Cybersecurity Expert - Senior Information Security Incident Manager (f/​m/​d)

immediately

Full-time, Unlimited

Düsseldorf, Hanover, Würzburg

Cybersecurity Expert - Senior Information Security Incident Manager (f/m/d)

Locations: Düsseldorf (NRW), Hanover (NDS), Würzburg (BY)

Your responsibilities

The Uniper Cybersecurity Operations Center is continuously enhancing its capabilities to strengthen our cybersecurity readiness and response to evolving threats. To meet our growing maturity and scalability demands, we are expanding our internal team to bolster skills, capacity, and gain fresh external perspectives to refine our incident response and cybersecurity functions.

Role Description:

We are seeking skilled and experienced professionals with proven expertise in cybersecurity. You should be confident in assessing, classifying, and investigating potential threats or incidents. Ideally, you hold certifications such as Incident Handler and have deep knowledge of Microsoft products, Cloud Solutions, Palo Alto, PowerBI, and automation tools. Experience in forensics and using forensic tools is essential, along with strong familiarity with querying and coding languages.

You possess the ability to handle complex situations and communicate confidently with both technical and non-technical audiences. Your work is well-organized, and you consistently produce high-quality documentation, striving for continuous improvement in processes and procedures. Fluency in both English and German is required. If you're someone who thrives in dynamic environments and constantly seeks improvement— we want you on our team!

Key Responsibilities:

  • Incident Lifecycle Management: Manage and coordinate the full lifecycle of information and cybersecurity incidents, including detection, containment, eradication, and restoration of affected systems. Act as the central communication point, coordinating incident management activities with IT and OT teams, service providers, suppliers, and other relevant stakeholders from start to finish
  • Technical Expertise & Threat Identification: Leverage a strong technical background across multiple disciplines (Cloud, infrastructure, architecture, Industry 4.0) with a focus on information security. Identify malware types, infection methods, and objectives, while extracting and defining Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs)
  • Threat Analysis & Monitoring: Analyze system logs, including network traffic, payloads, event logs, application logs, and firewall logs to detect and understand security incidents. Contribute to threat hunting activities, pen tests, forensic analysis, and continuous monitoring to enhance security posture
  • SOC & Automation Integration: Apply experience in setting up or working within modern Security Operations Centers (NextGen/Fusion/Converged Cyber Defense Ops) with automation, orchestration, and threat intelligence tools. Familiarity with tools like Palo Alto XSOAR/XSIAM, MS Sentinel, and Defender for Cloud is highly valued
  • Network & Endpoint Security: Provide expertise in network security and incident handling, with experience in managing firewalls and using advanced security solutions like Microsoft E5 Security (e.g., Palo Alto Cortex, MS Defender XDR)
  • Threat Intelligence & Vulnerability Management: Collaborate with teams focused on Threat Intelligence and Vulnerability Management, ensuring proactive identification of threats and tracking remediation efforts. Familiarity with frameworks like Mitre ATT&CK and tools like MISP and Mandiant is preferred
  • Documentation & Reporting: Prepare high-quality reports on security incidents, findings, and lessons learned. Generate documentation for processes, procedures, and playbooks, ensuring clear communication of outcomes to both technical and non-technical audiences. Crisis management and communications expertise are considered advantageous
  • Emerging Threat Awareness: Stay informed about emerging threats and exploit vectors, sharing insights with leadership and cross-functional teams to inform decision-making and ensure continuous improvement
  • Communication & Collaboration: Work closely with cross-functional teams, delivering clear, concise communication on security incidents, vulnerabilities, and mitigation strategies to all levels of the organization

Your profile

Qualifications:

  • Education: Bachelor’s or Master’s degree in Computer Science, IT Security, Business Informatics, or a related field
  • Experience: Minimum of 8 years in IT security with over 3 years of hands-on experience in Cyber Defense Operations Centers (CDC) or Security Operations Centers (SOC). Proven expertise in managing cybersecurity incidents, cyber defense operations, and threat intelligence with a strong technical background
  • Technical Expertise: Deep knowledge of cybersecurity threats, attack techniques, and relevant intelligence tools (e.g., MISP, Mandiant). Proficiency in network architectures, cloud security, and IT security frameworks, including experience with Microsoft Azure and Palo Alto solutions. Familiarity with the MITRE ATT&CK framework and advanced incident response methodologies. Strong skills in coding and querying languages such as Python, KQL, XQL, GO, JavaScript, Java, C#/.NET, Rust, Lucene, and RegEx
  • Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or similar. Incident Response certifications such as E|CIH, GCIH, or GEIR are preferred. IT vendor certifications, particularly in Microsoft Azure and Palo Alto, would be advantageous
  • Analytical Skills: Strong ability to analyze complex threat data, detect patterns, and develop actionable intelligence. Expertise in working with Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs) to enhance security operations
  • Human Skills: Experience working within international teams, adept at managing intercultural communications, and promoting effective collaboration despite differing opinions or perspectives
  • Other Requirements: Fluency in both spoken and written English and German is a plus

