All jobs

Senior Security Engineer (m/f/d)

isaraerospace Sourced

Parsdorf, Bavaria, Germany Full-time Not specified

About the role

<p><strong>Mission Brief</strong>&nbsp;</p> <p>You are the guardian and the challenger of our security posture. At Isar Aerospace, the systems that build our rockets and the ground systems that launch them are mission critical, and protecting them takes more than good design. It takes someone who will attack their own work to be sure it holds.&nbsp;</p> <p>We are looking for a deeply hands-on Senior Security Engineer. You live in the consoles, the rule sets and the code. You own our secure access and network security controls, our endpoint and identity security stack, and our detection content, and you operate them yourself rather than directing from the sidelines. You wear two hats: the Builder who implements and runs the controls that keep us safe, and the Adversary who keeps testing whether those controls and detections actually fire.&nbsp;</p> <p>This is a senior engineering role with the spirit of an architect. You are expected to design what you operate, not just configure it: pick the pattern, write it down, and make it hold at fleet scale. A versatile engineer with real depth, comfortable switching from a firewall rule set to a detection query to a directory hardening sprint in the same week, and a technical anchor others lean on.&nbsp;</p> <p><strong>Your Role in Our Space Mission</strong>&nbsp;</p> <p>&nbsp;</p> <p><strong>SASE and Network Security</strong>&nbsp;</p> <ul> <li><strong>Own and operate our SASE platform</strong>, including revamping Internet Security policies and redefining Private Access policies.&nbsp;</li> </ul> <ul> <li><strong>Drive firewall security with the network team: </strong>own network security engineering and segmentation strategy, analyze rule sets, identify gaps, and see remediation through together with network engineering, who own the devices.&nbsp;</li> </ul> <ul> <li><strong>Coordinate firewall-adjacent controls: </strong>IPS, AV, sandboxing and DDoS protection.&nbsp;</li> </ul> <ul> <li><strong>Manage our DNS security and WAF solutions</strong>, including our edge and CDN-based protection services.&nbsp;</li> </ul> <p><strong>Security Posture and Hardening</strong>&nbsp;</p> <ul> <li><strong>Apply CIS Benchmarks </strong>to raise posture across firewalls, endpoints, our cloud identity platform and our cloud productivity suite.&nbsp;</li> </ul> <ul> <li><strong>Lead the clean-up and hardening of our on-premises and cloud identity directories </strong>together with the infrastructure team, then keep both hardened on an ongoing basis.&nbsp;</li> </ul> <ul> <li><strong>Drive our phishing-resistant MFA and privileged access programme, </strong>including just-in-time elevation and the remediation of the attack paths we find.&nbsp;</li> </ul> <ul> <li><strong>Own certificate lifecycle and PKI operations: </strong>key ceremonies, automated renewal, and input to our post-quantum migration plan.&nbsp;</li> </ul> <p><strong>Detection and Visibility</strong>&nbsp;</p> <ul> <li><strong>Manage and tune our IPS/IDS platforms; </strong>write and maintain custom IDS signatures, and operate network sensors for NTA appliances.&nbsp;</li> </ul> <ul> <li><strong>Build and maintain detections in our SIEM </strong>and apply MITRE ATT&amp;CK to detection engineering and use-case design in support of the SOC.&nbsp;</li> </ul> <ul> <li><strong>Extend visibility into OT </strong>with purpose-built OT monitoring tooling.&nbsp;</li> </ul> <ul> <li><strong>Act as an L3 incident responder </strong>for escalated security events, and turn every finding into a fix, a new detection or a hardened configuration.&nbsp;</li> </ul> <p><strong>Security Stack and Automation</strong>&nbsp;</p> <ul> <li><strong>Own our endpoint detection and response, data protection and CASB platforms</strong> as their technical owner.&nbsp;</li> </ul> <ul> <li><strong>Script and build internal tooling </strong>in PowerShell and Python, so controls and checks run themselves.&nbsp;</li> </ul> <p><strong>Design and Engineering Partnership</str

Skills

Information & Cybersecurity

Apply to Senior Security Engineer (m/f/d) at isaraerospace

Hyrovo matches you to jobs worldwide and helps you apply. Browsing, matching, and applying are free; AI-written CVs and cover letters are pay-as-you-go.

Apply now