Jobiglo

No results.

Senior Security & Compliance Engineer

codesphere · Munich

New
Hybrid Senior 🇬🇧 English
Penetration testing Vulnerability scanning DAST SAST DevSecOps SIEM Incident response Forensic analysis GDPR ISO 27001 IAM

Job description

About the role

Codesphere is building a sovereign cloud platform and needs a senior professional to own its security posture. You will lead vulnerability management, incident response and compliance initiatives while enabling developers to build securely.

Key responsibilities

  • Conduct security assessments, penetration testing and vulnerability scanning, driving remediation with development teams.
  • Manage DAST/SAST tooling and perform security code reviews.
  • Design and implement security controls across the full technology stack, defining standards for development, infrastructure and data.
  • Integrate security into CI/CD pipelines, applying Shift‑Left and DevSecOps practices.
  • Develop and maintain the Security Incident Response Plan, monitor logs via SIEM and lead forensic analysis when required.
  • Ensure compliance with GDPR, ISO 27001 and other relevant regulations.
  • Manage IAM systems using a least‑privilege approach.
  • Deliver security awareness training company‑wide and specialised secure‑coding training for engineering teams.

Required profile

  • 5+ years in security engineering, preferably in cloud or SaaS environments.
  • Hands‑on experience with penetration testing, vulnerability management and DAST/SAST tools.
  • Strong understanding of DevSecOps principles and CI/CD security integration.
  • Familiarity with SIEM tools, incident response and forensic analysis.
  • Knowledge of GDPR, ISO 27001 and ideally BSI IT‑Grundschutz.
  • Excellent communication skills to translate security risks for technical and non‑technical audiences.
  • Fluent English; German is a strong plus.

Required skills

  • Penetration testing
  • Vulnerability scanning
  • DAST and SAST tooling
  • CI/CD pipeline security
  • DevSecOps
  • SIEM
  • Incident response
  • Forensic analysis
  • GDPR
  • ISO 27001
  • BSI IT‑Grundschutz
  • IAM (least‑privilege)

What we offer

  • 32 days paid time off (including Christmas Eve and New Year’s Eve).
  • Meal allowance up to €100 net per month.
  • Hybrid work setup with flexible core hours.
  • Fast‑moving environment with real ownership.
  • Bike‑lease programme, gym access and regular employee events.
  • Company‑supported pension scheme and excellent public‑transport links.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec codesphere.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:ashby

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 day ago

Expires 1 month from now

15 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

codesphere

Munich