Your mission
As IT Security Engineer (m/f/d), you will safeguard our IT infrastructure, digital assets, and products while reporting regularly to the C-level on strategic progress. In this critical role, you will professionalize and scale our security foundations to meet NIS2 and high-growth requirements. You will act as a specialized consultant to our R&D/Engineering teams and maintain a proactive, hands-on approach to securing our IT operations, working in close synergy with the broader IT organization.
Your Responsibilities:
- Take full operational and strategic responsibility for IT security within a complex, international, and highly sensitive system landscape.
- Act as a key internal advisor for engineers and developers to improve product cybersecurity, advocating for "Security by Design" principles throughout the R&D lifecycle.
- Lead the implementation and ongoing management of NIS2 compliance and ensure processes align with international standards.
- Provide regular updates and reports to the C-level regarding security milestones, risk assessments, and compliance roadmaps.
- Operate and develop endpoint security while continuously hardening and monitoring client and server infrastructure.
- Monitor, analyse, and lead the response to security events and forensic analysis of incidents.
- Conduct regular vulnerability analyses, derive remediation measures, and enforce strict patch and update discipline.
- Architect firewall, proxy, and network security policies and harden interfaces between the network and end devices.
- Lead security-related (sub-)projects and provide technical coaching to the IT and Engineering teams.
- Partner closely with the IT team on infrastructure updates and serve as a senior escalation point for complex security issues.
Your profile
- At least two years of professional experience in IT security, ideally within a highly regulated, research-heavy, or product-driven environment.
- ISO 27001 certification (e.g., Professional or Internal Auditor) or a similar recognized professional credential.
- Knowledge of security frameworks, with specific experience in NIS2 and an interest in supporting secure software/hardware development considered a strong plus
- Solid expertise in network security (firewalls, VPN, routing), endpoint security, and security operations (SIEM, incident handling, log analysis).
- High flexibility to adapt to a startup environment, combining a senior "owner" mentality with the willingness to be hands-on during technical implementations.
- Strong teamwork abilities with the capability to communicate technical risks to the C-level and provide actionable guidance to developers and engineers.
- Very good German and English skills (written and spoken) for our international environment.
Why us?
- Attractive compensation package, including a competitive base salary and stock options
- Key role in a highly advanced and fast-growing startup company
- Impactful product promoting better understanding and treatment of cancer
- International team, from over 30 different nationalities
- Positive work environment with open communication and a collaborative mindset
- Indefinite employment contract
- 30 vacation days
- Flexible working hours
- Annual health budget (Allianz bKV)
- EGYM Wellpass
- Relocation support