Team Lead - Application Security Team
MOIA
Seniority
Senior
Model
Remote
Sector
Salary
Undisclosed
Contract
Full-Time
About the role
The Application Security (AppSec) team is part of MOIA's Platform Engineering organization and contributes directly to our secure-by-design approach. You will lead and drive MOIA's cloud-based security projects and programs, serving as a strategic leader within the AppSec team while maintaining hands-on involvement in key security initiatives.
What you'll do
- Lead and drive MOIA's cloud-based security projects and programs in their implementation, ensuring compliance with relevant standards and maintaining a strong security posture across the organization.
- Support certification initiatives such as ISO 27001 and TISAX, preparing documentation and enabling audit activities for successful readiness.
- Identify security gaps and risks, align with internal teams to define remediation actions, and continuously improve our security controls and processes.
- Collaborate closely with Digital Workplace/IT, engineering, and compliance teams to integrate security principles into cloud and software development workflows.
- Lead and establish Security Monitoring activities, ensuring a good proactive posture, proper incident response and investigation, as well as derived hardening measures.
- Shape MOIA's strategic Cloud Cybersecurity roadmap and align it with Vehicle Cybersecurity initiatives.
- Promote secure and responsible use of AI across development workflows, enabling teams to innovate safely and confidently.
What you'll need
- Proven experience in leading teams or people within cybersecurity or related technology domains, fostering collaboration and accountability.
- Understanding of information security frameworks (e.g., ISO 27001, TISAX, NIS2) and hands-on experience with audits and/or certifications.
- Strong expertise in cloud security (AWS or GCP), combined with a strategic mindset to align cloud and vehicle cybersecurity domains.
- Practical experience in security operations, including incident handling and response management.
- Excellent communication and stakeholder management skills, both with internal teams and external partners.
- Ability to balance strategic thinking with hands-on implementation in a fast-moving, cross-functional environment.
- Ability to communicate fluently and effectively in English.
Nice to have
- Familiarity with AI technologies and enthusiasm for enabling secure AI adoption.
- Good knowledge of application security frameworks and methodologies (e.g. OWASP Top 10, OWASP SAMM).
- German language skills.
What they offer
- Competitive salary including bonus
- Hybrid work setup with flexibility to work from home or offices
- 30 vacation days, sabbatical and unpaid leave option
- Learning environment with continuous learning days, trainings, conferences, and language classes
- Mental health support and wellness benefits
- Relocation support and fully subsidized public transport ticket
