Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Engineer (m/w/d) image - Rise Careers
Job details

Senior Security Engineer (m/w/d)

Festanstellung, Vollzeit * Deutschland (hybrid oder remote)

WERDE TEIL VON ROADSURFER

Wir suchen einen Security Engineer, die/der unser Team bei der Arbeit an internen IT-Systemen und unseren Software-Anwendungen für Endverbraucher verstärkt. Du wirst Teil unserer Erfolgsgeschichte sein und hilfst dabei, einzigartige Reiseerlebnisse für Kunden weltweit zu ermöglichen und unsere Teams an den Stationen zu unterstützen.

Wenn du eine kreative Person bist, die Probleme löst und ein neues Abenteuer sucht, dann bist du in unserem internationalen Arbeitsumfeld genau richtig!

WARUM ROADSURFER?

  • TEAMSPIRIT & TEAMEVENTS: Freu dich auf eine kollegiale Atmosphäre mit flachen Hierarchien, jede Menge Spaß und großartigem Teamspirit sowie regelmäßige Teamevents wie gemeinsame Sportsessions, Pizza & Bier Abende, etc.

  • FLEX WORK & WORKACTION: Du bist flexibel hinsichtlich der Arbeitszeit und kannst dank unserer Flex Work Policy zwischen Bürotagen und Home-Office Tagen wechseln und einen Monat pro Jahr aus dem europäischen Ausland arbeiten

  • PERSONAL DEVELOPMENT: Wir unterstützen deine persönliche und fachliche Weiterentwicklung durch einen individuellen Growth Plan und unsere Inhouse Academy

  • CAMPER BUDGET: Du bekommst eine jährliche Freimiete für unsere Camper, damit du den #happyroadsurfing Lifestyle selbst erleben kannst

  • JOB BIKE: Bleibe fit mit unserem Angebot eines Jobrads

  • DISCOUNTS: Nutze unsere Corporate Benefits Plattform, die Travel Industry Card und Family & Friends Rabatte

  • THE PLACE TO BE: Freu dich auf ein wunderschönes, helles Büro mit allem, was das Herz begehrt wie Tischtennisplatte & Kicker. Lass dich außerdem von wöchentlichen Frühstücks- und Mittagsessensangeboten verwöhnen

  • OFFICE DOGS: Hunde im Büro sind bei uns herzlich willkommen

DIE ROLLE - DEINE LEIDENSCHAFT

  • Du förderst ein Security-First - Mindset innerhalb der internen IT- und Softwareentwicklungsteams, indem du aktiv das Bewusstsein für potenzielle Risiken, deren Schäden und die Bedeutung der Integration von Sicherheit in alle Aspekte ihrer Arbeit schaffst.

  • Du koordinierst, führst durch und überprüfst externe Penetrationstests und Sicherheitsprüfungen unserer internen IT-Systeme und Anwendungslandschaft, um gründliche Bewertungen sicherzustellen und die Umsetzung von empfohlenen Verbesserungen zur Behebung identifizierter Sicherheitslücken zu verfolgen.

  • Du entwickelst und implementierst robuste Verfahren und Richtlinien, die sicherstellen, dass alle Systeme den regulatorischen Sicherheitsstandards und Compliance-Anforderungen entsprechen und schaffst klare Leitlinien, damit Teammitglieder proaktiv ihre Sicherheitsverantwortung wahrnehmen.

  • Du analysierst, empfiehlst und implementierst strategische Projekte zur Verbesserung unserer Sicherheitslage, während du gleichzeitig die Produktivitätsbedürfnisse der Organisation berücksichtigst, wie z. B. den Einsatz KI-unterstützter Produktivitätstools oder die Absicherung einer umfassenden Cybersecurity-Versicherung.

  • Du bleibst der sich entwickelnden Bedrohungslandschaft im Bereich Cybersicherheit stets einen Schritt voraus, indem du kontinuierlich neue Technologien und Branchentrends verfolgst und aktiv Beziehungen zu Cybersicherheitsanbietern pflegst, um sicherzustellen, dass roadsurfer stets gut gerüstet ist, um neue Herausforderungen zu bewältigen.

  • Du arbeitest eng mit dem IT-Sicherheitsteam und den Softwareentwicklungsteams zusammen, um wirksame Sicherheitskontrollen umzusetzen, ihre Leistung rigoros zu verfolgen und Nachbesprechungen durchzuführen, um kontinuierliche Verbesserung zu gewährleisten.

  • Dein proaktiver Ansatz stellt sicher, dass roadsurfer das Vertrauen der Kunden und die regulatorische Compliance aufrechterhält, sensible Daten schützt und alle Sicherheitsmaßnahmen mit dem Engagement des Unternehmens für Exzellenz und Transparenz in Einklang bringt.

