Senior Cyber Security Engineer
Enpal
Seniority
Senior
Model
In-Office
Sector
Salary
Undisclosed
Contract
Full-Time
About the role
We are looking for a Senior Cyber Security Engineer to join our CISO organization. In this role, you are the person who takes ISO 27001, NIS2, and KRITIS requirements off the page and turns them into real work assessing our actual systems, finding where we fall short, collecting evidence, and making sure gaps get closed.
What you'll do
- Build secure solutions adopting Shift-Left and Zero-Trust approaches in all our units.
- Break down ISO 27001, NIS2/BSIG, and KRITIS into concrete, prioritized actions and develop solutions or coordinate with CTO and IT teams.
- Go hands-on across Azure, Entra ID, M365, Intune, Defender XDR, AKS, Terraform, CI/CD pipelines, and Datawarehouse to find gaps.
- Develop solutions that close gaps, respond to cyber security incidents, and create plans to prevent future occurrences.
- Use AI tooling to automate evidence collection, speed up gap analysis, and generate structured audit documentation.
- Track findings, coordinate with technical owners, escalate blockers, and verify that fixes hold.
- Make regulatory requirements understandable for technical teams and security requirements understandable for everyone else.
What you'll need
- 5+ years of experience in cyber security or a technical compliance role in a cloud-first environment.
- Technical fluency across Azure, Entra ID, Microsoft 365, Intune, and Defender, and comfort with Kubernetes, IaC, Terraform, CI/CD, and APIs.
- Experience with security tooling and automation across domains like SAST, SCA, DAST, CNAPP, CWPP.
- Insights on what ISO 27001:2022, NIS2/BSIG, and KRITIS require.
- Daily use of AI tools and knowledge of how to apply them to compliance and security operations.
- Clear English communication, spoken and written.
- Security-first mindset and appreciation for developer experience.
Nice to have
- Knowledge of German language, BSI-Grundschutz, and BSI C5.
- Certifications like CISSP, OSCP, CISM, CRISC, AZ-500, SC-100, GCIH, or OSIR.
What they offer
- The chance to shape security at Germany's first green unicorn and make a real dent in climate change.
- A team of 65+ nationalities that is smart, driven, and genuinely collaborative.
- On-site in Berlin-Friedrichshain with modern office, height-adjustable desks, table tennis, and barista coffee.
- Real ownership from day one with short decision paths and open feedback culture.
- 29 + 2 vacation days, Wellhub membership, and corporate benefits.

