About this job
IT Security Engineer (m/f/d) – Enterprise Security and Threat Defense
For one of our clients, Expert Select GmbH is looking for an experienced IT Security Engineer (m/f/d) to protect complex, business-critical IT environments.
This is not a general IT support role, not a junior position and not a compliance-only function. The focus is on hands-on security engineering, threat detection, vulnerability management, incident response and the continuous hardening of productive enterprise systems.
As an IT Security Engineer, you will work closely with infrastructure, network, cloud, endpoint, DevOps and operations teams. You will identify risks, implement technical controls and help ensure that security measures work under real operational conditions.
Your responsibilities
- Design, implement and improve security measures across network, server, endpoint, identity and cloud environments
- Analyze IT infrastructures for vulnerabilities, misconfigurations, attack paths and operational risks
- Operate, tune and improve security monitoring, including SIEM, log analysis and SOC-related workflows
- Investigate suspicious activity, anomalies and possible indicators of compromise
- Support incident response, including containment, root cause analysis, remediation and post-incident hardening
- Perform or coordinate vulnerability assessments, security reviews and penetration testing activities
- Prioritize vulnerabilities based on exploitability, exposure, business impact and operational criticality
- Develop secure configurations, hardening standards and baseline security controls
- Work on IAM, privileged access, MFA, role-based access and secure authentication concepts
- Secure cloud environments, hybrid infrastructures, endpoints, network segments and critical services
- Integrate security requirements into infrastructure, cloud, DevOps and IT projects
- Document risks, decisions, mitigations, dependencies and security standards in a structured way
- Translate technical findings into clear recommendations for engineering teams and management
Your profile
The requirements for this role are intentionally high. We are looking for a security professional who can take ownership, make sound technical decisions and contribute directly to the protection of productive systems.
You should bring:
- Several years of experience as an IT Security Engineer, Cyber Security Engineer, Security Architect, Security Analyst, Security Consultant or System Engineer with a strong security focus
- Proven hands-on experience in securing productive enterprise environments
- Strong knowledge of network security, firewalls, segmentation, VPN, IDS/IPS, proxy technologies and secure network architectures
- Experience with endpoint protection, EDR/XDR, hardening, malware protection and detection concepts
- Practical experience with SIEM systems, log analysis, alert triage, security monitoring or SOC-related processes
- Strong understanding of modern attack techniques, privilege escalation, lateral movement, persistence mechanisms and common attacker behavior
- Experience in vulnerability management, including scanning, validation, prioritization, remediation tracking and risk-based reporting
- Knowledge of incident response methodology, containment strategies, forensic basics and post-incident improvement
- Strong understanding of Windows and Linux security in enterprise environments
- Experience with IAM, MFA, privileged access management and secure authentication
- Good understanding of cloud security in AWS, Microsoft Azure or Google Cloud
- Ability to assess risks across infrastructure, cloud, network, endpoint and application-related contexts
- Strong documentation skills and clear technical communication
- Very good German language skills, both written and spoken
- Good English skills for technical documentation, vendor communication and international security sources
A degree in computer science, IT security, information systems or a comparable technical field is an advantage. Practical security engineering experience is essential.
Strongly preferred experience
- Enterprise SIEM platforms, EDR/XDR tools, vulnerability scanners, IDS/IPS systems or cloud-native security tools
- Microsoft Defender, Sentinel, Splunk, QRadar, CrowdStrike, Tenable, Qualys, Rapid7, Palo Alto, Fortinet, Check Point or comparable technologies
- Security architecture, secure-by-design principles and technical security governance
- Zero Trust, network segmentation, conditional access and privileged access models
- Cloud security posture management, workload protection, identity security and secure landing zones
- DevSecOps, CI/CD security, secrets management, container security or Kubernetes security
- ISO 27001, BSI IT-Grundschutz, NIST, CIS Controls, GDPR or comparable frameworks
- Scripting or automation with Python, PowerShell, Bash or similar tools
- Certifications such as CISSP, CISM, CompTIA Security+, SSCP, CEH, OSCP, Microsoft Security or AWS Security
Incase you would like to apply to this job directly from the source, please click here