Isar Aerospace is a Munich-based aerospace company developing the Spectrum orbital launch vehicle and commercial launch services.
<p><strong><span lang="EN-US">Mission Brief </span></strong></p> <p><span data-contrast="auto">You are the guardian and the challenger of our security posture. At Isar Aerospace, the systems that build our rockets are mission critical, and protecting them takes more than good design. It takes someone who will attack their own work to be sure it holds.</span><span data-ccp-props="{"335559739":80}"> </span></p> <p><span data-contrast="auto">We are looking for a deeply hands-on Senior Security Architect. You will be in the environment, building and testing our defenses yourself, not directing from the sidelines. You wear two hats: the Defender who designs and operates the controls that keep us safe, and the Adversary who continuously attacks those controls the way a real threat would. You own your work end to end and turn what you find under attack into stronger defenses, sharper detection, and faster response.</span><span data-ccp-props="{"335559739":80}"> </span></p> <p><span data-contrast="auto">This is a senior role with one of the broadest mandates on the team. You are the kind of expert who can pick up almost anything we throw at you, from architecture to incident response to offensive testing, and go deep where it matters. A versatile generalist with real depth, not a narrow specialist, and a technical anchor others lean on.</span><span data-ccp-props="{"335559739":80}"> </span></p> <p><span class="TextRun SCXW114497174 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun CommentStart CommentHighlightPipeRest CommentHighlightRest SCXW114497174 BCX8">Your Role in Our Space Mission</span><span class="NormalTextRun CommentHighlightRest SCXW114497174 BCX8">:</span></span><span lang="EN-US"><span class="EOP CommentHighlightPipeRest SCXW114497174 BCX8" data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}"> </span></span></p> <ul> <li><strong><span data-contrast="auto">Design the Defense: </span></strong><span data-contrast="auto">Lead the design and implementation of security architecture across our systems, networks, and applications, building in resilience from the start.</span><span data-ccp-props="{"335559739":80}"> </span></li> <li><strong><span data-contrast="auto">Attack What We Build: </span></strong><span data-contrast="auto">Run realistic adversary emulation and attack-path analysis against our own environment, prove whether our controls and detections actually fire, and convert every finding into a fix, a new detection, or a hardened design.</span><span data-ccp-props="{"335559739":80}"> </span></li> <li><strong><span data-contrast="auto">Own the Detection: </span></strong><span data-contrast="auto">Develop and operationalize our detection and response capability, tune monitoring to separate signal from noise, and keep our coverage honest against how attackers actually operate.</span><span data-ccp-props="{"335559739":80}"> </span></li> <li><strong><span data-contrast="auto">Direct the MSSP: </span></strong><span data-contrast="auto">Own the technical relationship with our managed security provider. Set the detection and use-case backlog, hold them to escalation and response-quality standards, run service reviews, and make sure we get the protection we pay for.</span><span data-ccp-props="{"335559739":80}"> </span></li> <li><strong><span data-contrast="auto">Lead the Response: </span></strong><span data-contrast="auto">Develop and maintain incident response plans, and lead the handling of incidents from day-to-day alerts through to high-profile events.</span><span data-ccp-props="{"335559739":80}"> </span></li> <li><strong><span data-contrast="auto">Hunt and Reduce Risk: </span></strong><span data-contrast="auto">Run risk and vulnerability assessments across business-critical infrastructure, then work with stakeholders to prioritize and close the gaps that matter most.</span><span data-ccp-props="{"335559739":80}"> </span></li> <li><strong><span data-contrast="auto">Stay Ahead of the Threat: </span></strong><span data-contrast="auto">Track emerging threats and tactics, and use threat intelligence to anticipate how an adversary would target us and harden accordingly.</span><span data-ccp-props="{"335559739":80}"> </span></li> <li><strong><span data-contrast="auto">Embed Security with Engineering: </span></strong><span data-contrast="auto">Partner with IT and engineering teams to implement and validate controls, and produce clear documentation and standards others can execute against.</span><span data-ccp-props="{"335559739":80}"> </span></li> </ul> <p><strong><span lang="EN-US"><span class="EOP CommentHighlightPipeRest SCXW114497174 BCX8" data-ccp-props="{"201341983":0,"335551550":6,"335551620":6,"335559740":360}">Qualification Checklist </span></span></strong></p> <ul> <li><strong><span data-contrast="auto">Experience: </span></strong><span data-contrast="auto">10+ years in information security, with hands-on depth across both defending and attacking systems.</span><span data-ccp-props="{"335559739":70}"> </span></li> <li><strong><span data-contrast="auto">Dual Mindset: </span></strong><span data-contrast="auto">You can both build secure architecture and break it under controlled, agreed scope, and you know how to feed one into the other.</span><span data-ccp-props="{"335559739":70}"> </span></li> <li><strong><span data-contrast="auto">Versatile Range: </span></strong><span data-contrast="auto">Comfortable operating across the full security stack and switching context fast, from design to detection to active testing, while still going deep where the problem demands it.</span><span data-ccp-props="{"335559739":70}"> </span></li> <li><strong><span data-contrast="auto">Security Architecture: </span></strong><span data-contrast="auto">Proven experien