Summary
β¨ AIβGenerated
A senior security engineering role responsible for protecting cloud infrastructure through assessments, incident handling, compliance initiatives, and collaboration with engineering teams.
Highlights
Own security strategy for critical cloud infrastructure with opportunities to shape security practices, compliance programs, and engineering standards in a growing international environment.
Description
About Codesphere
Codesphere is a Virtual Cloud Provider from Germany building the future of sovereign cloud infrastructure.
Our platform gives enterprises and governments full sovereignty without giving up modern cloud capability β a vision recently validated by a series of multi-million European government tenders.
Since our founding in Karlsruhe in 2020, weβve expanded into an international team of 60+ experts.
Based in Karlsruhe and Munich and backed by top-tier investors, we are chasing a bold vision.
Weβre scaling fast and would love for you to join us and grow alongside us π
About The Role
Codesphere runs cloud infrastructure that enterprises and governments depend on β security is not an afterthought, it's a foundation.
As a Senior Security & Compliance Engineer (m/f/d), you own the security posture of our platform: from vulnerability management and incident response to compliance frameworks and developer enablement.
What you'll drive
You conduct security assessments, penetration testing, and vulnerability scanning β and drive remediation with development teamsYou manage security scanning tooling (DAST/SAST) and perform security code reviewsYou design and implement security controls across our full technology stack, defining and enforcing standards for development, infrastructure, and dataYou integrate security into our CI/CD pipelines and development processes β Shift Left and DevSecOps in practice, not just on paperYou develop and maintain our Security Incident Response Plan, monitor security logs via SIEM, and lead forensic analysis when neededYou ensure compliance with relevant standards and regulations β including GDPR and ISO 27001You manage IAM systems with a least privilege approachYou develop and deliver security awareness training for the whole company β and specialised secure coding training for engineering teams
What makes you a great fit
5+ years in a security engineering or similar role, ideally in a cloud or SaaS environmentHands-on experience with penetration testing, vulnerability management, and DAST/SAST toolingSolid understanding of DevSecOps principles and CI/CD security integrationFamiliarity with SIEM tools, incident response, and forensic analysisKnowledge of relevant compliance frameworks β GDPR, ISO 27001, and ideally BSI IT-GrundschutzStrong communicator β able to translate security risks into clear guidance for both technical and non-technical audiencesFluent in English; German is a strong plus given the nature of our compliance landscape
What's in it for you
32 days of paid time off β 30 regular vacation days plus Christmas Eve and New Year's Eve offMeal allowance β up to 15 digital vouchers per month, adding up to over β¬100 net for youFlexibility β hybrid work setup with mobile work options and flexibility around core hoursSteep learning curve β fast-moving environment, real ownership, and a front-row seat to scaling a companyJob-Rad β lease a bike through us, tax-freeGym access β stay active on site (Karlsruhe office only)Employee events β from team offsites to regular get-togethersCompany pension scheme β company-supported pension to set you up for laterGreat public transport links β both offices are within walking distance of tram and metro stops