Cybersecurity Engineer (m/f/d)
isaraerospace · Parsdorf, Bavaria
<p><strong>Mission Brief </strong></p>
<p><span data-contrast="auto">You are a technical guardian of our digital environment. At Isar Aerospace, the systems, data and people that build our rockets are mission critical and protecting them takes someone who builds controls and then proves they hold.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></p>
<p><span data-contrast="auto">We are looking for a hands-on Security Engineer who bridges the gap between Security Architecture and Operations. You are not just a consultant; you are a builder and an auditor. You wear two hats: the Engineer who designs and implements security controls, and the Technical Auditor who verifies that systems and operations meet the high standards required for a space company. You will act as the technical conscience of our environment, working across domains such as endpoints, identity, cloud, networks and applications.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></p>
<p>Your Role in Our Space Mission: </p>
<ul>
<li><strong><span data-contrast="auto">Engineer security controls: </span></strong><span data-contrast="auto">design, implement and maintain security controls across our technology stack, defining the exact configurations and policies required to protect our systems, applications and data.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Act as the technical auditor: </span></strong><span data-contrast="auto">you don’t just trust; you verify. Check the configurations of IT and engineering teams against security baselines and provide guidance to close gaps.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Protect identity and access: </span></strong><span data-contrast="auto">help safeguard the keys to the kingdom through strong authentication, least privilege and privileged access controls across the environment.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Detect and respond: </span></strong><span data-contrast="auto">use security monitoring and telemetry to separate signal from noise. When an alert fires, investigate the root cause and coordinate remediation.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Define the hardening standard: </span></strong><span data-contrast="auto">develop and maintain secure configuration baselines and engineering standards for the systems in your scope. You define what “secure” looks like.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Automate the defence: </span></strong><span data-contrast="auto">use scripting to automate security checks, streamline incident response and integrate disparate security tools.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Collaborate and document: </span></strong><span data-contrast="auto">produce clear technical documentation and translate complex security requirements into runbooks that IT and engineering teams can execute.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
</ul>
<p><strong>Qualification Checklist </strong></p>
<ul>
<li><strong><span data-contrast="auto">Education: </span></strong><span data-contrast="auto">Bachelor’s or Master’s degree in Computer Science, Information Security or a related field, or the equivalent through relevant certifications and hands-on experience.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Experience: </span></strong><span data-contrast="auto">3–5+ years in Information Security or Security Engineering, with hands-on ownership of security controls in a production environment.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Hands-on Engineering: </span></strong><span data-contrast="auto">deep experience implementing security controls in at least one domain such as endpoint, identity, cloud, network or application security. You configure controls yourself, not just review them.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Broad Security Fluency: </span></strong><span data-contrast="auto">solid understanding of core security domains and how they interact to defend an enterprise environment.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Technical Audit Mindset: </span></strong><span data-contrast="auto">you can “check the homework” of other teams and know exactly where to look to verify whether a system is truly compliant with CIS Benchmarks or internal standards.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Detection and Response: </span></strong><span data-contrast="auto">proficiency in log analysis and security telemetry, able to troubleshoot an incident across network, endpoint, application and cloud logs to find the smoking gun.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Scripting: </span></strong><span data-contrast="auto">basic to intermediate scripting skills (e.g., PowerShell, Python) to automate administrative tasks and security validations.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Soft Skills: </span></strong><span data-contrast="auto">clear communicator who translates technical risk for different audiences, works controls through other teams and takes ownership of their work.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><strong><span data-contrast="auto">Languages: </span></strong><span data-contrast="auto">fluent English; German is a plus.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
</ul>
<p>Bonus Skills</p>
<ul>
<li><span data-contrast="auto">Specialist depth in one or more areas such as cloud security, endpoint and identity (e.g., Microsoft ecosystem), network security (e.g., SASE, segmentation) or application security.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
<li><span data-contrast="auto">Relevant certifications (e.g., OSCP, GIAC, CISSP, SC-200, AZ-500) and experience applying frameworks such as CIS Benchmarks, NIST or ISO 27001.</span><span data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></li>
</ul>
<p><strong><span lang="EN-US">Benefits </span></strong></p>
<ul>
<li><span lang="EN-US"><strong>Employee Participation Program:</strong> Share in our success through our virtual company share program</span></li>
<li><span lang="EN-US"><strong>30 days of vacation: </strong>Enjoy the days off to relax and recharge </span></li>
<li><span lang="EN-US"><strong>Company pension plan:</strong> Secure your future with our company pension plan, featuring a 20% employer contribution after the probation period</span></li>
<li><span lang="EN-US"><stronView application details