Key Attributes:

  • Innovative & Analytical: You challenge the status quo, bringing new ideas and innovative solutions to the table. You are constantly looking for ways to enhance processes, especially in cybersecurity and technical problem-solving
  • Team Player: While you thrive in individual tasks, you excel in collaborative environments and work well within cross-functional teams. You proactively offer assistance, contributing to team success even without being asked
  • Problem Solver: You are an independent thinker and an excellent listener, capable of delivering effective solutions. You maintain your composure under pressure and solve complex technical challenges with ease, particularly in the context of cybersecurity operations
  • Ownership & Accountability: You take full ownership of your work, ensuring accountability in every task. You deliver results that align with the organization’s goals and continually improve its cybersecurity defenses
  • Strong Communicator: You possess excellent verbal and written communication skills, adept at explaining complex technical issues to both technical and non-technical audiences. You aren’t afraid to speak up, ensuring clarity in all communications
  • Passionate & Motivated: You bring energy and enthusiasm to your work, balancing hard work with a positive attitude. You inspire and motivate those around you, staying engaged and driven to achieve top-tier results while enjoying your work
  • Technical Expertise: Your skills extend to working with cybersecurity frameworks, threat intelligence tools, and coding languages like Python, KQL, and XQL. You leverage this technical knowledge to innovate and solve security challenges

Job ID:

87290

Do you have any questions?

If you have any questions, please feel free to contact us by e-mail and we will get back to you:

career@uniper.energy

Please note: Unfortunately, we cannot consider applications by e-mail for data protection reasons. We would therefore like to ask you to apply exclusively here via our career page. The process is very simple and only takes a few minutes.

As long as our positions are online here on the career page, the application process is not yet complete and the positions are still vacant.

We look forward to receiving your application!

Your Uniper Talent Acquisition Team

Living diversity, fairness and inclusion (DEI) at Uniper

As an employer, Uniper is committed to diversity and equal opportunities. That's why we encourage applications from suitably qualified and suitable people regardless of gender, origin, disability, age, religion, ideology, sexual identity or marital status. We embrace inclusion and support flexible working.

What makes Uniper stand out as an employer

  • We allow you a high level of flexibility and individuality based on our unique FlexWork culture. You decide in coordination with the team how, when and where you work together

    FlexWork

  • We offer you flexible workplaces and open spaces with state-of-the-art ergonomic equipment, both in the office and at home.

    Modern workplaces

  • We support you in balancing your private and professional life through flexible working time models, job sharing, sabbaticals and extensive offers in the area of child care and nursing.

    Work Life Balance

  • With a mix of digital and analog learning formats and topic-specific communities, we promote your personal and profossional development and lifelong learning.

    Further education

  • Experienced specialists and managers are happy to support you in strengthening your skills and advancing your career development.

    Coachings and Mentoring

  • Performance discussions, 360-degree feedback and employee surveys will help you and the company move forward, strengthen our collaboration and give you room to contribute your ideas.

    Open feedback culture

  • Safety and well-being are our top priorities. That's why we offer you regular free preventive medical checkups as well as a variety of learning impulses on occupational safety, health and well-being, and support programs.

    Health care

  • With our online exercise courses, sponsorship of your participation costs in central sports events and a large sports community, we offer you a healthy working environment.

    Sport and Fitness

  • You can enjoy a wide range of healthy and balanced meals in our canteen. In addition, you can participate in nutrition programs.

    Healthy nutrition

  • We offer you the option of leasing a car or bicycle through deferred compensation with financial benefits.

    Car and job bike leasing

  • We have electric charging stations for free charging of your electric or hybrid car.

    Electric charging stations

  • We provide you with free parking spaces.

    Free parking spaces

  • We take care of you and offer you a wide range of coverage beyond the legal requirements with our company pension plan, accident insurance, company health insurance and continued salary payments in the event of illness.

    Insurance and coverage

  • We pay capital-forming benefits and offer you a wide range of financial benefits through our corporate benefits program

    Financial benefits

Get to know your future colleagues

  • Valentina

    EVP Operational Excellence

    At Uniper “treating everyone in a fair way”, and “making everyone feel included” are serious topics. This is why we regularly seek feedback from our employees, we listen to them, and we make changes so that we can get closer and closer to our vision of DEI.asd

  • Thomas

    Head of ETRM department

    I was excited to join Uniper as it a give me the opportunity to be part of a large, complex and dynamic Trading Organization. The company trades a lot of different commodities in many markets with all their uniqueness, which ultimately requires many different IT tools and solutions. I enjoy working with traders and all the supporting functions in such a challenging environment.

