> Markdown version of [/jobs/ext/1231225-principal-it-security-engineer](https://www.wearedevelopers.com/jobs/ext/1231225-principal-it-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal IT Security Engineer - **Company:** MY GAMES - **Location:** Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Bash Shell, Software as a Service, Cyber Security, Continuous Integration, Linux, Event Logging, Fraud Prevention and Detection, Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Systems Development Life Cycle, Phishing, Security Information and Event Management, Software Vulnerability Management, Ddos, Vulnerability Analysis - **Published:** July 11, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=346032db4d616ce0 ## About the Role * 5+ years of hands-on infosec experience - this isn't a purely strategic role; you're comfortable configuring and running security tools, digging into incidents, and analyzing infrastructure and code * Strong command of Linux, networking, and infrastructure - enough to independently track down and fix problems * Scripting and automation skills (Python, Bash, or similar) - you automate the routine instead of doing it by hand * A solid grasp of attack patterns, and the ability to read what's happening from logs, traffic, and configs * Practical experience in vulnerability management, incident response, and monitoring * Experience with SIEM, vulnerability scanners, and endpoint protection at the category level (we'll talk specific stack in the interview) * Working knowledge of recognized security frameworks and privacy requirements - as practical tools, not checkbox exercises * Ability to work autonomously, prioritize ruthlessly, and close out risks without a team standing behind you ## Description * Shape and evolve our risk-based security strategy and roadmap; own the risk register and drive risk-based prioritization * Develop and maintain security policies, standards, and procedures * Own and grow vulnerability management - detection, prioritization, remediation tracking, and regular scanning of infrastructure and applications * Build out security monitoring, detection, and event logging * Lead incident response: investigation, containment, post-mortems, and corrective actions * Secure our on-prem infrastructure (and cloud resources in hybrid setups) through hardening, network security, and endpoint protection * Manage access and account governance, including control over privileged access * Embed secure development practices into the SDLC and CI/CD; run threat modeling and advise teams on secure architecture for new services and features * Protect source code and intellectual property from leaks * Drive product security - player account protection, anti-fraud, and DDoS resilience * Ensure compliance with privacy requirements (GDPR and others) and operate within recognized frameworks (ISO 27001 / NIST CSF / CIS) * Assess risk from vendors, SaaS providers, and external teams * Run internal security trainings and phishing simulations, and help grow a strong security culture across engineering * Lead security's side of AI adoption - setting policy for AI tool usage and managing the risks that come with it * Manage security tooling, budget, and vendor relationships; coordinate external pentests and our bug bounty / VDP (Vulnerability Disclosure Program) * Report on security posture and metrics to leadership ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)