Point your AI agent at freehire and let it find you a job.

Get the CLI →

IONOS EN

NewBe an early applicant

Staff Information Security Manager (f/m/d)

Posted 4 views
Discussion

About IONOS

At IONOS, we don't just manage servers – we shape the digital future for more than 6.2 million customers worldwide with our solutions. As Europe's leading hosting provider and a pioneer in independent cloud solutions, we are building next-generation infrastructure – from sovereign cloud architectures and high-performance GPU clusters to integrated AI automation tools.

What drives us is digital sovereignty for Europe and real impact for small and medium-sized businesses (SMBs) as well as large enterprises. We work in agile teams, rely on transparent structures, and believe that excellence and innovation only emerge through true team spirit.

Ready for your next step? Become part of IONOS and grow with us.

For us, security isn't an afterthought or a checkbox exercise – it's built right into our DNA. We integrate security exactly where it matters most: into our architectures, pipelines, and operational concepts. Compliance evidence is generated naturally from our day-to-day operations, not from stressful last-minute audit prep. We are looking for someone who can translate security requirements into resilient technical concepts and actively verify their effectiveness.

Tasks

  • Drive the evolution of our Secure SDLC side-by-side with our dev teams.
  • Lead Threat Modeling and architecture reviews – catching risks early in the design phase, not right before a release.
  • Design robust IAM concepts (role models, permission logic, recertification) and define clear cryptographic standards and baselines.
  • Take charge of vulnerability and pentest management: scanning, CVSS scoring, prioritizing, and tracking remediations.
  • Specify requirements for logging, monitoring, and error handling, and review their implementation across the board.
  • Design and evaluate technical Business Continuity (BC) and disaster recovery tests.
  • Automate compliance and evidence collection directly within the teams' CI/CD pipelines.

Qualifications

  • Well-founded, multi-year practitioner’s experience with standardised management systems and certifications, attestations in the cyber security area.
  • You have practical experience from two or more certified scopes according to ISO 27001, IT-Grundschutz, BSI C5. More ISO management system experience from privacy standards comes as a plus.
  • You have multi-year experience with above standards and certifications in a technical organisation, as in the company offers technical products.
  • You are burning for modern tool supported, efficient integration of management systems and certification activities into the daily routine of an organisation.
  • You love technology, you do not shy away from documentation but would like to structure it as efficiently as possible.
  • You convince through your confident and communicative character when achieving goal oriented results with your international and internal interfaces.
  • You proficiently lead discussions in English (CEFR C1 or higher). Completely fluent German (C1 CEFR level is a must).

Nice to Have

  • Deep conceptual knowledge of IAM (Role/Permission models, SSO, Federation, PAM, recertification logic).
  • Practical experience with applied cryptography (TLS, PKI, Key Management, HSM).
  • Familiarity with major frameworks (ISO/IEC 27001 Annex A, BSI IT-Grundschutz, OWASP ASVS & Top 10, CIS Benchmarks, NIST CSF).
  • Experience with Policy as Code and Continuous Compliance.
  • An understanding of audit logic and how to collaborate smoothly with external auditors.

Benefits

  • Hybrid working model with home office option.
  • Flexible working hours through trust-based working hours.
  • At some locations a subsidized canteen and various free drinks.
  • Modern office space with very good transport connections.
  • Various employee discounts for activities and products.
  • Employee events such as summer and winter parties, as well as workshops.
  • Numerous training and development opportunities.
  • Various health offers, such as sports and health courses.

Application Note

We value diversity and welcome all applications – regardless of, for example, gender, nationality, ethnic or social origin, religion, disability, age as well as sexual orientation and identity, physical characteristics, marital status or any other irrelevant factor subject to applicable law.

Skills

What Staff Security jobs ask for — and how much of it you have →
Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available