Jobs Companies Isar Aerospace SE Senior Security Engineer (m/f/d)

À propos de ce poste Senior Security Engineer (m/f/d) chez Isar Aerospace SE

Isar Aerospace SE · Sur site · Parsdorf, Bavaria, Germany

Mission Brief 

You are the guardian and the challenger of our security posture. At Isar Aerospace, the systems that build our rockets and the ground systems that launch them are mission critical, and protecting them takes more than good design. It takes someone who will attack their own work to be sure it holds. 

We are looking for a deeply hands-on Senior Security Engineer. You live in the consoles, the rule sets and the code. You own our secure access and network security controls, our endpoint and identity security stack, and our detection content, and you operate them yourself rather than directing from the sidelines. You wear two hats: the Builder who implements and runs the controls that keep us safe, and the Adversary who keeps testing whether those controls and detections actually fire. 

This is a senior engineering role with the spirit of an architect. You are expected to design what you operate, not just configure it: pick the pattern, write it down, and make it hold at fleet scale. A versatile engineer with real depth, comfortable switching from a firewall rule set to a detection query to a directory hardening sprint in the same week, and a technical anchor others lean on. 

Your Role in Our Space Mission 

 

SASE and Network Security 

  • Own and operate our SASE platform, including revamping Internet Security policies and redefining Private Access policies. 
  • Drive firewall security with the network team: own network security engineering and segmentation strategy, analyze rule sets, identify gaps, and see remediation through together with network engineering, who own the devices. 
  • Coordinate firewall-adjacent controls: IPS, AV, sandboxing and DDoS protection. 
  • Manage our DNS security and WAF solutions, including our edge and CDN-based protection services. 

Security Posture and Hardening 

  • Apply CIS Benchmarks to raise posture across firewalls, endpoints, our cloud identity platform and our cloud productivity suite. 
  • Lead the clean-up and hardening of our on-premises and cloud identity directories together with the infrastructure team, then keep both hardened on an ongoing basis. 
  • Drive our phishing-resistant MFA and privileged access programme, including just-in-time elevation and the remediation of the attack paths we find. 
  • Own certificate lifecycle and PKI operations: key ceremonies, automated renewal, and input to our post-quantum migration plan. 

Detection and Visibility 

  • Manage and tune our IPS/IDS platforms; write and maintain custom IDS signatures, and operate network sensors for NTA appliances. 
  • Build and maintain detections in our SIEM and apply MITRE ATT&CK to detection engineering and use-case design in support of the SOC. 
  • Extend visibility into OT with purpose-built OT monitoring tooling. 
  • Act as an L3 incident responder for escalated security events, and turn every finding into a fix, a new detection or a hardened configuration. 

Security Stack and Automation 

  • Own our endpoint detection and response, data protection and CASB platforms as their technical owner. 
  • Script and build internal tooling in PowerShell and Python, so controls and checks run themselves. 

Design and Engineering Partnership 

  • Design what you operate: run threat modeling and attack-path analysis on the systems you own, choose the pattern, and document standards others can execute against. 
  • Evaluate tooling and support vendor selection and renewal decisions in your domain, with a clear view of what each control costs us and what it buys. 
  • Embed security with engineering: partner with IT, infrastructure, manufacturing and mission teams to implement and validate controls in their environments across both IT and OT, respecting launch-window and change-freeze constraints and producing the evidence our audits depend on. 

Qualification Checklist 

  • Experience: 10+ years in security engineering, with real ownership of production security tooling, not policy or advisory work. 
  • Architect Spirit: you can step back from the console, design the target state, write the pattern down, and then go build it yourself. 
  • SASE: hands-on experience administering an enterprise SASE platform end to end, not just consuming it. 
  • Hardening: experience applying CIS Benchmarks to firewalls, endpoints, cloud identity and cloud productivity platforms in production, plus experience rolling out phishing-resistant MFA or privileged access management. 
  • Networking and Firewalls: solid fundamentals, enough to own segmentation strategy and to drive rule set analysis and gap remediation with a network team that owns the devices. Experience with CDN-based WAF and edge protection services. 
  • Security Stack Depth: strong background across endpoint detection and response, data protection, SIEM and detection query languages, cloud identity and on-premises directory hardening, certificate lifecycle and PKI operations, ideally including a large-scale directory clean-up or remediation effort. 
  • Detection Engineering: practical MITRE ATT&CK-driven detection work, and experience writing custom IDS/IPS signatures. 
  • Operational Depth: strong capability in detection, incident response and vulnerability management, with time spent on escalated incidents. 
  • Automation: scripting ability in PowerShell and Python, plus infrastructure-as-code and policy-as-code experience. 
  • IT and OT: comfortable working across both. Working knowledge of OT protocols such as EtherNet/IP, OPC UA and Modbus, and familiarity with OT network monitoring, is a strong plus. 
  • Autonomy: operates with very high autonomy as an internal expert, taking full ownership of their work and guiding others. 
  • Mentoring: mentors engineers and analysts on the team, and acts as technical lead in cross-functional projects. 
  • Communication: clear communication and collaboration skills, able to translate technical risk for a range of audiences and to work controls through other teams. 
  • Education: Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field, or the equivalent through relevant certifications and hands-on experience. 

