Why This Role Stands Out
In this hybrid role, you'll directly shape the security and compliance of a platform vital for European enterprises and governments, fostering digital sovereignty and innovation. You'll thrive here if you have a passion for hands-on security engineering, DevSecOps, and a desire to build foundational security for critical infrastructure. Apply today to make a significant impact on a respected company's security posture.
Quick Overview
Job Description
As a Senior Security & Compliance Engineer at Codesphere, you will own the security posture of a platform that enterprises and governments across Europe depend on to achieve digital sovereignty – without sacrificing modern cloud capability. Your work directly enables a future where critical infrastructure no longer has to choose between innovation and independence. Security here is not a checkbox – it's the foundation that makes that vision possible.
Activities
- You conduct security assessments, penetration testing, and vulnerability scanning – and drive remediation with development teams
- You manage security scanning tooling (DAST/SAST) and perform security code reviews
- You design and implement security controls across our full technology stack, defining and enforcing standards for development, infrastructure, and data
- You integrate security into our CI/CD pipelines and development processes – Shift Left and DevSecOps in practice, not just on paper
- You develop and maintain our Security Incident Response Plan, monitor security logs via SIEM, and lead forensic analysis when needed
- You ensure compliance with relevant standards and regulations – including GDPR and ISO 27001
- You manage IAM systems with a least privilege approach
- You develop and deliver security awareness training for the whole company – and specialised secure coding training for engineering teams
Requirements
- 5+ years in a security engineering or similar role, ideally in a cloud or SaaS environment
- Hands-on experience with penetration testing, vulnerability management, and DAST/SAST tooling
- Solid understanding of DevSecOps principles and CI/CD security integration
- Familiarity with SIEM tools, incident response, and forensic analysis
- Knowledge of relevant compliance frameworks – GDPR, ISO 27001, and ideally BSI IT-Grundschutz
- Strong communicator – able to translate security risks into clear guidance for both technical and non-technical audiences
- Fluent in English; German is a strong plus given the nature of our compliance landscape
Team
You'll be our second dedicated security hire – working closely with one colleague (based in MUC) to build the function together. That means tight collaboration, real ownership from day one, and a direct hand in shaping how security at Codesphere looks as we scale.
Similar jobs
- TI
(Senior) Cyber Security Expert (m/w/d) DFIR, Adversary Operations & Assessments
NewTÜV Informationstechnik GmbH
essen, nordrhein westfalen🇩🇪Hybrid2 hours agoTechnology - TI
IT-Sicherheitsexpert:in
NewTÜV Informationstechnik GmbH
essen, nordrhein westfalen🇩🇪Hybrid2 hours agoOnboarding - CG
IT Security Engineer (m/w/d)
NewCGM
koblenz, Rheinland-Pfalz🇩🇪Hybrid2 hours agoGrafanaTechnology - IN
Senior Security & Compliance Engineer
NewInstaffo GmbH
München, Bayern🇩🇪HybridYesterdayAdministrative - IA
Senior Security Engineer (m/f/d)
NewIsar Aerospace SE
Parsdorf🇩🇪20 hours agoMFACDNDNS+6Technology - SI
Sicherheitsingenieur (m/w/d)
NewSika AG
Bad Urach, BW🇩🇪HybridYesterdayManufacturing