Skip to content

Cyber Security Engineer (f/m/d) Infrastructure & AI Platform Security

IONOS SE
IT Security
Karlsruhe
Full-time
I-1613

About IONOS SE

At IONOS, we don't just manage servers – we shape the digital future for more than 6.2 million customers worldwide with our solutions. As Europe's leading hosting provider and a pioneer in independent cloud solutions, we are building next-generation infrastructure – from sovereign cloud architectures and high-performance GPU clusters to integrated AI automation tools. What drives us is digital sovereignty for Europe and real impact for small and medium-sized businesses (SMBs) as well as large enterprises. We work in agile teams, rely on transparent structures, and believe that excellence and innovation only emerge through true team spirit. Ready for your next step? Become part of IONOS and grow with us.

To the company page
United Internet Office Building

Tasks

Both halves of this role are about the same underlying question: which systems can reach our most sensitive infrastructure, and under what controls. You will own the security architecture for our provider-side infrastructure layer, and you will be the subject matter expert for the AI platforms and agents we operate internally, making sure they run in a secure, governed, auditable state rather than accumulating quietly as a new class of privileged access.

This is a hands-on expert role. You set standards, pressure-test designs, and work directly with platform and engineering teams across our brands to get them implemented.

Internal AI platform and agent security

  • Define and maintain security architecture standards and hardening baselines for provider-side infrastructure: virtualization and container platforms, control planes and provisioning systems, DNS, mail infrastructure, and backup and recovery systems.
  • Assess and strengthen tenant isolation across shared hosting, virtualization, and container layers, and drive remediation with the responsible platform teams.
  • Review infrastructure designs and major changes for security impact, and act as an escalation point for infrastructure security questions from platform, cloud, and brand engineering teams.
  • Reduce blast radius on the paths that matter most: privileged access to customer-facing infrastructure, administrative segmentation, secrets handling, and recovery integrity — translated into workable per-brand implementation plans across our heterogeneous platforms.
  • Support Cyber Defense, Vulnerability Management, and IT Emergency Management with infrastructure expertise during incidents and post-incident hardening.

Infrastructure security

  • Own the security architecture and baseline standards for the AI platforms we run internally: model gateways and self-hosted models, agent frameworks, assistant integrations, connectors, and retrieval pipelines over internal data.
  • Define and enforce how agents are identified, authenticated, and authorized: non-human identity handling, credential and token management, least-privilege tool and system access, and where autonomous action requires a human in the loop.
  • Establish what data internal AI systems may access and index, and ensure agent activity is logged, attributable, and reviewable to the standard our regulatory and certification obligations require.
  • Run pre-deployment security reviews for new internal AI platforms and agent use cases, at a pace that fits how fast these are being adopted, and keep a picture of where unsanctioned AI usage is emerging.
  • Advise the security functions and internal engineering teams on adopting AI safely, including the guardrails that make that adoption defensible.

Qualifications

  • Several years of hands-on experience in infrastructure or platform security, ideally at a hosting provider, cloud provider, telco, or comparably large-scale multi-tenant environment.
  • Deep practical knowledge of Linux, virtualization and container platforms, networking, and the security properties of multi-tenant infrastructure.
  • Strong background in identity and access: privileged access, machine and workload identity, secrets management, authorization models, and infrastructure-as-code security.
  • Experience designing and enforcing security standards in a heterogeneous, partly legacy landscape, and getting them adopted by teams you do not manage.
  • Working knowledge of how LLM and agent systems are built and operated, and of the risks specific to them: prompt injection through untrusted data, over-scoped tool access, data exposure via retrieval, unlogged autonomous action, model and provider dependency.
  • Ability to make and defend risk-based decisions, including blocking a deployment with a clear rationale, and to explain technical risk to non-technical stakeholders.
  • Fluent English; German is a strong advantage given our regulatory and public-sector environment.

Nice to have

  • Hands-on experience deploying or securing internal AI platforms, agent frameworks, or tool-calling integrations in production.
  • Familiarity with NIS2 / BSIG or ISO 27001
  • Background in DNS, e-mail infrastructure, or abuse-adjacent platform security.
  • Experience in a multi-brand or post-acquisition environment where the same control has to land in several different implementations.
  • Security engineering or development background (automation, tooling, scripting).

Who fits

Someone comfortable being the only expert in the room on a given question, who prefers fixing root causes over filing findings, and who can operate across security functions and platform teams they do not control. You should be genuinely interested in AI systems as engineering artifacts, not just as a policy topic — much of this practice is still being written, and you will be writing ours.

Benefits that make a difference

As an employer, United Internet offers interesting roles with exciting projects, personalized development opportunities and excellent career prospects.

Culture

Our working environment is characterized by flat hierarchies and short decision-making processes. We encourage a positive approach to learning from mistakes and open feedback!

Mobility

To support sustainable and flexible mobility, we provide our employees with attractive benefits packages. For example, through JobRad, you can lease your ideal bike on attractive terms. We also provide a financial subsidy for this offer. Alternatively, you can use public transport and benefit from a subsidy towards the Deutschlandticket.

Events

We celebrate our successes as a team: at United Internet, we throw legendary parties. And our varied workshops and team events foster a special sense of camaraderie.

Flexible Working

Many of our roles allow for remote working from home and flexible working hours.

Pension and health

Our employees benefit from attractive pension schemes. These include modern financial security options that support wealth accumulation. Our health and fitness programmes, covering topics such as ergonomics, exercise and nutrition, round off the package. The aim is to provide a working environment in which all colleagues can not only develop professionally but are also well-positioned for their personal future. 

Discounts

Our employees benefit from a wide range of discounts on our Group’s products and services, for example in the form of discounted broadband and mobile phone contracts. In addition, we offer exclusive price advantages for selected leisure and partner offers.

A wide range of training opportunities

Strengths are individual – and that is a good thing! Our wide range of development programmes offers excellent opportunities for personal and professional growth. From e-learnings to trainings, conferences and mentoring – we learn from, for and with one another to grow together.

Technology

To provide our employees with a productive and comfortable working environment, we rely on state-of-the-art technology. This includes high-performance hardware, ergonomic accessories and the latest software tools for efficient collaboration.

Our benefits in detail

  • Hybrid working model.
  • Flexible working hours through trust-based working hours.
  • At some locations a subsidized canteen and various free drinks.
  • Modern office space with very good transport connections.
  • Various employee discounts for activities and products.
  • Employee events such as summer and winter parties, as well as workshops.
  • Numerous training and development opportunities.
  • Various health offers, such as sports and health courses.

Join our team

United Internet offers diverse opportunities for people who want to help shape the digital future. Those who want to contribute their strengths and grow in an innovative environment will find the right place with us.

apply online now

Two colleagues in the office
WORK UNITED.
 

Diversity enriches. Different cultures, nationalities, genders, ages, sexual orientations and religions as well as people with disabilities - we value diversity and encourage it. Because only teams that reflect all facets of society offer the best environment for creativity and make a company productive and distinctive. We value diversity and welcome all applications.

Contact

Questions?

IONOS SE
Recruiting Team IONOS

Hinterm Hauptbahnhof 3-5
D-76137 Karlsruhe
jobs@ionos.com

Please submit your application exclusively through our easy-to-use online application form. This allows us to ensure a transparent application process while maintaining full compliance with all applicable data protection regulations. Unfortunately, we are unable to accept applications submitted via email for the reasons outlined above.