-
General Information
Location: Berlin, hybrid with 3–4 days on-site
Company Type: Corporate Group
Company size: 10,000+ employees
Contract Type: Permanent, Full-Time
Security Clearance: Extended Security Clearance (SÜ 2)
Tasks
Security Architecture: Definition and enforcement of security standards throughout the entire product development lifecycle (SecSDLC) for military and defense applications.
Threat Modeling: Leading advanced threat modeling, vulnerability assessments, and penetration tests for hardware, firmware, and software.
Compliance & Certifications: Ensuring that products comply with defense industry standards (e.g., NIST SP 800-171, CMMC, FIPS, Common Criteria).
Team Leadership: Recruiting, mentoring, and leading a high-performing team of product security engineers.
Stakeholder Management: Serves as the primary technical point of contact for defense customers, military inspectors, and government regulatory agencies regarding the safety status of products.
Qualifications
Extensive experience in product security and/or embedded security—including at least 5 years in a supervisory role.
In-depth understanding of secure coding practices, cryptography, hardware security modules (HSMs), and reverse engineering.
In-depth knowledge of security frameworks and regulatory requirements such as CRA.
Meeting the criteria for a successful SÜ2 security clearance.
-
General Information
Location: Berlin, hybrid with 2–3 days on-site
Company Type: Corporate Group
Company size: 10,000+ employees
Contract Type: Permanent, Full-Time
Security Clearance: Extended Security Clearance (SÜ 2)
Tasks
Development, maintenance, and enforcement of product safety standards within the security architecture.
Designing secure architectures that incorporate Zero Trust, IAM, and microsegmentation.
Conducting threat modeling at the architectural level as well as risk assessments.
Evaluation, pilot testing, and recommendation of security technologies and tools for integration into the enterprise stack.
Work closely with the DevOps, network engineering, and product teams to seamlessly integrate security into system designs.
Qualifications
Extensive experience in IT security, including at least 2 years with a clear focus on security architecture.
A proven track record of success in designing secure infrastructures.
Practical experience with architecture frameworks such as SABSA and TOGAF, or threat modeling methodologies such as STRIDE.
Relevant certifications such as CISSP-ISSAP, CCSP, AWS/Azure Certified Security Specialist, or comparable qualifications are a plus.
-
General Information
Location: Remote + business travel throughout Germany (approx. 1 day per week)
Type of Company: IT Security Consulting
Company size: 10–50 employees
Contract Type: Permanent, Full-Time
Tasks
You will handle consulting tasks related to the planning, implementation, and auditing of ISMS for our clients
In this role, you will evaluate and draft policy documents in accordance with applicable information security standards
You'll work closely with our clients' CISOs or take on this role yourself as an external consultant
You plan and oversee certification audits and identify actions needed to address outstanding requirements
In short: You’ll take our customers’ information security to a new level, thereby contributing directly to their protection
Qualifications
You have a good understanding of business processes, combined with an affinity for technical security
You can explain complex topics in a simple and easy-to-understand way
You already have experience with ISO 27001 and, ideally, with TISAX, KRITIS, and NIS2 as well
Ideally, you'll also have some knowledge of data protection and business continuity management
You're interested in getting up to speed on new regulations and applying that new knowledge to projects at full speed
-
General Information
Location: Munich / Remote
Company Type: Corporate Group (Bank)
Company size: 10,000+ employees
Contract Type: Freelance (Project Duration: Approximately 6 Months)
Tasks
DORA Implementation: Analysis of existing gaps (gap analysis) and operational implementation of the DORA pillars (specifically, ICT risk management, incident reporting, assessment of digital operational resilience, and management of third-party ICT risk).
ISMS Expansion: Further development, optimization, and documentation of the existing Information Security Management System (ISMS) in accordance with ISO/IEC 27001 and banking-specific requirements (BAIT / MaRisk).
BCM Integration: Close integration of ICT risk management with Business Continuity Management (BCM). Development and updating of emergency plans and business impact analyses (BIA), and conducting crisis management team drills.
Qualifications
In-depth understanding of regulatory requirements in the banking sector (BAIT, MaRisk, EBA Guidelines) as well as solid, practical knowledge of the DORA framework.
Proven, long-term project experience in the areas of information security, IT risk management, or IT compliance
Extensive experience in establishing and auditing ISMS (in accordance with ISO 27001 or IT-Grundschutz), as well as in-depth knowledge of BCM (e.g., in accordance with ISO 22301 or BSI 200-4).
Proficiency in spoken and written German and English at a business level.