Responsibilities
- Safeguard systems and cloud platforms by proactively assessing threats, applying current security frameworks, and protecting critical infrastructure.
- Develop and refine security policies, standardize procedures, and ensure organization-wide implementation and adherence.
- Lead initiatives to increase security awareness through training, workshops, and ongoing communication across departments.
- Manage incident and risk response by detecting threats early, coordinating resolution, analyzing outcomes, and refining response protocols.
- Support compliance with industry standards such as PCI, ISO, and NIS2 by preparing for audits and guiding teams through regulatory requirements.
- Oversee key security controls by evaluating critical components, supporting monitoring efforts, and maintaining visibility into security events.
- Partner with Product, IT, and Engineering teams to design secure systems, reduce vulnerabilities, streamline processes, and support scalable architecture.
- Strengthen secure software development by advancing SSDLC practices, guiding teams on security integration, and embedding security reviews into workflows.
Requirements
- Demonstrated ability to detect security risks early and develop proactive solutions.
- Solid understanding of software, infrastructure, and cloud system interactions.
- Strong interest in evaluating the security posture of systems, services, and processes.
- Advanced analytical skills for assessing vulnerabilities and security incidents.
- Excellent communication abilities, with a talent for translating technical risks into clear, accessible language.
- Familiarity with cloud platforms such as GCP or AWS and automated workflows like CI/CD pipelines.
Nice to Have
- Hands-on experience with compliance frameworks including ISO 27001, PCI DSS, or NIS2.
- Background in security testing methods such as SAST, DAST, or vulnerability scanning.
- Knowledge of secure development and cloud security practices, including IAM and risk management.
- Experience using security tools like SIEM, SSO/MFA, audit systems, and policy enforcement mechanisms.
Benefits
- Option to work remotely or in partner coworking spaces up to three days per week, with reliable internet access required.
- Ongoing professional development opportunities.
- Stability of a profitable German tech company funded by product success, not external investors.
- Teams focused on outcomes with a culture of direct, constructive feedback.
- Provision of modern work equipment: MacBook.
- Collaborative, international team environment with strong team cohesion.
- Annual team events held in various European locations.
- High level of autonomy from the start.
- Informal workplace culture: first-name basis, no dress code, and equal collaboration.
- Flexible working hours during weekdays (Monday to Friday).
Work Arrangement
Remote (Worldwide)
Team
200-person team with members from over 40 countries, united by a shared vision and operating in a collaborative, autonomous environment.
Your typical day at Digistore24
- Monitor and analyze security alerts, logs, and system notifications to initiate timely responses.
- Work on security improvements including SSDLC enhancements, risk assessments, policy updates, and cloud security hardening.
- Respond to reported security incidents by analyzing impact, evaluating risks, and helping implement long-term fixes.
- Contribute to projects such as policy creation, compliance readiness, vulnerability tracking, and enterprise-wide awareness campaigns.
This position is NOT for you if…
- You are not motivated to detect and reduce security risks.
- You find structured, analytical work and forward-looking planning challenging.
- You are not committed to continuous learning in the evolving field of IT security.
- You prefer not to work independently on high-priority security initiatives.
- You avoid direct confrontation, as security often requires openly addressing risks.
- You are uncomfortable working in a multicultural, international environment.
- You do not align with the company's core values.