Staff Information Security Manager (f/m/d)
About IONOS
At IONOS, we don't just manage servers – we shape the digital future for more than 6.2 million customers worldwide with our solutions. As Europe's leading hosting provider and a pioneer in independent cloud solutions, we are building next-generation infrastructure – from sovereign cloud architectures and high-performance GPU clusters to integrated AI automation tools.
What drives us is digital sovereignty for Europe and real impact for small and medium-sized businesses (SMBs) as well as large enterprises. We work in agile teams, rely on transparent structures, and believe that excellence and innovation only emerge through true team spirit.
Ready for your next step? Become part of IONOS and grow with us.
For us, security isn't an afterthought or a checkbox exercise – it's built right into our DNA. We integrate security exactly where it matters most: into our architectures, pipelines, and operational concepts. Compliance evidence is generated naturally from our day-to-day operations, not from stressful last-minute audit prep. We are looking for someone who can translate security requirements into resilient technical concepts and actively verify their effectiveness.
Tasks
- Drive the evolution of our Secure SDLC side-by-side with our dev teams.
- Lead Threat Modeling and architecture reviews – catching risks early in the design phase, not right before a release.
- Design robust IAM concepts (role models, permission logic, recertification) and define clear cryptographic standards and baselines.
- Take charge of vulnerability and pentest management: scanning, CVSS scoring, prioritizing, and tracking remediations.
- Specify requirements for logging, monitoring, and error handling, and review their implementation across the board.
- Design and evaluate technical Business Continuity (BC) and disaster recovery tests.
- Automate compliance and evidence collection directly within the teams' CI/CD pipelines.
Qualifications
- Well-founded, multi-year practitioner’s experience with standardised management systems and certifications, attestations in the cyber security area.
- You have practical experience from two or more certified scopes according to ISO 27001, IT-Grundschutz, BSI C5. More ISO management system experience from privacy standards comes as a plus.
- You have multi-year experience with above standards and certifications in a technical organisation, as in the company offers technical products.
- You are burning for modern tool supported, efficient integration of management systems and certification activities into the daily routine of an organisation.
- You love technology, you do not shy away from documentation but would like to structure it as efficiently as possible.
- You convince through your confident and communicative character when achieving goal oriented results with your international and internal interfaces.
- You proficiently lead discussions in English (CEFR C1 or higher). Completely fluent German (C1 CEFR level is a must).
Nice to Have
- Deep conceptual knowledge of IAM (Role/Permission models, SSO, Federation, PAM, recertification logic).
- Practical experience with applied cryptography (TLS, PKI, Key Management, HSM).
- Familiarity with major frameworks (ISO/IEC 27001 Annex A, BSI IT-Grundschutz, OWASP ASVS & Top 10, CIS Benchmarks, NIST CSF).
- Experience with Policy as Code and Continuous Compliance.
- An understanding of audit logic and how to collaborate smoothly with external auditors.
Benefits
- Hybrid working model with home office option.
- Flexible working hours through trust-based working hours.
- At some locations a subsidized canteen and various free drinks.
- Modern office space with very good transport connections.
- Various employee discounts for activities and products.
- Employee events such as summer and winter parties, as well as workshops.
- Numerous training and development opportunities.
- Various health offers, such as sports and health courses.
Application Note
We value diversity and welcome all applications – regardless of, for example, gender, nationality, ethnic or social origin, religion, disability, age as well as sexual orientation and identity, physical characteristics, marital status or any other irrelevant factor subject to applicable law.
Skills
As published by greenhouse · 13 questions
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
Short answers (4)
- LinkedIn/Xing Profile optional
- What is your current notice period? optional
- What are your yearly salary expectations for this role?
- In which city do you currently live?
Pick from a list (9)
- How did you hear about this position?
- If you do not live in Berlin, would you be willing to relocate?
- Which communication language do you prefer?
- Do you have a work permit to work in the country in which the role is based?
- What languages do you speak fluently? optional
- Would you agree to us forwarding your application documents to other departments? optional
- Have you worked at IONOS in the past? optional
- Please select all of your tools and competencies optional
- I agree that my application documents and all other personal data that I have submitted to IONOS SE as part of my application may be transmitted in the IONOS talent pool and used for a maximum of 2 years by IONOS SE and its affiliates - including in third countries - for other job advertisements. I can revoke my consent at any time at jobs@ionos.com.