  • Du nutzt Automatisierung und Orchestrierung, um Sicherheitsoperationen zu optimieren, wiederkehrende Aufgaben zu automatisieren und komplexe Workflows zu koordinieren, um menschliche Fehler zu reduzieren und sicherzustellen, dass die Verteidigung von roadsurfer immer einen Schritt voraus ist, um neuen Bedrohungen zu begegnen.

WAS DU MITBRINGEN SOLLTEST, UM MIT UNS AUF EINER WELLE ZU REITEN

  • Agiere als Botschafter: Du repräsentierst und förderst eine Security-first Kultur und fungierst als Vorbild und Befürworter:in bewährter Praktiken auf allen Ebenen der Organisation.

  • Andere beeinflussen: Du inspirierst Teams, indem du die Bedeutung von Cybersecurity klar kommunizierst, Zusammenarbeit förderst und die Ausrichtung auf gemeinsame Ziele vorantreibst.

  • Technische Schreibkompetenz: Du bist ausgezeichnet darin, klare und prägnante Dokumentationen zu erstellen, einschließlich Problembeschreibungen, Erfolgsmessungen, Optionenbewertungen und umsetzbare Empfehlungen.

  • Erste Erfahrung in IT- und Anwendungssicherheit: Du hast grundlegende Kenntnisse in Sicherheitspraktiken wie OWASP und verstehst die wichtigsten Risiken und Strategien zur Risikominderung für Anwendungen und IT-Systeme.

  • Bereitschaft, Sicherheitszertifikate zu erwerben: Du zeigst eine proaktive Haltung, indem du deine Expertise durch branchenweit anerkannte Zertifikate wie CISSP, CISM oder CEH erweitern möchtest.

  • Erfahrung in der Erlangung von Unternehmenssicherheitszertifikaten: Du hast praktische Erfahrung in der Mitwirkung oder Leitung von Bemühungen zur Erlangung von Sicherheitszertifikaten auf Unternehmensebene, wie z.B. ISO 27001, um die Compliance zu gewährleisten und Sicherheitsstandards zu verbessern.

  • Sprachkenntnisse: Du bist deutschsprachig und verfügst über verhandlungssichere Englischkenntnisse.

BEREIT, DIE WELLE ZU REITEN?

Wir freuen uns sehr auf deine Bewerbung! Wenn du eine Frage hast, dann wende dich gerne an unseren Recruiter Luca unter: team@roadsurfer.com.

ABOUT #ROADSURFER

As a #roadsurfer you are part of an open, fast-growing team with ambitious goals and a great team spirit. We stick together and combine a brutal hands-on mentality with fun at work! It means shaping the future of outdoor travel and building an ecosystem for sustainable outdoor travel. We are more than Europe's largest campervan rental company. In 2021 we launched our platform roadsurfer spots in addition to our other products rent, abo and sales – a platform where you can discover and book unique camping spots. But that’s only the beginning. We are growing fast, so hop on board and join us on our journey. We’re looking for motivated and passionate people whose hearts beat for campers. Wanna spread the roadsurfer spirit across the globe with us?

roadsurfer Glassdoor Company Review
4.0 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
roadsurfer DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of roadsurfer
roadsurfer CEO photo
Markus Dickhardt
Approve of CEO

Average salary estimate

$70000 / YEARLY (est.)
min
max
$60000K
$80000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Security Engineer (m/w/d), roadsurfer

Are you ready to embark on an exciting journey with Roadsurfer as a Senior Security Engineer (m/w/d) in Munich? In this pivotal role, you will be instrumental in fortifying our internal IT systems and enhancing our customer-facing software applications. Your expertise will help not just in safeguarding the data but also in creating unforgettable travel experiences for customers around the globe. We thrive in a vibrant, international environment that values creativity and problem-solving, where every team member’s input is crucial in crafting secure and efficient digital solutions. At Roadsurfer, we offer a plethora of perks including flexible working hours, a chance to work from abroad, personal development programs, and even a camper budget for you to explore the #happyroadsurfing lifestyle yourself! Our team spirit shines brightly through fun team events and a supportive workplace, where you can bond over shared interests and engage in collaborative projects. As a key player in our IT security team, you will promote a security-first mindset, lead penetration tests, develop compliance strategies, and stay ahead of the evolving cybersecurity threats. If you have a passion for security practices and are eager to take on new challenges, we would love to see your application. Let’s create innovative solutions together at Roadsurfer!

Frequently Asked Questions (FAQs) for Senior Security Engineer (m/w/d) Role at roadsurfer
What are the main responsibilities of a Senior Security Engineer at Roadsurfer?

