IONOS Is Hiring a Cyber Security Engineer in Karlsruhe
Employer: IONOS
Sector: Cloud solutions and digital services
Location: Karlsruhe, Baden-Württemberg, Germany — Hinterm Hauptbahnhof 3-5
Open roles: 1
Employment information: Hybrid working model; schedule not stated
IONOS has published a Cyber Security Engineer opening in Karlsruhe for a practitioner focused on the security boundaries of provider-operated infrastructure and internally operated AI platforms. The work concerns the systems that can reach sensitive infrastructure, the controls that govern that reach, and the evidence needed to keep those controls manageable and auditable.
This is a hands-on specialist assignment for someone who can turn security architecture into usable standards, test designs closely, and work with platform and engineering colleagues across brands. It suits a security engineer who is comfortable addressing root causes, explaining technical risk to non-technical stakeholders, and making well-reasoned decisions when a deployment needs stronger safeguards.
Opportunity Details
Security architecture across infrastructure and internal AI
A Karlsruhe-based role centred on controls, assurance and practical remediation
The vacancy spans two connected areas. One is the provider-side infrastructure layer: virtualisation and container platforms, control planes, provisioning systems, DNS, mail infrastructure, and backup and recovery systems. The other is the security of internal AI platforms, including model gateways, self-hosted models, agent frameworks, assistant integrations, connectors and retrieval pipelines that use internal data.
Rather than treating these areas as separate policy exercises, the position establishes architectural standards and hardening baselines, then helps make them real on varied platforms. Reviews of infrastructure designs and material changes form part of the work, alongside escalation support when platform, cloud or brand engineering teams need an infrastructure-security view.
Karlsruhe is the stated workplace, with a hybrid working model. The advertised remit also calls for collaboration across security functions and internal engineering teams, especially where secure AI adoption depends on clear guardrails, ownership and controls that can be implemented in day-to-day engineering work.
About the Employer: IONOS
IONOS and its digital services portfolio
Web presence, productivity and cloud offerings in one portfolio
IONOS describes its portfolio as supporting customers through digitalisation with web presence and productivity products alongside cloud solutions. Its published business model identifies web hosting, domain registration, e-commerce tools, email and office services, server hosting and value-added services among the web presence and productivity offering.
The cloud side of the portfolio includes public cloud, private cloud, bare metal cloud and managed services. IONOS states that these offerings cover cloud hosting, data storage and scalable computing resources, with an emphasis on secure and reliable cloud solutions from Europe.
The company’s official material describes a technology foundation of high-performance, reliable and highly secure IT infrastructure, developed in-house in Germany. That operating context makes the vacancy’s attention to privileged access, tenant isolation, deployment systems and recovery integrity directly relevant to the services behind the portfolio.
Infrastructure context behind the security remit
Cloud services built around scalable computing, storage and hosting
IONOS also presents digital sovereignty and data protection and security as considerations in its cloud business. For this role, that background is reflected in the expectation that internal AI activity is traceable, attributable and reviewable in line with applicable regulatory obligations and certifications.
The official business model says IONOS operates in markets across Europe and North America and works with local brands. The vacancy therefore refers to heterogeneous platforms and collaboration across brands, requiring standards that can be translated into implementable plans rather than treated as a single uniform technical environment.
This operational setting helps explain why the advertised security work reaches beyond an isolated product review. The role examines the boundaries around shared and customer-facing infrastructure while also considering internal AI systems that may call tools or retrieve internal data. The published vacancy names model gateways, self-hosted models and assistant integrations, showing that its scope covers both conventional platform controls and emerging engineering components. Effective security architecture in that setting depends on controls that teams can understand, deploy and maintain across differing technical implementations.
Open Positions
1. Cyber Security Engineer, Infrastructure and AI Platform Security / Cyber Security Engineer — Infrastructure & AI Platform Security (w/m/d)
Official title: Cyber Security Engineer — Infrastructure & AI Platform Security (w/m/d)
Location: Karlsruhe, Germany — Hinterm Hauptbahnhof 3-5 Employment information: Hybrid working model; schedule not stated
The engineer is expected to own security architecture for the provider-side infrastructure layer and act as a subject-matter specialist for internal AI platforms and agents. A central objective is to ensure that systems handling sensitive infrastructure remain securely governed instead of creating an accumulating set of privileged access paths.
The role combines standard-setting, detailed design assessment and direct engagement with engineering teams. It covers preventive architecture work, practical remediation with responsible platform teams, and infrastructure expertise for cyber defence, vulnerability management and IT incident-management activities.
