients, partner banks, and supervisory authorities • Risk management: You will advise executive management on strategic IT risks and serve as a competent point of contact for all security-related questions
Job Requirements
- Degree or training in IT (e.g., system architecture) with a focus on information security or IT compliance
- Initial solid experience with frameworks such as ISO 27001 or DORA
- Ability to translate regulatory texts into technical processes
- You work independently, think solution-oriented, and appear confident in negotiations with external stakeholders
- Fluent German and English
Benefits
- Starting salary up to €50,000–€60,000 gross
- Planned salary increase after a 6-month probationary period
- Participation via virtual shares (VSOP)
- High flexibility and full remote option
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Manager, Security GRC
AspenView Technology PartnersAspenView Technology Partners empowers organizations to thrive with agile, expert-staffed, nearshore IT teams.
Role Description The Senior Manager, Security GRC drives the enterprise security governance framework, shaping risk posture, compliance strategy, and policy architecture across global operations. Serving as the primary cyber risk advisor to the CISO and executive leadership, you will translate regulatory requirements and board-level risk appetite into actionable, enterprise-wide programs. - Strategy & Governance Management: - Own the enterprise GRC strategy and program roadmap aligned to business objectives and risk appetite. - Establish and enforce security policies, standards, and the exceptions management process. - Build and develop a high-performing GRC team while partnering with Legal, Internal Audit, and business unit leaders. - Risk Reporting & Compliance: - Govern regulatory compliance across NIST CSF, ISO 27001, SOX, GDPR, and CMMC, while managing audit relationships. - Lead cyber risk reporting to the CISO, Board, and executive stakeholders, and define risk quantification methods. - Supply Chain & Resilience: - Lead Cyber-Supply Chain Risk Management and third-party security assessment programs. - Oversee Business Continuity Planning integration with cybersecurity resilience and drive the Training & Awareness strategy. - Tools & Technologies: - Frameworks: Mastery of NIST CSF, NIST RMF, ISO 27001, and ISO 31000. - Regulations: Expertise in SOX ITGC, GDPR, CMMC, and cross-jurisdictional regulatory compliance. - Methodologies: Advanced understanding of third-party risk, supply chain security, and business continuity methodologies. Qualifications - 12+ years in cybersecurity with 5+ years leading enterprise GRC programs in complex, global organizations. - CISSP or CISM is required; CRISC or CGEIT is highly preferred. - Exceptional skills with a proven ability to translate complex cyber risk into board-level narratives. - Demonstrated ability to build and lead high-performing teams in a transformation or build-out context. Equal Opportunity Employer AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact. Visa Sponsorship Disclaimer USA AspenView does not provide visa sponsorship for this role. Candidates must already be legally authorized to work in their country of residence.
Security Engineer, Vulnerability & Attack Surface Management
AspenView Technology PartnersAspenView Technology Partners empowers organizations to thrive with agile, expert-staffed, nearshore IT teams.
Role Description The Security Engineer, Vulnerability & Attack Surface Management operates across the full vulnerability lifecycle. You will act as the technical engine of the VM program, transforming it from a reactive process into a proactive, intelligence-driven capability. By embedding AI across scanning, triage, and remediation, you will ensure high-risk vulnerabilities are addressed before exploitation across IT, cloud, and OT-adjacent environments. What you will do: - AI-Driven Scanning & Prioritization - Design and operate AI-augmented vulnerability scanning pipelines across IT, cloud, and hybrid environments. - Deploy and tune AI-driven prioritization models combining CVSS, EPSS, CISA KEV, threat intelligence, and asset criticality. - Correlate vulnerability data with live threat intelligence and active exploit activity to keep prioritization models current and accurate. - Automated Remediation & Workflows - Build and maintain automated remediation workflows, including AI-generated ticket creation and resolution tracking through ITSM platforms. - Monitor SLA compliance across workflows using automated alerting and predictive SLA breach detection. - Produce AI-generated operational dashboards and executive reporting to translate raw vulnerability data into clear risk narratives. - Attack Surface & Asset Management - Maintain asset inventory accuracy and CMDB integrations, using AI-assisted asset discovery to identify shadow IT and coverage gaps. - Contribute to attack surface management using AI-powered exposure analysis to map external trends and model risk reduction scenarios. - Support exception documentation and compensating control tracking through structured, audit-ready workflows. Tools & Technologies: - Scanning Platforms: Tenable Nessus, Qualys VMDR, Rapid7 InsightVM, or Microsoft Defender Vulnerability Management. - Risk Scoring: CVSS v3/v4, EPSS, CISA KEV, and asset-criticality-based prioritization frameworks. - ASM Platforms: Cortex Xpanse, Microsoft Defender EASM, or Axonius. - Scripting & ITSM: ServiceNow, Jira, Python, and PowerShell. Qualifications - Experience: 4-6+ years in cybersecurity with a primary focus on vulnerability management, attack surface management, or security operations. - Certification: Security+ or GEVA preferred; vendor certifications (Tenable, Qualys) or AI/ML security coursework are a strong plus. - Communication: Strong analytical skills with the ability to translate AI-generated vulnerability insights into risk narratives for technical teams and executive stakeholders. - Collaboration: Effective at driving remediation velocity across IT, cloud, and application teams using data to influence prioritization. Equal Opportunity Employer AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact. Visa Sponsorship Disclaimer USA AspenView does not provide visa sponsorship for this role. Candidates must already be legally authorized to work in their country of residence.
