> Markdown version of [/jobs/ext/122675-security-engineer](https://www.wearedevelopers.com/jobs/ext/122675-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** GRAYOAK - **Location:** Frankfurt am Main, Germany (Remote available) - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Bash Shell, Cloud Computing, Cyber Security, Identity and Access Management, Python (Programming Language), Network Security, OAuth, OpenID, Open Web Application Security, Windows PowerShell, Security Information and Event Management, Tripwire, Data Logging, Scripting, Generative AI, Kubernetes, Information Technology, Key Vault, Static Application Security Testing, Dynamic Application Security Testing - **Published:** May 14, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=496913b07ae032be ## About the Role * Abgeschlossenes Studium der Informatik, IT-Sicherheit oder vergleichbare Qualifikation * Mehrjährige Erfahrung in IT-Security mit deutlichem Fokus auf Cloud-Umgebungen * Tiefe Kenntniess in Security Services für OnPremise und Cloud Lösungen * Fundierte Kenntnisse im Bereich Netzwerksicherheit * Fundierte Erfahrung mit IAM, OAuth 2.0, OIDC und Zero-Trust-Architekturen * Sicherer Umgang mit gängigen Security-Frameworks (OWASP Top 10, NIST CSF, MITRE ATT&CK) * Verhandlungssichere Deutsch- und Englischkenntnisse in Wort und Schrift Pluspunkte! * Zertifizierungen wie CISSP, OSCP oder Azure Security Engineer Associate * Erfahrung mit KRITIS oder Security-Standards wie IEC 62645 * Scripting in Python, PowerShell oder Bash * Erfahrung mit Container- und Kubernetes-Security (Falco, Trivy, Kyverno) * Hintergrund in Red Teaming oder Bug Bounties ## Description Bei GRAYOAK arbeitest du an anspruchsvollen Softwareprojekten im Umfeld von Data, AI und moderner Plattformarchitektur. In interdisziplinären Teams entwickeln wir skalierbare Enterprise-Lösungen und begleiten deren Umsetzung von der Architektur bis in den produktiven Betrieb. Dabei verantwortest du die Sicherheit unserer Plattformen, setzt Security-by-Design um und sorgst dafür, dass unsere Lösungen höchsten Compliance- und Sicherheitsanforderungen standhalten - insbesondere in anspruchsvollen, regulierten Kundenprojekten. Dein Fokus liegt auf Threat Modeling, der Umsetzung von Compliance-Standards (ISO 27001, BSI C5, IEC 62443) sowie dem Aufbau von Zero-Trust-Konzepten für Cloud und OnPremise. Generative AI setzt du dabei gezielt für Spec-driven Development ein - als Werkzeug, dem du nicht blind vertraust, sondern dass du mit Engineering-Verstand kritisch hinterfragst., * Implementierung und Pflege von Security-Maßnahmen in Applikationen und Cloud-Infrastruktur (Azure) * Threat Modeling, Integration von SAST/DAST und Koordination von Penetration-Tests * Umsetzung von Compliance-Anforderungen (ISO 27001, BSI C5, IEC 62443, KRITIS) * Aufbau von Secrets-Management, Key Vault und Zero-Trust-Konzepten * Betreuung von Audit-Logging, SIEM und Incident-Response-Prozessen * Security-Reviews und Schulungen für das Entwicklerteam * Begleitung von Externen Security Audits und Penetration Tests ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Hacking Kubernetes: Live Demo Marathon](https://www.wearedevelopers.com/videos/488-hacking-kubernetes-live-demo-marathon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Finding Jobs in Germany](https://www.wearedevelopers.com/magazine/375-finding-jobs-in-germany) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Backend Developer Salary in Germany [2023]](https://www.wearedevelopers.com/magazine/196-backend-developer-salary-in-germany-2023)