Bonus Skills 

  • Experience in aerospace, defense, energy, manufacturing or other OT-heavy, safety-critical environments. 
  • Prior SOC or incident response team experience. 
  • Cloud security depth in a major public cloud and its native security services. 
  • Familiarity with industry standards such as ISO 27001 and NIST. 
  • Relevant certifications, defensive or engineering (e.g., Security+, GCIA) and offensive (e.g., OSCP or equivalent), are both valued. 

 

What We Offer 

  • Real Ownership: the security tooling that protects a premier European space company is yours to run, rebuild and prove. 
  • Impact: the opportunity to directly protect the future of spaceflight as we approach our first orbital launch. 
  • Collaboration: work hand-in-hand with brilliant engineers and IT professionals on genuinely hard problems. 

 

Benefits 

  • Employee Participation Program: Share in our success through our virtual company share program
  • 6 weeks of vacation: Enjoy the days off to relax and recharge
  • Subsidised lunch: Stay energised with delicious, subsidised lunches every day
  • Relocation support: Benefit from our relocation bonus with deductible expenses up to an agreed amount
  • Wellness allowance: Stay healthy and fit with our yearly allowance for wellness activities (e.g., Gym, Massages)
  • Individual learning allowance: Grow your skills with an individual learning budget granted after the probation period
  • Physical and mental well-being: Access via OpenUp the online support from certified psychologists and lifestyle experts at no cost to you and your family
  • And Much More! Discover additional perks and benefits when you join our team.  

Who we are

We are Isar Aerospace and we are at the forefront of New Space building a modern space business to enable faster, better and cheaper access to space.

Our mission is to help democratise space and use it for good in order to improve life on Earth now and for the future generations.

We are a fast-growing company aiming to provide sustainable and environmentally friendly launch solutions for small and medium-sized satellites and constellations into Low Earth Orbit. The company is privately funded by world-leading technology investors with strong commitment and support and our team is made of driven and talented people with a real passion for space innovation.

We're making rockets in a way that hasn't been done before disrupting a traditional industry. If you are up for the challenge, want to work on cutting-edge projects and be part of a team changing the world for better, come, join us and launch your career!

Want to find out more about us?

Visit www.isaraerospace.com

 

Data Protection

We process your personal data for the purpose of managing the recruitment process and assessing your application. For detailed information on how your data is processed, including your rights, please refer to our Privacy Policy.

 

Disclaimer

Isar Aerospace SE is an equal-opportunity employer committed to fairness and inclusivity. We do not prioritize any specific religion, gender, nationality, or background. Due to security clearance requirements, affiliations with countries listed under § 13 para. 1 no. 17 SÜG may affect the application process. All qualified applicants are encouraged to apply.

We use Metaview to record interview audio so our team can review it later and stay focused during the conversation. We will record interviews only if you opt in. Please note that we will request your consent separately during the interview process. Participation is completely voluntary and will not affect your application in any way. For more information on how we process your personal data, please see our Privacy Policy.

Prêt à postuler chez Isar Aerospace SE ?
Postuler chez Isar Aerospace SE

Emplois similaires

Wells Fargo
Senior Information Security Engineer
Wells Fargo
⚡ Postuler tôt CHARLOTTE, NC Hybride $100,000–$163,000
● Nouveau 👁 Vu ✓ Postulé il y a 58 min
AL
Product Engineer, Cloud Security (Multiple Levels)
Allstate
⚡ Postuler tôt Belfast 10 Mays Meadow Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 1 h
CrowdStrike
Security Engineer - Cybersecurity IAM (Remote, ROU)
CrowdStrike
⚡ Postuler tôt Romania - Bucharest Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 2 h
CrowdStrike
Security Engineer - Cybersecurity IAM (Remote,ROU)
CrowdStrike
⚡ Postuler tôt Romania - Bucharest Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 2 h
CrowdStrike
Security Engineer - Cybersecurity IAM (Remote,ROU)
CrowdStrike
⚡ Postuler tôt Romania - Bucharest Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 2 h
Stedin
Lead Cyber Security Engineer
Stedin
⚡ Postuler tôt Rotterdam Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 2 h
Wispr Flow
Platform Engineer, Product Security
Wispr Flow
⚡ Postuler tôt San Francisco Sur site $220,000–$350,000
● Nouveau 👁 Vu ✓ Postulé il y a 3 h
PNC
Cloud Security Engineer - Azure Defender/Prisma Cloud/Cortex Cloud
PNC
⚡ Postuler tôt ZZ - Remote Location · lieu restreint $91,000–$202,800
● Nouveau 👁 Vu ✓ Postulé il y a 3 h
Reddit
Staff Machine Learning Engineer, AI Security
Reddit
⚡ Postuler tôt Remote - United States · lieu restreint $230,000–$322,000
● Nouveau 👁 Vu ✓ Postulé il y a 3 h

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Isar Aerospace SE

Voir tous les emplois chez Isar Aerospace SE →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit