Senior Security Engineer (m/w/d)
Senior Security Engineer (m/w/d)
Senior Security Engineer (m/w/d)
Senior Security Engineer (m/w/d)
Forteil GmbH - bonify
Bankwesen
Berlin
- Art der Beschäftigung: Vollzeit
- 77.500 € – 90.000 € (von XING geschätzt)
- Vor Ort
- Zu den Ersten gehören
Senior Security Engineer (m/w/d)
Über diesen Job
About us
Join bonify, Germany’s leading platform for credit scoring and financial management. We are on the mission to revolutionize the FinTech industry and make the credit score and financial data available and transparent for our users. We are seeking a talented Senior Security Engineer (m/w/d) to join our dynamic team in Berlin (full remote possible).
At bonify, Information Security is structured into three closely collaborating areas:
- Product Security (security-by-design, SDLC, pre/post pentests, product-focused controls)
- Corporate Security (this role) (security operations & protection of corporate infrastructure and workforce)
- Office of the CSO (Governance, Risk & Compliance, security strategy and company-wide accountability)
Your tasks
As our Senior Security Engineer (m/w/d), you will take ownership of key corporate security capabilities and day-to-day operational resilience, including:
- Vulnerability & Patch Management
- Security Tooling, Configuration & Monitoring
- Incident Response & Forensics
- Identity, Endpoint & Access Security (Corporate Environment)
- Security Awareness & Phishing Program
- Physical Security
Requirements
- 5-7 years of hands-on experience in corporate security / security operations / blue team / SecOps, with a strong ability to work independently and drive topics end-to-end.
- Solid understanding of:
- Incident response lifecycle, investigation methods, and operational security fundamentals
- Vulnerability management (risk-based prioritization, remediation coordination, validation)
- Endpoint, identity, and email security concepts in modern organizations
- Practical experience working with and improving enterprise security tooling—ideally within the Microsoft security ecosystem.
- Strong communication skills: you can clearly explain risk and response actions to both technical and non-technical stakeholders.
- A structured, pragmatic mindset: you prioritize impact, build repeatable processes, and create clarity during incidents.
Experience
- Microsoft E5 security suite components (e.g., Defender capabilities, identity protection patterns, policy hardening, alert tuning)
- Log analysis, detection engineering basics, and monitoring concepts (including writing queries and building dashboards)
- Email security incidents (phishing, BEC patterns), endpoint investigations, and account compromise response
- Operating vulnerability scanners, managing remediation backlogs, and building reporting/KPIs
- Scripting/automation for security operations (e.g., PowerShell, basic automation workflows)
- Working with external providers (MDR/SOC, incident response retainers, penetration test providers for corporate assets)
Cloud and SaaS security fundamentals (access control, misconfiguration risk, audit logging) - Developing and maintaining security runbooks, playbooks, and operational documentation
Nice to have
- Written and spoken German language skills
- Experience in regulated environments (FinTech, banking, credit, or highly sensitive personal data contexts)
- Familiarity with ISO 27001 and DORA-oriented controls in practice (e.g., translating policy requirements into technical operations)
- Relevant certifications: Microsoft Security (e.g., SC-200 / SC-300), GIAC (e.g., GCIH / GCFA / GNFA), CompTIA Security+, CISSP (or equivalents)
What we offer
As part of the bonify team, you'll have:
- The opportunity to take ownership from day one
- The chance to thrive in a dynamic and flexible startup environment.
- Access to extensive coaching and training programs through our personal development budget
- 30 vacation days
- Mental health platform
- Subsidies for BVG and UrbanSportsClub / ClassPass
- 1:1 language classes in both German and English.
The Company is committed to the principle that no employee or job applicant shall receive unfavorable treatment on grounds of age, disability, gender reassignment, race, religion or belief, sex, sexual orientation, marriage or civil partnership, pregnancy, and maternity.
If you're ready to make a meaningful impact in the world of FinTech and embark on an exciting career journey, apply now to join bonify!
