Infrastructure Security Analyst in Berlin
Berlin
Please apply here on „ITbbb.de“ with the „Apply Now“ link/button at the top right.
- Ensure that infrastructure events and changes related to information security are timely reviewed
- Quickly review infrastructure events that impact information security, like access to customer data, to be in line with internal policies
- Quickly review infrastructure changes that impact information security, like a change in firewall rules or introduction of a new SaaS solution or open source component, to be in line with internal policies
- Work with Security Engineers to automate reviews where possible
- Ensure that infrastructure security incidents are quickly contained
- Quickly perform a first assessment on infrastructure security incidents, including reported vulnerabilities from several sources (IDS, WAF, vendors of third party dependencies, penetration tests), regarding their risk and derive next actions
- Ensure that security aspects are well reflected in infrastructure risk assessments
- Support security readiness assessments for new infrastructure services or after major changes
- Support annual and ad-hoc risk assessment workshops with Infrastructure team members to identify and mitigate infrastructure related security risks for existing systems and during the design of new services
- Monitor treatment of risks and support continuous improvement of the maturity of the infrastructure security program to reduce security related risks
- Ensure security awareness among Infrastructure engineers (SREs)
- Maintain information security and data privacy training program and train infrastructure engineers on information security and data privacy with respect to their infrastructure engineers function
- Rensible for successful internal and external security audits and due diligences
- Coordinate pentests from infrastructure perspective
- Perform internal infrastructure security audits
- Support maintaining the documentation of the infrastructure security in our Control register and security assurance documents
- Coordinate table-top exercises for infrastructure team, covering scenarios like disaster recovery, data breaches, or cyber attacks
- Attend internal and external audits and due diligence activities to demonstrate evidences of current practices related to infrastructure security
- Information Security Knowledge: Concepts of information security (confidentiality, integrity, availability, etc.) and their implementation options (encryption, identity and access management, backups, redundancy & high availability, network configuration)
- Knowledge of modern application architecture
- Knowledge of modern infrastructure
- Analytical, detail oriented and creative problem solving skills
- Strong written and verbal communication skills in English
- Information security risk management incl. threat modeling
- ISO 27001 Implementation Knowledge
- Internal Auditor Experience
- Data Privacy / GDPR Knowledge
- Knowledge and experience with a programming language (e.g. Python)
- Mambu has over 250+ live deployments, helping to revolutionise financial services in more than 46 countries globally, and we're just getting started;
- We understand nothing ensures our customers' success more than a happy team, so Mambu is built on a culture of trust and a sense of ownership in everything we do;
- Mambu proactively takes the initiative to improve the industry for the better;
- Mambu is using top tool for development activities;
- Because you want more, you want to know how your lines of code impact the world.
Brief profile of Mambu
Die MAMBU GmbH hilft FinTech-Innovatoren, Banken und Mikrofinanzinstituten essentielle Bankdienstleistungen auf der ganzen Welt anzubieten. Dafür stellt MAMBU diesen Finanzinstituten zur Verwaltung ihrer Kunden-, Konten- und Transaktionsdaten eine erstklassige Software as a Service Plattform zur Verfügung.
Spheres of competence
IT architectJavaSaaSsystem administrator
Job
Application Security Engineer
BerlinTechnical Auditor
BerlinInformation Security Officer
BerlinJunior Accountant
BerlinUX Designer
Berlin
Publication date: 11-11-2020