Cybersecurity Engineer (m/f/d)
Job Description & Overview
Mission Brief
You are a technical guardian of our digital environment. At Isar Aerospace, the systems, data and people that build our rockets are mission critical and protecting them takes someone who builds controls and then proves they hold.
We are looking for a hands-on Security Engineer who bridges the gap between Security Architecture and Operations. You are not just a consultant; you are a builder and an auditor. You wear two hats: the Engineer who designs and implements security controls, and the Technical Auditor who verifies that systems and operations meet the high standards required for a space company. You will act as the technical conscience of our environment, working across domains such as endpoints, identity, cloud, networks and applications.
Your Role in Our Space Mission:
- Engineer security controls: design, implement and maintain security controls across our technology stack, defining the exact configurations and policies required to protect our systems, applications and data.
- Act as the technical auditor: you don’t just trust; you verify. Check the configurations of IT and engineering teams against security baselines and provide guidance to close gaps.
- Protect identity and access: help safeguard the keys to the kingdom through strong authentication, least privilege and privileged access controls across the environment.
- Detect and respond: use security monitoring and telemetry to separate signal from noise. When an alert fires, investigate the root cause and coordinate remediation.
- Define the hardening standard: develop and maintain secure configuration baselines and engineering standards for the systems in your scope. You define what “secure” looks like.
- Automate the defence: use scripting to automate security checks, streamline incident response and integrate disparate security tools.
- Collaborate and document: produce clear technical documentation and translate complex security requirements into runbooks that IT and engineering teams can execute.
Qualification Checklist
- Education: Bachelor’s or Master’s degree in Computer Science, Information Security or a related field, or the equivalent through relevant certifications and hands-on experience.
- Experience: 3–5+ years in Information Security or Security Engineering, with hands-on ownership of security controls in a production environment.
- Hands-on Engineering: deep experience implementing security controls in at least one domain such as endpoint, identity, cloud, network or application security. You configure controls yourself, not just review them.
- Broad Security Fluency: solid understanding of core security domains and how they interact to defend an enterprise environment.
- Technical Audit Mindset: you can “check the homework” of other teams and know exactly where to look to verify whether a system is truly compliant with CIS Benchmarks or internal standards.
- Detection and Response: proficiency in log analysis and security telemetry, able to troubleshoot an incident across network, endpoint, application and cloud logs to