Job Overview
Job description
- Location:
- Germany
- Work arrangement:
- Hybrid
Role Summary
APT-ONE GmbH in Berlin is a consulting firm specializing in cyber security. We effectively protect our customers’ IT, OT, cloud and AI systems from digital threats.
Our approach is different: AI-supported tools handle discovery, routine analysis and pattern recognition - our consultants validate, interpret and focus on strategy and tailor-made solutions. This results in deeper analyzes and a reliable basis for decision-making in a shorter time, with 40-60% less effort for routine work.
AI only with the highest sensitivity for customer data: data protection trumps any gain in efficiency. AI exclusively on contractually secured, data protection-compliant platforms, minimized and anonymized data, never customer data in model training. This approach – and the willingness
We expect all consultants to continually develop our processes and products further with AI.
Of great advantage
- Cloud architecture expertise: design and securing of cloud and hybrid environments (Azure, AWS, GCP), cloud-native security services, infrastructure-as-code
- Prompt engineering, AI agents or LLM integration into workflows
- AI governance (EU AI Act, ISO/IEC 42001, OWASP Top 10 for LLM)
- Regulated environments (CRITIS, financial sector, industry/OT)
- Certifications (nice to have)
- Cloud architecture and cloud security certifications
- CCSP (ISC²) or CCSK (Cloud Security Alliance)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100) and/or Azure Solutions Architect Expert (AZ-305)
- AWS Certified Solutions Architect – Professional and/or AWS Certified Security – Specialty
- Google Professional Cloud Architect or
Error 500 (Server Error)!!1500.That’s an error.There was an error. Please try again later.That’s all we know.
Responsibilities
- Design and further development of security architectures across IT, OT, cloud and AI systems
- Design of secure cloud and hybrid architectures (Azure, AWS, GCP) including landing zones, identity and network design, encryption and security baselines
- Creation of target architectures, security roadmaps and migration paths - especially for cloud transformations and multi-cloud scenarios
- Conduct threat modeling, architecture reviews and risk analysis for applications, networks, cloud workloads and platforms
- Design of network and perimeter security including segmentation, firewalling and zero trust network access – on-premises and in the cloud
- Conception of IAM and PAM architectures as well as cryptography and PKI concepts, including cloud-native identity and key management services
- Assessing and securing cloud platform services, container/Kubernetes environments and CI/CD pipelines (DevSecOps)
- Definition of security requirements for projects, products, cloud providers and service providers
- Translation of regulatory requirements (NIS2, DORA, ISO 27001, BSI IT-Grundschutz, BSI C5) into technical specifications and auditable controls
- Expert advice from CISOs, cloud teams, architecture boards and technical decision-makers
- Creation of security concepts, guidelines and technical documentation
- Use of AI-supported tools in discovery, architecture reviews and documentation – including technical validation and release of the results
Requirements
You've come to the right place if
- you want an attractive fixed salary plus above-average profit sharing.
- you want to work on highly relevant projects in security operations and AI security, regardless of location.
- you see AI as a lever and want to rethink security consulting – without compromising data protection.
- you want to expand your expertise in SOC platforms, detection engineering and automation.
- Confident handling of AI tools in everyday consulting including critical evaluation of the results
- Strong awareness of confidentiality when using AI: You know which data is allowed into which system and know the risks (data leakage, model training, prompt injection)
- Willingness to continuously develop processes and products based on AI
- At least 3-5 years of experience in IT/cyber security, including several years in architecture or consulting roles
- Broad understanding of technology across network, endpoint, identity, application and cloud
- Experience with zero trust and segmentation concepts as well as IAM/PAM (Entra ID, Active Directory)
- Secure handling of ISO 27001, BSI IT-Grundschutz, NIST CSF, MITER ATT&CK, SABSA/TOGAF
- Knowledge of cryptography, PKI and secure application design
- Fluent German and English skills
- Role:
- IT | OT Security Architekt (m/w/d)
- Job Type:
- Full Time