Job
- Level
- Erfahren
- Ort
- Friedrichshafen
- Arbeitsmodell
- Hybrid, Onsite
- Job Feld
- IT, Security
- Anstellung
- Vollzeit
- Vertragsart
- Unbefristetes Dienstverhältnis
Job Zusammenfassung
In dieser Rolle konfigurierst du das SIEM-System, managst Sicherheitsvorfälle, optimierst Endpoint-Security und entwickelst Automatisierungen zur Reaktion auf Bedrohungen, während du die Einhaltung von Sicherheitsstandards sicherstellst.
Job Technologien
Deine Rolle im Team
- Build, configure and operate the SIEM system (Microsoft Sentinel or similar), including the integration of all relevant log sources (Entra ID, firewalls, servers, cloud).
- Manage and co-manage the external SOC/MDR service provider (24/7 monitoring, incident escalation, threat hunting).
- Operate and further develop endpoint security (Microsoft Defender for Endpoint, Intune compliance policies, Conditional Access).
- Plan and carry out BCM tests and restore drills (including the use of dedicated test hardware).
- Act as the point of contact for external and internal audits as well as certifications in the area of information security.
- Administer and optimise firewall rules, Secure Web Gateway, PAM (Entra PIM) and bastion access (Windows 365).
- Build SOAR playbooks to automate incident-response processes.
- Advise the development teams on secure software development, secret scanning and code signing.
- Contribute to the Security Committee (KPIs, vulnerability management, dashboards, strategic decisions).
Unsere Erwartungen an dich
Qualifikationen
- Sound knowledge of SIEM operations (ideally Microsoft Sentinel / Azure Monitor).
- Knowledge of the Microsoft 365 E5 security stack (Defender, Intune, Entra ID, Conditional Access).
- Good knowledge of network security (firewalls, VPN, segmentation).
- A structured and self-directed way of working.
- Very good German and English language skills.
- Knowledge of SOAR platforms and playbook automation.
- Certifications such as CompTIA Security+, CISSP, CEH, SC-200 or comparable.
- Knowledge of container security (Kubernetes, Docker).
Erfahrung
- At least 3-5 years of professional experience in IT security operations or a comparable role.
- Experience with Endpoint Detection & Response (EDR), vulnerability management and incident response.
- Experience with business continuity management and disaster recovery testing.
- Experience with cloud security (Azure, AWS) and CIS hardening.
- Experience in regulated environments (financial sector, ISO 27001).
Unser Angebot
- Flexible working hours (flexitime and no core working hours).
- A great working atmosphere and a motivated team.
- Home-office options to help you balance work and family life.
- The opportunity to work from abroad temporarily through our worldwide workation program.
- A personal mentor and individual development opportunities, such as training courses, specialist seminars and trade fairs.
- Modern workplaces with attractive benefits, including team events, free drinks, fresh fruit, an ice cream freezer in summer and much more.
- 30 days of annual leave based on a five-day working week, allowing you to recharge.
- Employee discounts through the corporate benefits portal.
- Company pension scheme.
- Company health insurance and access to a company doctor.
- Sports program through EGYM Wellpass and a company bike through bike leasing.
- A permanent employment contract.
Benefits
Work-Life-Integration
Gesundheit, Fitness & Fun
Themen mit denen du dich im Job beschäftigst
Job Standorte
Das ist dein Arbeitgeber
ACTICO GmbH
ACTICO ist ein international führender Anbieter von Software für die intelligente Automatisierung und digitale Entscheidungsfindung. Das Unternehmen bietet erstklassige Software und Tools, die in verschiedenen Branchen eingesetzt werden und die die täglichen Entscheidungen und die End-to-End-Automatisierung verbessern.
Description
- Unternehmenstyp
- Etablierte Firma
- Arbeitsmodell
- Hybrid, Onsite
- Branche
- Elektronik, Automatisation, Internet, IT, Telekom