As a Senior Security Engineer at Roadsurfer, your primary responsibilities include promoting a security-first mindset within IT and software development teams, coordinating external penetration tests and security audits, and implementing robust security policies and procedures. You will also analyze and recommend strategic security initiatives while collaborating closely with various teams to ensure that security measures align with company goals.

Join Rise to see the full answer
What qualifications are required for the Senior Security Engineer position at Roadsurfer?

To thrive as a Senior Security Engineer at Roadsurfer, you should have foundational knowledge in IT security principles and practices such as OWASP, experience in organizational security certification efforts like ISO 27001, and a commitment to acquiring recognized security certifications like CISSP or CISM. Strong technical writing skills and proficiency in German and English are also key to the role.

Join Rise to see the full answer
How does Roadsurfer support the personal and professional development of a Senior Security Engineer?

Roadsurfer is deeply invested in the personal and professional development of its team members. As a Senior Security Engineer, you will benefit from an individualized Growth Plan and access to our Inhouse Academy, which promotes continuous learning and skill enhancement tailored to your career aspirations.

Join Rise to see the full answer
What is the work culture like for a Senior Security Engineer at Roadsurfer?

The work culture at Roadsurfer for a Senior Security Engineer is dynamic and engaging. With a focus on team spirit, collaborative work styles, and regular team events, you’ll find yourself in a fun, open environment where innovation thrives and every voice is heard. The flexibility in work hours and the opportunity for remote work makes it even more attractive.

Join Rise to see the full answer
Can a Senior Security Engineer work remotely at Roadsurfer?

Yes, a Senior Security Engineer at Roadsurfer can enjoy the benefits of a hybrid work model. You have the freedom to choose between in-office days in Munich and remote work, with the added advantage of being able to work from anywhere in Europe for one month each year.

Join Rise to see the full answer
Common Interview Questions for Senior Security Engineer (m/w/d)
How do you promote a security-first culture within teams as a Senior Security Engineer?

To promote a security-first culture, emphasize clear communication and the importance of collective responsibility within your teams. Share best practices, conduct training sessions, and lead by example to inspire confidence in security protocols.

Join Rise to see the full answer
What strategies do you use to stay updated on the latest cyber threats?

To stay updated on the latest cyber threats, I regularly follow cybersecurity news sources, engage with industry forums, and maintain relationships with cybersecurity providers to leverage their insights and tools for proactive threat management.

Join Rise to see the full answer
How do you handle security incidents and breaches?

In handling security incidents, my approach begins with immediate containment and assessment of the breach's scope. Following that, I work on communication protocols, analyzing the incident thoroughly, and implementing corrective measures to prevent future occurrences.

Join Rise to see the full answer
What experience do you have with conducting penetration tests?

I have significant experience coordinating penetration tests with external vendors, allowing for comprehensive assessments of system vulnerabilities. My role typically involves overseeing the testing process, reviewing findings, and prioritizing the remediation of identified issues.

Join Rise to see the full answer
Can you explain a time when you successfully improved an organization's security posture?

In a previous role, I initiated a project that involved upgrading the existing firewall systems and introducing multi-factor authentication, which significantly reduced unauthorized access attempts and enhanced our overall security framework.

Join Rise to see the full answer
What are the key elements of a strong security policy?

Key elements of a strong security policy include clear definitions of roles and responsibilities, guidelines for data protection, incident response protocols, compliance requirements, and regular review mechanisms to adapt to changing threat landscapes.

Join Rise to see the full answer
How do you prioritize security projects in a fast-paced environment?

I prioritize security projects by evaluating risks associated with potential threats and aligning projects with organizational objectives. Collaborating with stakeholder teams also helps gauge the urgency and resource allocations needed.

Join Rise to see the full answer
What is your experience with ISO 27001 and why is it important?

I have participated in efforts to achieve ISO 27001 certification, which is vital as it establishes a framework for managing sensitive company information, thereby reinforcing customer trust and ensuring compliance with regulatory requirements.

Join Rise to see the full answer
How do you communicate complex security concepts to non-technical stakeholders?

To communicate complex security concepts to non-technical stakeholders, I focus on simplifying terminology and using relatable analogies. I also emphasize the implications of security risks on business outcomes to engage their interest.

Join Rise to see the full answer
What tools or software do you prefer for automating security operations?

I prefer using tools like SIEM solutions for real-time monitoring and response. Additionally, employing automation software for vulnerability scanning and patch management helps streamline operations while significantly reducing the scope for human error.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Posted 13 days ago
Inclusive & Diverse
Collaboration over Competition
Fast-Paced
Growth & Learning
Empathetic
Posted 4 hours ago
Photo of the Rise User
Posted 12 days ago
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 12, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!