IT-Security Manager at Alterric safeguarding critical IT infrastructures for the energy transition. Responsibilities include risk management and development of security architectures in hybrid settings.
Responsibilities
IT security responsibility
Protection of IT infrastructure, particularly cloud, network and critical production systems
Ensuring endpoint, application and identity security (IAM, MFA, Conditional Access)
Implementation of zero-trust architectures and network segmentation
Compliance with standards such as ISO 27001 and legal requirements (KRITIS, NIS2)
Development and implementation of holistic technical security concepts and policies
Conducting security architecture reviews for new projects and technologies
Introduction and maintenance of KPIs to measure the security posture
Proactive identification, assessment and treatment of IT security risks
Management of incident and problem handling, including coordination of the external SOC
Planning and testing of disaster recovery plans, including alignment with business continuity management
Supporting internal departments on security issues related to cloud, IoT and new software solutions
Integration of Security by Design into projects
Organizing and tracking actions arising from ISO 27001 audits
Conducting gap analyses and deriving improvement measures
Requirements
Degree in IT, IT security or comparable qualification — alternatively several years of relevant professional experience with appropriate further training
Several years of experience in technical IT security, ideally in the energy sector, critical infrastructures or other regulated industries
Solid expertise in network security, cloud security (Microsoft Azure), zero-trust architectures and modern security solutions
Experience with sovereign cloud solutions, data sovereignty and data residency
Practical experience in Identity & Access Management (IAM, MFA, Conditional Access) and experience with SIEM/SOC environments
Knowledge of current standards and methods (ISO 27001, BSI IT-Grundschutz, NIS2, KRITIS) — certifications such as CISSP or Microsoft Security are an advantage
Analytical and conceptual thinking, solution-oriented and structured way of working
Strong communication skills and enjoyment of interdisciplinary collaboration
Very good German and English skills
Driver's license and mobility required
Benefits
30 vacation days per year (plus December 24 and 31 off)
Overtime tracking that can be converted into flex-time days
Individual development opportunities and training offers
High level of development and support opportunities
Monthly benefits budget of €50, flexibly usable for sports, shopping or mobility
Option to use the company health insurance BKK EWE
Company pension scheme with gross salary conversion including 20% employer contribution
Various leave options using time-value accounts (e.g. sabbatical, part-time)
Collegial first-name culture and diversity
Employee discounts via the Corporate Benefits platform
Professional focused on Cloud Security solutions and DevSecOps at innovative tech consulting firm Leega. Implementing security for AWS services and integrating security analysis tools.
Technicien d'installation de dispositifs antichute supervisant l'installation et la sécurité. Participer aux visites de chantier, préparer et gérer l'installation avec une autre personne.
IT Specialist ensuring smooth IT operations in a growing beauty company. Collaborate with external service providers and support internal teams with compliance and documentation.
Strategic leader focused on Cyber Security and Fraud analytics at Sun Life. Establishing centralized functions and driving proactive detection and response efforts.
Manager Infrastructure & Security driving IT infrastructure and security landscape for semiconductor firm. Collaborating with teams to build scalable systems and innovative security strategies.
Residential Security Agent managing physical security for clients in California and Nevada, ensuring compliance with safety protocols and quick response to emergencies.
Senior Cyber Security Consultant at HvS - Consulting focusing on ISMS development and team leadership. Engaging clients in ISO 27001 compliance and strategic cybersecurity improvements.