4 hours ago
Berlin, GermanySenior
Responsibilities
- Define and maintain security architecture standards and hardening baselines for provider infrastructure.
- Assess tenant isolation across shared-hosting, virtualization, and container layers and drive remediation with platform teams.
- Review infrastructure designs and major changes for security impact and act as an escalation point for infrastructure security.
- Reduce blast radius across privileged access, administrative segmentation, secrets handling, and recovery integrity.
- Support Cyber Defense, Vulnerability Management, and IT emergency management during incidents and post-incident hardening.
- Own security architecture and baseline standards for internally operated AI platforms, agents, connectors, and retrieval pipelines.
- Define agent identity, authentication, authorization, credential and token management, least-privilege access, and human-in-the-loop controls.
- Set data access and indexing rules for internal AI systems and ensure agent activity is logged, attributable, and auditable.
- Perform pre-deployment security reviews for internal AI platforms and agent use cases and oversee Shadow AI.
- Advise security and engineering teams on secure AI adoption and practical guardrails.
Requirements
- Several years of practical infrastructure or platform security experience, ideally in hosting, cloud, telecommunications, or a comparably large multi-tenant environment.
- Deep practical knowledge of Linux, virtualization and container platforms, networking, and multi-tenant infrastructure security.
- Strong identity and access background covering privileged access, machine and workload identities, secrets management, authorization models, and infrastructure-as-code security.
- Experience developing and enforcing security standards across heterogeneous, partly legacy environments and gaining adoption outside one’s reporting line.
- Practical experience building and operating LLM and agent systems and understanding risks such as prompt injection, excessive tool access, retrieval-based data exposure, unlogged autonomous actions, and model or provider dependencies.
- Ability to make and defend risk-based decisions, including blocking deployments with clear justification, and explain technical risk to non-technical stakeholders.
- Fluent English; German is strongly advantageous.
- Preferred: production experience deploying or securing internal AI platforms, agent frameworks, or tool-calling integrations.
- Preferred: familiarity with NIS2, BSIG, or ISO 27001.
- Preferred: DNS, email infrastructure, platform-adjacent abuse prevention, multi-brand or post-acquisition environments, security engineering, software development, automation, tooling, or scripting experience.
Benefits
- Hybrid work model.
- Flexible working hours through trust-based working time.
- Subsidized canteen at some locations and various complimentary drinks.
- Modern offices with excellent transport connections.
- Employee discounts for activities and products.
- Employee events including summer and winter celebrations and workshops.
- Numerous training and development opportunities.
- Health offerings including sports and health courses.
About IONOS DE
IONOS DE provides domains, web hosting, website builders, e-commerce and marketing tools for small and midsize businesses, and offers cloud infrastructure and IaaS for organizations with European data sovereignty requirements. The company earns revenue from subscriptions and pay-as-you-go cloud services. Founded in 1988 and headquartered in Karlsruhe, it serves more than six million customers across 18 markets in Europe and North America.
