Login Enter

IONOS SE

8 hours ago

Cyber Security Engineer — Infrastructure & AI Platform Security (m/f/d)

Sign up free Log in

Sign up to save this job, get alerts, and apply with an optimized CV.

Company information

Company
IONOS SE
Location
Karlsruhe Germany
Posted
8 hours ago
View all jobs at IONOS SE

Job description

About IONOS

At IONOS, we don't just manage servers, we shape the digital future for over 6.2 million customers worldwide with our solutions. As Europe's leading hosting provider and pioneer for independent cloud solutions, we are building a next-generation infrastructure: from sovereign cloud architectures and high-performance GPU clusters to integrated AI automation tools.

What drives us: Digital decision-making freedom for Europe and real impact for small and medium-sized enterprises (SMEs) and large corporations. We work in agile teams, rely on transparent structures, and believe that excellence and innovation can only arise with true team spirit.

Ready for your next step? Become a part of IONOS and grow with us.

Both halves of this role revolve around the same fundamental question: Which systems can access our most sensitive infrastructure and under what controls. You will take responsibility for the security architecture of our provider-side infrastructure layer and be the expert (m/f/d) for internally operated AI platforms and agents. You will ensure that these run in a secure, managed, and auditable state, rather than stealthily accumulating as a new class of privileged access.

This is a hands-on expert role. You set standards, scrutinize designs, and work directly with platform and engineering teams across all our brands to implement them.

Areas of Responsibility

Infrastructure Security

  • Defining and maintaining security architecture standards and hardening baselines for provider-side infrastructure: virtualization and container platforms, control planes and deployment systems, DNS, mail infrastructure, and backup and recovery systems.
  • Assessing and strengthening tenant isolation across shared hosting, virtualization, and container layers, and driving remediation measures with the responsible platform teams.
  • Reviewing infrastructure designs and significant changes for security implications, and acting as an escalation point for infrastructure security questions from platform, cloud, and brand engineering teams.
  • Reducing the blast radius on critical paths: privileged access to customer-facing infrastructure, administrative segmentation, secrets management, and recovery integrity — translated into actionable, brand-specific implementation plans for our heterogeneous platforms.
  • Supporting Cyber Defense, Vulnerability Management, and IT Disaster Recovery with infrastructure expertise during incidents and post-incident remediation/hardening.

Internal AI Platform and Agent Security

  • Responsibility for the security architecture and baseline standards for internally operated AI platforms: model gateways and self-hosted models, agent frameworks, assistant integrations, connectors, and retrieval pipelines across internal data.
  • Defining and enforcing how agents are identified, authenticated, and authorized: handling non-human identities, credential and token management, least privilege access to tools and systems, and determining where autonomous actions require a human-in-the-loop.
  • Defining which data internal AI systems may call and index, and ensuring that agent activities are logged, attributable, and auditable — in accordance with our regulatory obligations and certifications.
  • Conducting pre-deployment security reviews for new internal AI platforms and agent use cases in line with the rapid pace of adoption, and overseeing unsecured/unsanctioned AI usage (Shadow AI).
  • Advising security functions and internal engineering teams on the secure adoption of AI, including the guardrails that enable responsible adoption.

Qualifications

  • Several years of practical experience in infrastructure or platform security, ideally with a hosting provider, cloud provider, telecommunications company, or in a comparably large multi-tenant environment.
  • Deep practical knowledge of Linux, virtualization and container platforms, networks, and the security properties of multi-tenant infrastructures.
  • Strong background in Identity & Access: Privileged Access, machine and workload identities, secrets management, authorization models, and Infrastructure-as-Code security.
  • Experience in developing and enforcing security standards in a heterogeneous, partly legacy landscape, and in gaining acceptance from teams outside of one's own reporting line.
  • Practical knowledge in building and operating LLM and agent systems, as well as their specific risks: prompt injection through untrusted data, overly broad tool access, data exposure through retrieval, unlogged autonomous actions, model and provider dependencies.
  • Ability to make and defend risk-based decisions — including blocking deployments with clear justification — and to explain technical risk understandably to non-technical stakeholders.
  • Fluent English skills; German language skills are a strong advantage due to our regulatory environment and public sector business.

Desirable / Advantageous

  • Practical experience deploying or securing internal AI platforms, agent frameworks, or tool-calling integrations in a production environment.
  • Familiarity with NIS2 / BSIG or ISO 27001.
  • Background in DNS, email infrastructure, or platform-adjacent abuse prevention.
  • Experience in a multi-brand or post-acquisition environment where the same controls must be implemented across different implementations.
  • Background in Security Engineering or Software Development (automation, tooling, scripting).

Who fits with us

Someone who is comfortable being the only expert in the room on certain issues, who prefers to fix root causes rather than just document findings, and who can operate across security functions and platform teams. You should have a genuine interest in AI systems as engineering artifacts, not just as a compliance topic — a large part of this practice is still emerging, and you will help shape ours.

Benefits

  • Hybrid working model.
  • Flexible working hours through trust-based working time.
  • Subsidized canteen and various free drinks at some locations.
  • Modern office spaces with excellent public transport connections.
  • Various employee discounts for activities and products.
  • Employee events such as summer and winter parties, as well as workshops.
  • Numerous further training and development opportunities.
  • Various health offerings, such as sports and health courses.

Note on Application

We value diversity and welcome all applications – regardless of, for example, gender, nationality, ethnic and social origin, religion, disability, age, or sexual orientation and identity, physical characteristics, marital status, or any other irrelevant criterion according to applicable law.

Required skills

Interested in this position?

Create your free account and tailor your CV to match this job.