• **Secure Remote Access Platform: **Identity-bound, MFA-protected access anchored at the OT DMZ / Purdue Level 3, with session brokering, just-in-time privilege, and policy enforcement designed for industrial environments. • **Protocol-Aware Policy Authoring: **A Protocol Registry that maps OT protocol names (Modbus TCP, DNP3, IEC 61850, OPC-UA, EtherNet/IP) to port and transport defaults, making policy authoring OT-aware without changing the underlying enforcement model. • **Evidence and Audit Baseline: **Structured access logs capturing user identity, target, session start/end, and outcome - forwardable to Splunk, Kinesis, Datadog etc. supporting NERC CIP, IEC 62443, NIST SP 800-82, and CMMC audit requirements. • **Session Governance: **Enforced session recording, keystroke logging, step-up authentication, and dual-authorization approval workflows for regulated and defense environments. • **Asset Context Ingestion (Phase 2+): **API-based integration with OT visibility platforms (Dragos, Nozomi, Claroty) normalized into policy-ready attributes, without blocking access in the critical path. • **Design and implement **backend services across AppGate's distributed architecture — Controller, Gateway, and Connector components — with a focus on OT-safe deployment patterns. • **Build and maintain **REST and gRPC APIs supporting policy evaluation, access control, protocol registry management, and OT-specific system integrations. • **Apply Zero Trust principles **to remote access for industrial assets, accounting for the safety, uptime, and determinism constraints of OT environments. • **Integrate **with industrial protocols and OT asset types — PLCs, RTUs, HMIs, historians — running Modbus, DNP3, OPC-UA, Profinet, and EtherNet/IP. • **Own features end-to-end, **from architecture through production deployment in real customer environments. • **(Staff / Principal) **Define technical direction, lead architecture reviews, and support hiring as the OT engineering function scales.
Lead / Staff Embedded Cybersecurity Engineer
Advanced Micro Devices, IncAMD does not accept unsolicited resumes from headhunters, recruitment agencies, or fee-based recruitment services. AMD and its subsidiaries are equal opportunity, inclusive employers and will consider all applicants without regard to age, ancestry, color, marital status, medical condition, mental or physical disability, national origin, race, religion, political and/or third-party affiliation, sex, pregnancy, sexual orientation, gender identity, military or veteran status, or any other characteristic protected by law. We encourage applications from all qualified candidates and will accommodate applicants’ needs under the respective laws throughout all stages of the recruitment and selection process. AMD may use Artificial Intelligence to help screen, assess or select applicants for this position. AMD’s “Responsible AI Policy” is available here. This posting is for an existing vacancy.
Role Description AMD is looking for an influential software engineer who is passionate about improving the performance of key applications and benchmarks. You will be a member of a core team of incredibly talented industry specialists and will work with the very latest hardware and software technology. Key Responsibilities - Develop and drive execution of comprehensive, highly effective security software for sophisticated new technology and new product introduction projects (FPGA/SoC, embedded x86). - Engage in deep technical discussions to define security requirements for next generation products. - Participate in resolution of critical customer support cases. - Review security architectures in support of customer-driven use cases. - Collaborate closely with engineering teams to manage requirements throughout the product lifecycle (architecture, design, test, etc.) using requirement management software and tools. - Participate in the validation of new SW security features before releasing them to customers. - Collaborate closely with multiple teams to deliver key planning solutions and the technology to support them. - Help contribute to the design and implementation of future architecture for a highly scalable, durable, and innovative system. - Work very closely with dev teams and Project Managers to drive results. Support Secure Development Lifecycle activities including Threat Modeling, Penetration Testing, Red Teaming, Code Reviews, etc. - Help contribute to the design and implementation of future architecture for implementing security features such as secure boot, state of the art cryptographic algorithms, and access control policies. Qualifications - Familiarity with potential threats, vulnerabilities, and attack vectors targeting SoC and embedded x86 designs. - Security expertise in the following industries: Aerospace & Defense, Automotive, Datacenter, Test & Measurement. - Knowledge in security concepts & cryptographic algorithms in microelectronics. - Experience with the application of security into products and systems. - Experience with security certifications (e.g. Common Criteria and/or FIPS). - Experience in FPGA or embedded x86 design. - Experience in use of simulation and verification techniques. - Experience in Verilog, VHDL, Python, PERL, C, or other programming languages. - Hands-on experience with lab equipment in a testing environment. - Hands-on experience with HW (FPGA/SoC/embedded x86). - Knowledge of ARM-based Embedded Systems. - Knowledge of other Embedded OS such as RTOS. - Knowledge of Embedded Hypervisors. - Knowledge of Trusted Execution Environment. - Knowledge of ARM Trustzone Technology. Academic Credentials - Bachelor’s, Master’s degree or PhD in Computer Science, Computer Engineering, Electrical Engineering, or equivalent. Location - Germany (Remote) Benefits - AMD benefits at a glance.


