IT-Security Manager at Alterric responsible for safeguarding digital infrastructures in energy sector. Protecting IT systems and ensuring compliance with security standards and regulations.
Responsibilities
Overall responsibility for IT security
Protection of IT infrastructure, with emphasis on cloud, network and critical production systems
Ensuring endpoint, application and identity security (IAM, MFA, Conditional Access)
Implementation of Zero-Trust architectures and network segmentation
Compliance with standards and legal requirements such as ISO 27001, KRITIS and NIS2
Development and implementation of comprehensive technical security concepts and policies
Conducting security architecture reviews for new projects and technologies
Introducing and maintaining KPIs to measure the security posture
Proactive identification, assessment and remediation of IT security risks
Continuous monitoring and response to security incidents
Supporting internal departments on security matters related to cloud, IoT and new software solutions
Requirements
Degree in IT, IT security or a comparable qualification — alternatively several years of relevant professional experience with appropriate further training
Several years of experience in technical IT security, ideally in the energy sector, critical infrastructures or other regulated industries
Solid expertise in network security, cloud security (Microsoft Azure), Zero-Trust architectures and modern security solutions
Experience with sovereign cloud solutions, data sovereignty and data residency
Practical experience in Identity & Access Management (IAM, MFA, Conditional Access) and working with SIEM/SOC environments
Knowledge of current standards and frameworks (ISO 27001, BSI IT-Grundschutz, NIS2, KRITIS) — certifications such as CISSP or Microsoft Security are an advantage
Analytical and conceptual thinking, solution-oriented and structured way of working
Strong communication skills and enjoyment of interdisciplinary collaboration
Very good German and English language skills
Driver’s license and mobility required
Benefits
30 vacation days per year (additionally December 24 and 31 off)
Overtime tracking that can be converted into flex/compensatory time off
Individual development opportunities and training programs
Collegial, informal first-name culture and diversity
Employee discounts via the Corporate Benefits platform
Monthly benefits budget of €50, flexible for sports, shopping or mobility
Option to use the company health insurance fund BKK EWE
Company pension plan with gross salary conversion including 20% employer contribution
Various leave options through time-value accounts (e.g., sabbatical, part-time)
Significant opportunities to contribute and a culture that welcomes employee ideas
Cloud & AI Security Engineer designing secure cloud infrastructures and AI/LLM services at Assurity Trusted Solutions. Engineers with solid cloud fundamentals are encouraged to apply.
OT Cybersecurity Engineer deploying and managing security solutions for operational technology environments at Solventum. Collaborates with teams to improve security posture and provide user support.
Principal Cybersecurity role at AT&T focusing on cloud security feature design and implementation. Leading innovative security solutions in conjunction with modern cloud technologies and Agile methodologies.
Cloud Security Vulnerability Management Program Specialist ensuring secure configurations of cloud workloads. Focused on vulnerability management, monitoring, and risk remediation across environments at Bank of America.
Security Architect delivering secure solutions for Defence and National Security at SiXworks. Supporting agile teams in technical projects like Kubernetes and security risk management.
CIS Security Manager responsible for EID’s information security strategy and compliance. Ensuring protection of information assets and promoting security culture across the organization.
Cyber Security Subject Matter Expert at CACI supporting a new DoD contract. Working on cloud security with an emphasis on system security engineering and risk management.
Cybersecurity Engineer developing solutions for complex security challenges protecting data and networks. Implementing next generation security solutions for government and commercial clients in hands - on roles.
Information Security Manager responsible for security governance and risk management. Engaging with technical teams for compliance with security standards and best practices.