CyberSecurity Engineer (m/f/d)
Must-have:KubernetesMicroservicesSecurity
Machine translation — original language: German.Show original
TASKS
- Responsibility for the planning, implementation, and maintenance of security measures in IT systems and networks
- Assessment of relevant security vulnerabilities, development of corresponding solutions and policies, as well as intervention in the event of a security incident
- Responsibility and implementation of end-to-end application security throughout the entire value creation process for the initial creation, delivery, and maintenance of our software products, using our security platform and tools and complying with current security standards
- Training, further education, and support of "Security Champions" in software development according to OWASP SAMM
- Participation in the creation of concepts, offers, policies, risk analyses, processes, templates, and guidelines from a technological and security-relevant perspective
- Advising and supporting our colleagues from all business areas in the implementation of technical and organizational measures for CyberSecurity in accordance with applicable legal requirements from ISO/IEC 27001, NIS2, CRA, etc.
- Exchange and further development regarding CyberSecurity with specialist colleagues in local and international environments
PROFILE
- You have a completed degree in Cyber-/ IT-Security or have comparable qualifications or experience
- You already have at least 5 years of experience in the field of CyberSecurity
- BSI Standards and BSI IT-Grundschutz are the basis of your actions; the BSI IT-Grundschutz-Kompendium with its modules is the bible according to which you align your daily work
- SAST, SCA, IAST are not cryptic names for objects in the starry sky to you, but are skills and processes lived and applied daily in practice
- You are well-acquainted with security tools such as Falcon or similar, ideally with Arnica and Sysdig, and have already used them fully in practice
- Kubernetes and CI-/CD-Pipelines are familiar environments and facilities to you
- You have several years of experience in the field of application development and are well-versed in a microservice architecture
- You have sound knowledge of legal requirements and regulations from ISO/IEC 27000 / BSI §8a, NIS2, CRA, BSI, B3S, etc.
- You have already gained experience in advising and implementing technical and organizational security measures
- You are ideally characterized by your know-how in security processes, SOC concepts, and the securing of OT-/IoT-systems
- You have strong communication skills and a confident appearance towards management and specialist departments and are proficient in English, both written and spoken
BENEFITS
- A strong sense of teamwork and pronounced cohesion – confirmed by the latest employee survey. Teamwork is our focus.
- Take advantage of our hybrid and flexible working arrangements, which allow for both on-site and mobile work depending on the activity
- SWARCO offers a secure job in a stable industry within an international group
- Benefit from tailor-made further training opportunities (internal and external in seminars or via learning platforms)
- Use 30 days of vacation as well as special leave, e.g., for marriage
- €50 tax-free every month – save on refueling, shopping, or eating with the SWARCO Card
- We offer a 40% subsidy for company pension schemes, far more than the legal subsidy, as well as capital-forming benefits
- Your health is important to us: Benefit from (e-)bike leasing and a €160/year subsidy for health prevention and fitness programs, e.g., via wellhub
- Our offer for your personal well-being includes free, unbureaucratic external advice for professional, private, or health-related questions
#LI-AN1