Skip to content
All opportunities
IONOS SEExternal opportunity

Cyber Security Engineer — Infrastructure & AI Platform Security (w/m/d)

Karlsruhe, Germany

About the role

About IONOS At IONOS, we don't just manage servers; we shape the digital future for over 6.2 million customers worldwide with our solutions. As Europe's leading hosting provider and a pioneer in independent cloud solutions, we are building a next-generation infrastructure: from sovereign cloud architectures and high-performance GPU clusters to integrated AI automation tools. What drives us: Digital freedom of choice for Europe and real impact for small and medium-sized enterprises (SMEs) as well as large corporations. We work in agile teams, rely on transparent structures, and believe that excellence and innovation only arise with true team spirit. Ready for your next step? Become part of IONOS and grow with us. Both halves of this role revolve around the same fundamental question: which systems can reach our most sensitive infrastructure and under what controls. You will take responsibility for the security architecture of our provider-side infrastructure layer and be the subject matter expert (w/m/d) for internally operated AI platforms and agents. In doing so, you will ensure that these run in a secure, managed, and auditable state, rather than creeping in as a new class of privileged access. This is a hands-on expert role. You will set standards, put designs through their paces, and work directly with platform and engineering teams across all our brands to implement them. Area of Responsibility Infrastructure Security • Defining and maintaining security architecture standards and hardening baselines for provider-side infrastructure: virtualization and container platforms, control planes and deployment systems, DNS, mail infrastructure, as well as backup and recovery systems. • Assessing and strengthening tenant isolation across shared hosting, virtualization, and container layers, and driving remediation measures with the responsible platform teams. • Reviewing infrastructure designs and major changes for security implications and acting as an escalation point for infrastructure security questions from platform, cloud, and brand engineering teams. • Reducing the blast radius on key paths: privileged access to customer-facing infrastructure, administrative segmentation, handling of secrets, and recovery integrity - translated into actionable brand-specific implementation plans for our heterogeneous platforms. • Supporting Cyber Defense, Vulnerability Management, and IT emergency management with infrastructure expertise during incidents and follow-up/hardening. Internal AI Platform and Agent Security • Responsibility for the security architecture and baseline standards for internally operated AI platforms: model gateways and self-hosted models, agent frameworks, assistant integrations, connectors, and retrieval pipelines over internal data. • Defining and enforcing how agents are identified, authenticated, and authorized: handling non-human identities, credential and token management, least-privilege access to tools and systems, and determining where autonomous action requires a human-in-the-loop. • Determining which data internal AI systems may call and index, and ensuring that agent activities are logged, attributable, and verifiable - in accordance with the requirements of our regulatory obligations and certifications. • Conducting pre-deployment security checks for new internal AI platforms and agent use cases in line with the fast pace of adoption, and overseeing unsecured/unsanctioned AI usage (Shadow AI). • Advising security functions and internal engineering teams on the secure adoption of AI, including guardrails that enable justifiable adoption. Qualifications • Several years of practical experience in infrastructure or platform security, ideally at a hosting provider, cloud provider, telecommunications company, or in a comparably large multi-tenant environment. • Deep practical knowledge of Linux, virtualization and container platforms, networks, and the security properties of tenant infrastructures. • Strong background in Identity & Access: Privileged Access, machine and workload identities, secrets management, authorization models, and Infrastructure-as-Code security. • Experience in developing and enforcing security standards in a heterogeneous, partly legacy landscape, as well as gaining buy-in from teams outside one's own reporting line. • Practical knowledge in building and operating LLM and agent systems as well as the specific risks: prompt injection through untrusted data, overly broad tool access, data exposure through retrieval, unlogged autonomous action, model and provider dependencies. • Ability to make and defend risk-based decisions - including blocking deployments with clear reasoning - and to explain technical risk to non-technical stakeholders. • Fluent English skills; German skills are a strong advantage due to our regulatory environment and the public sector. Desirable / An Advantage • Practical experience in deploying or securing internal AI platforms, agent frameworks, or tool-calling integrations in a production environment. • Familiarity with NIS2 / BSIG or ISO 27001. • Background in DNS, email infrastructure, or platform-level abuse prevention. • Experience in a multi-brand or post-acquisition environment where the same control is applied in different implementations.