  • Navya

    Lead Business Analyst

    My passion is driven by the excitement of learning something new every day and a strong sense of pride supporting our Uniper business growth & Strategy. This is enhanced by the presence of a great team around me, whom I can always rely on for support.

  • Mithun

    Lead - Strategic Endur Solutions

    Each day excites me with new challenges by driving various Strategic IT initiatives for our CCO Trading Business and accelerating the energy transition by decarbonising our portfolio. My motto: Entrepreneurship is trait that you live each moment! At Uniper, I can constantly challenge status quo and shape the environment around me.

  • We are Uniper

    At Uniper, we are pro-actively transforming the world of energy and at the same time securing the supply of energy. As a company operating internationally, we work in very diverse teams and offer our employees as much flexibility as is possible. Equity, mutual appreciation and respect are the core of our corporate culture. At our company you will have the opportunity to shape new technologies, work on solutions for a modern and future-oriented energy supply and actively design change processes.

    360_tour.webp

    Düsseldorf

    Virtual tour of our offices in Düsseldorf

    With our virtual reality tour, you can experience Uniper from a completely new perspective. Our Düsseldorf offices can be viewed in detail without being on site. You can also get to know your colleagues and the working environment virtually. A highlight of the tour is built right into the beginning: a video from a bird's eye view impressively shows how attractive our location in the Medienhafen is.

    Take the 360 degree tour
    Düsseldorf_Standort_1.webp

    Düsseldorf

    Uniper has been based at our headquarters in Düsseldorf's Media Harbour since 2019. Our central office consists of the two buildings Caprocorn and Float, which are connected by a walkway to form a single unit.

    Düsseldorf_Standort_2.webp

    Düsseldorf

    Uniper has been based at our headquarters in Düsseldorf's Media Harbour since 2019. Our central office consists of the two buildings Caprocorn and Float, which are connected by a walkway to form a single unit.

    Düsseldorf_Standort_3.webp

    Düsseldorf

    Uniper has been based at our headquarters in Düsseldorf's Media Harbour since 2019. Our central office consists of the two buildings Caprocorn and Float, which are connected by a walkway to form a single unit.

    Düsseldorf_Büro_1.webp

    Düsseldorf

    On the office floors, the modern furnished meeting areas and lounges are located in the centre of each floor and our colleagues work separately from the passage areas, each with window fronts. All workstations have modern equipment and height-adjustable desks.

    Düsseldorf_Büro_2.webp

    Düsseldorf

    On the office floors, the modern furnished meeting areas and lounges are located in the centre of each floor and our colleagues work separately from the passage areas, each with window fronts. All workstations have modern equipment and height-adjustable desks.

    Düsseldorf_Büro_3.webp

    Düsseldorf

    On the office floors, the modern furnished meeting areas and lounges are located in the centre of each floor and our colleagues work separately from the passage areas, each with window fronts. All workstations have modern equipment and height-adjustable desks.

    Düsseldorf_Café_1.webp

    Düsseldorf

    We offer many services at the location that positively support everyday working life. These include an IT walk-in centre, a fitness studio, an underground car park with free parking spaces for cars and an extra garage for bicycles, including showers. For a balanced diet, there is a canteen as well as a café and a deli with fruit and healthy snacks, which are also open to the public.

    Düsseldorf_Café_2.webp

    Düsseldorf

    We offer many services at the location that positively support everyday working life. These include an IT walk-in centre, a fitness studio, an underground car park with free parking spaces for cars and an extra garage for bicycles, including showers. For a balanced diet, there is a canteen as well as a café and a deli with fruit and healthy snacks, which are also open to the public.

    Düsseldorf_Café_3.webp

    Düsseldorf

    We offer many services at the location that positively support everyday working life. These include an IT walk-in centre, a fitness studio, an underground car park with free parking spaces for cars and an extra garage for bicycles, including showers. For a balanced diet, there is a canteen as well as a café and a deli with fruit and healthy snacks, which are also open to the public.

    FlexWork

    Flexible working at Uniper means that our teams decide for themselves how, when and where they work. We have created hubs for collaboration and networking in our offices and we provide our employees with the equipment for a modern and healthy workplace at home. We also offer geographical flexibility and various flexible working models. This means you can do your work from different locations and shape your job to fit your personal lifestyle, so you can balance your work and private life perfectly.

    To give you a deeper insight into the flexible working experience at Uniper, we have created a dedicated page where you can learn more about our flexible working models.

    More about FlexWork at Uniper

    Application process

    Step 1

    Online application

    Have you found a suitable job posting? Then you can apply online right here. The application process is very simple and only takes a few minutes. Once we have received your application successfully, you will receive confirmation by e-mail immediately afterwards.

    Your questions. Our answers.

    Your application

    Your general questions