Information Security Engineer; f_m_x
Verfasst am 2026-10-01
-
IT/Informationstechnik
Cyber-Sicherheit, IT Consulting, Informationssicherheit & Datenschutz
The GFZ Helmholtz Centre for Geosciences is one of the world's leading institutions in the field of geosciences. As part of the Helmholtz Association, Germany's largest research organisation, we address global challenges such as natural hazards, climate change and the sustainable use of resources. In doing so, we combine cutting-edge research with social relevance. Our international staff – around 1,200 employees and approx.
500 guests – work in a multidisciplinary way and with a unique infrastructure to research the dynamic processes of the Earth system. Our vision: "Taking the pulse of the Earth to safeguard a habitable planet."
Reference Number 11444
GFZ has many years of experience in providing digital services to the international scientific community. This is built on an IT environment tailored to the requirements of scientific research settings, combining technical infrastructure, secure operations and sustainable service provision. Particular expertise lies in networking, identity and access management, and IT security.
Within the Helmholtz Federated IT Services (HIFIS), this experience is now to be transferred to further research fields. Together with the Helmholtz Centres, we are developing practical standards and implementation guidance that strengthen the cyber resilience of federated research IT.
For this purpose, we are looking for someone who combines technical understanding with security governance. The position reports to the Chief Information Security Officer (CISO) of GFZ and translates between technical and information security – both within GFZ and across the Helmholtz Association. The focus is on architectural assessment rather than depth in individual technologies.
Your Responsibilities- You develop technical minimum standards and reference architectures together with Helmholtz partners and support their implementation
- You assess architectures for protection requirements, threats and failure scenarios, and carry out architecture reviews
- You assess to what extent GFZ and the Helmholtz Centres are affected by the Cyber Resilience Act (CRA), derive the required implementation measures and advise software development teams
- You form the professional bridge to the CISO: you put technical matters into context and translate ISMS requirements into actionable specifications
- You contribute actively to handling IT security incidents and IT emergencies at GFZ and conduct emergency exercises
- You develop best practices and guidelines and prepare complex security topics in a way that suits the respective audience
Essential
Qualifications:
- Academic university degree (Master's degree or German university Diplom) in computer science, IT security or a comparable discipline
- Several years of experience in information security or security architecture, as well as the ability to assess IT architectures and to explain technical matters appropriately for the respective audience. Specialist depth in individual technologies is not required
- An understanding of modern IT architectures: data centre operations, virtualisation, network and cloud infrastructures
- Sound knowledge of the relevant standards and regulations (BSI IT-Grundschutz, ISO/IEC 2700x, NIS2, Cyber Resilience Act) and of IT emergency management in accordance with BSI Standard 200-4
- Very good communication and advisory skills when dealing with both technical and non-technical audiences;
German at level C2 and English at level C1 (CEFR), spoken and written
- Experience in the research, higher education or public sector, as well as with federated and open-source environments
- Experience in advising software development teams on…
(Wenn dieser Job tatsächlich in Ihrem Zuständigkeitsbereich liegt, verwenden Sie möglicherweise einen Proxy oder VPN, um auf diese Seite zuzugreifen. Um weiterzukommen, sollten Sie Ihre Verbindung zu einem anderen Mobilgerät oder PC wechseln).