Responsibilities
- Define and maintain security architecture standards and hardening baselines for provider-side infrastructure, including virtualisation, containers, control planes and provisioning systems.
- Assess and strengthen tenant isolation across shared-hosting, virtualisation and container layers, driving remediation with responsible platform teams.
- Review infrastructure designs and material changes for security impact and provide escalation support to platform, cloud and brand engineering teams.
- Reduce exposure on critical paths involving privileged access to customer-facing infrastructure, administrative segmentation, secret handling and recovery integrity.
- Translate security requirements into practical, brand-specific implementation plans for heterogeneous platforms.
- Support cyber defence, vulnerability management and IT incident management with infrastructure expertise during incidents and follow-up hardening work.
- Set security architecture and baseline standards for internal AI platforms, agent frameworks, assistant integrations, connectors and retrieval pipelines.
- Define controls for agent identity, authentication, authorisation, credentials, tokens, tool access, data access, logging and human oversight; perform pre-deployment security reviews and advise on secure AI adoption.
Qualifications
- Several years of practical experience in infrastructure or platform security, ideally in hosting, cloud, telecommunications or a comparably large multi-tenant environment.
- Deep practical knowledge of Linux, virtualisation and container platforms, networking, and the security characteristics of tenant infrastructure.
- A strong identity-and-access background covering privileged access, machine and workload identities, secrets management, authorisation models and infrastructure-as-code security.
- Experience developing and enforcing security standards in heterogeneous, partly legacy environments, including building support beyond a direct reporting line.
- Practical knowledge of building and operating LLM and agent systems and their risks, including prompt injection, excessive tool access, retrieval data exposure, unlogged autonomous actions, and model or provider dependencies.
- Ability to make and defend risk-based decisions, including stopping a deployment with a clear rationale, and to explain technical risk to non-technical stakeholders.
- Fluent English. Preferred: German because of the regulatory environment and public-sector context.
- Preferred: production experience deploying or securing internal AI platforms, agent frameworks or tool-calling integrations; familiarity with NIS2, BSIG or ISO 27001; or experience in DNS, mail infrastructure, abuse prevention, multi-brand environments, security engineering or software development.
Skills and Competencies
- Security architecture and hardening-baseline design for complex infrastructure.
- Linux, networking, virtualisation and container-security practice.
- Privileged access, non-human identities, secrets and token management.
- Authorisation models, least-privilege design and infrastructure-as-code security.
- LLM and agent-system security, including guardrails and retrieval-pipeline risk.
- Risk communication, independent judgement and collaboration across security and engineering teams.
Benefits and Employment Information
- Hybrid working model.
- Flexible working hours through a trust-based working-time arrangement.
- Subsidised canteen and complimentary drinks at selected locations.
- Modern office spaces with strong transport connections.
- Employee discounts for activities and products.
- Employee events and workshops.
- Development opportunities and health offerings, including sport and health courses.
Application Guidance
Preparing evidence for an architecture-focused security discussion
Show how technical judgement translates into implementable controls
Lead with infrastructure-security examples that match this remit, such as hardening, identity and access work, or platform reviews you carried out yourself. Describe examples where you reviewed a platform design, defined a baseline, improved an access boundary, or helped remediate a control weakness. Explain the operating context without disclosing confidential customer, system or incident details.
The AI-platform aspect calls for more than a general interest in AI policy. Applicants can prepare concise examples of how they have assessed agent identities, tool permissions, secrets, retrieval access, logging, approval points or deployment risk. If a project was experimental rather than production-based, distinguish that clearly and focus on the engineering lessons learned.
- Map relevant Linux, network, virtualisation and container-security experience to the role requirements.
- Prepare a brief example of reducing privileged access or improving administrative segmentation.
- Identify security standards or hardening baselines you have written, reviewed or implemented.
- Outline an AI or agent-system risk assessment, including data access and human-oversight decisions.
- Be ready to explain a risk-based decision to both engineering and non-technical audiences.
How to Apply
Submit Your Application Through the Verified Route
Submit the requested information through the official application portal
The application for this IONOS post is made through the company's official portal, accessible below. The form requests a résumé and contact details, as well as information including location, notice period, pay expectations, communication language, work-authorization response, languages, and selected tools and competencies. It also provides an option to attach a cover letter.
Before submitting, check that the résumé gives a clear account of relevant infrastructure or platform-security practice, identity and access work, and any hands-on exposure to LLM or agent systems. Where experience is preferred rather than required, present it accurately and separate it from the core qualifications stated for the position.
.png)

Post a Comment