Endpoint Security Engineer - OT

ZEISS Group
Oberkochen, Germany
25 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Python (Programming Language) Network Segmentation Windows PowerShell Runbook Scripting Malware CIS Benchmarks

Job description

  • Deploy, configure and operate TXOne Stellar, Malware Check Stations (MCS) and related OT endpoint security components across global manufacturing sites
  • Maintain and continuously improve hardened security baselines for OT endpoints, including legacy OS, resource constrained devices, and production critical clients
  • Integrate OT endpoint telemetry, health checks and alerts into central monitoring, dashboards and ITSM systems; automate routine tasks (packaging, updates, remediation)
  • Investigate, troubleshoot and resolve OT endpoint security incidents; perform root-cause analysis and define preventive measures
  • Ensure policy consistency, allow/deny list management, signature tuning and stable operation in production environments
  • Collaborate with internal OT/IT stakeholders, production teams, and external integration partners to support rollout, upgrades and lifecycle management
  • Maintain service documentation (runbooks, architecture diagrams, SOPs) and support compliance, audit readiness and continuous improvement initiatives
  • Contribute to the overall OT security roadmap and alignment with Defender/XDR initiatives

Requirements

  • Hands-on experience with TXOne Stellar, Portable Inspectors, Malware Check Stations, and similar OT focused endpoint security solutions
  • Strong understanding of OT environments, including legacy operating systems, network segmentation, production constraints, and safety considerations
  • Good knowledge of endpoint security fundamentals: AV/EDR, application control/whitelisting, removable media governance, policy and signature tuning
  • Scripting/automation experience (PowerShell, Python or similar) for telemetry, packaging, and operational efficiency
  • Familiarity with Microsoft Defender ecosystem (MDE, XDR) and ITSM processes (Incident, Problem, Change)
  • Strong troubleshooting skills and the ability to work effectively with production teams and external providers
  • Excellent communication skills in English, with the ability to collaborate across global teams
  • Working experience in multinational manufacturing or regulated OT environments

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on de.indeed.com

Inside ZEISS Group

Culture, engineering, and team stories

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all