← Todos los puestos
MeJuvante GmbH · IT Security
Associate Consultant Information Security & Cyber Resilience (m/f/d)
Sobre el puesto
You support the review and assessment of security policies and controls, implement and operate information security and cyber resilience controls and tools, contribute to red team exercises and resilience strategies, and handle the detection, analysis of and response to cyber incidents. Sector: financial market infrastructure and payments. Engagement: long-term framework contract, with assignments called off per project. On-site in Frankfurt am Main per assignment, partial remote possible.
Responsabilidades
- Review and assess security policies, controls and change requests
- Evaluate the impact of changes on operational and cyber risks
- Implement and operate information security and cyber resilience controls and tools
- Support the organisation, planning and risk management of red team exercises
- Detect, analyse and respond to security incidents
La IA se encarga · Tú te encargas
La IA se encarga
First drafts of control assessments and review notes · Log correlation and evidence gathering for incident timelines · Cross-references between controls and regulatory frameworks · Test documentation and report scaffolding
Tú te encargas
The security judgement behind every assessment · The call on whether a change is safe to approve · What gets escalated during an incident, and when · The integrity of test findings
Tu perfil
- Assessment of security policies, controls and change requests
- Impact evaluation on operational and cyber risk
- Implementation and operation of security tooling such as SIEM, EDR and vulnerability management
- Support to red team exercises
- Incident detection, analysis and response
Titulación
- At least 2 years reviewing and assessing policies, controls and change requests from an information security and cyber resilience perspective
- Hands-on experience with red team or penetration testing engagements
- At least 2 years implementing and operating security controls and tools, for example SIEM, EDR and vulnerability management
- At least 2 years developing and implementing cyber resilience strategies
- Experience in incident management and response, covering detection, analysis and reaction
- Business-fluent English
- Willingness to undergo security screening for on-site work
- Desirable: knowledge of financial-sector systems including Distributed Ledger Technology (DLT)
- Desirable: experience with major European payment or settlement infrastructures
- Desirable: knowledge of incident response frameworks and experience coordinating incidents