> Markdown version of [/jobs/ext/2278354-security-engineer-iam](https://www.wearedevelopers.com/jobs/ext/2278354-security-engineer-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer IAM - **Company:** And-e - **Location:** Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Cloud Computing, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), OpenID, Windows PowerShell, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Software Vulnerability Management, Cloud Platform System, Cyberark, Mitre Att&ck, Cyber Threat Analysis, Fortinet, SailPoint, Splunk, Cisco - **Published:** August 28, 2026 - **Apply:** https://www.stepstone.de/stellenangebote--Senior-Security-Engineer-IAM-m-f-d-Ismaning-AND-E--14434713-inline.html ## About the Role * Bachelor's degree in IT Security, Cyber Security, or comparable qualification (or equivalent practical experience). * 5+ years in IT security engineering or operations, with significant hands-on IAM responsibility. * Deep expertise in Entra ID, Active Directory, MFA/passwordless, SSO protocols (SAML, OIDC, SCIM), and identity governance. * Strong foundation in zero-trust architecture and frameworks such as NIST, ISO 27001, or MITRE ATT&CK. * Working knowledge of Splunk Cloud SIEM, CyberArk, SailPoint IdentityIQ,and Cribl Stream/Edge. * Familiarity with AWS, Proofpoint, and Zscaler/Cisco/FortiGate. * Proficiency in PowerShell, Python, or Microsoft Graph API. * Very good English communication skills (German desirable). * Certifications such as Microsoft SC-300, SC-100, AZ-500, CISSP, CIDPRO, AWS Security Specialty, GIAC (GCIH, GCIA, GCFA), or Splunk/Cribl are considered a plus. ## Description Your heart beats for identity and access management, and you're driven by the mission to minimize digital risks and build trust? You enjoy turning complex security requirements into practical, actionable controls? A supportive culture, strong teamwork, and continuous development matter just as much to you as technical expertise? Then welcome to AND-E. How you'll make an impact * Own IAM strategy across Entra ID and Active Directory. * Manage conditional access, PIM/PAM, and identity lifecycle governance. * Develop identity-centric detections and threat-hunting workflows, analyzing Entra ID logs and privilege escalation paths in alignment with the SOC. * Partner with Infrastructure, Client Services, and Cloud Admin teams to review and implement controls across endpoint, email, network, and cloud environments. * Act as internal advisor for Splunk Cloud SIEM and Cribl Stream/Edge, partnering with the MSSP on detection engineering and optimization. * Oversee vulnerability management and quality-assure penetration tests. * Serve as senior escalation point for complex SOC investigations. * Mentor SOC analysts and junior engineers. * Contribute to the long-term security roadmap. * Keep leadership informed on risks and developments and maintain clear architecture and process documentation. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)