Join our international team that drives positive change, united by a spirit of openness and curiosity. We empower you to have an impact and to grow – personally and professionally. With us, you work at the heart of financial systems and evolve the way markets operate. We’re excited about the future because we are the ones shaping it. Let´s do this together by sharing value!
IT Security Engineer (Red Teamer and Threat Hunter) - CERT - Group Security (f/m/d)
Deutsche Börse AG • Frankfurt am Main, Prague
Learn. Develop. Grow. But always: Share value
Who we are
Tracing its origins to 1585, Deutsche Börse Group has become one of the world’s leading exchange organisations and an innovative market infrastructure provider. In this role, we provide investors, financial institutions and companies access to global capital markets. What’s your part in all this? With your commitment you contribute to the success of our unique business model: offering a wide range of products, services and technologies for security, transparency and integrity on the markets. By creating trust in the markets of today and tomorrow we foster growth and contribute to the prosperity of future generations.
Frankfurt am Main, Prague
Your career at Deutsche Börse Group
Your area of work:
CERT is the central unit for all IS Incident Management, Critical vulnerability notification and Threat Hunting, in strict cooperation with SOC and Cyber Analytics teams (responsible for Threat Landscape definition and SIEM use case implementation).
We are looking to hire a Red Teamer and a Threat Hunter for DBG CERT. The selected candidate will be in charge of providing Red Team to DBG group and its legal entities and support definition of a Threat Hunting program and orchestrate related activities. The job holder will be involved in projects aiming at delivering new service capabilities and will participate in the definition, implementation and delivery of such projects. The main activities include but are not limited to: payload design for Red Teaming, delivery and execution, post-exploitation activities and reporting, developing hypothesis based on threat intelligence for Threat Hunting, hunting with usage of technology like EDR, SIEM and Cloud-based solutions.
- Support definition of Red Teaming program and orchestrate related activities.
- Support definition of Threat Hunting program and orchestrate related activities.
- As CERT member, being available for IS Incident Handling and Critical vulnerability assessment as well as other CERT daily duties.
- Recommend security measures to address cyber threats identified, e.g. defining SIEM use-cases and logs onboarding.
- Help to improve the CERT process excellence by maintaining information security documentation
- Available during the working hours (Mo-Fr) + on call duty
- Solid IT Security technical background and broad knowledge of IT and Information Security technologies especially in the frame of threat detection and security monitoring (e.g. SIEM, EDR, Honeypot infrastructure)
- Solid understanding of cyber threats and MITRE ATT&CK framework
- Deliverable-oriented, with strong problem-solving skills and adaptation on complex and highly regulated environment.
- Team player willing to cooperate with multiple colleagues across office locations
- Previous experience in a CERT or SOC team is considered a strong asset as well as involvement in IS Incident investigations
- Good report-writing skills to present the findings of investigations
- Scripting skills (e.g. Python, Bash, Perl) is considered a strong asset
- Experience with JIRA ticketing tool and JIRA Service Manager is a strong asset
- Develop and help implement automation of various CERT processes via SOAR solution is a strong asset
- Technical certification in the area of Red Teaming/Penetration Testing or Threat Hunting (e.g. GIAC, OCSP, CEH, etc.) are considered as a strong asset.
Why Deutsche Börse Group?
We are committed to providing a work environment which makes our employees both feel at each other and reach their full potential. Our standards go far beyond simply matching candidate with the suitable position.
Exciting, cutting-edge projects
“Boredom” is a concept unknown to us. With us you are part of a growing company that is shaping the future and where you can make a difference and actively participate – by supporting companies and start-ups going public, developing trading technologies or designing the cloud infrastructure for a highly regulated environment.
Our market infrastructures are connected globally: whether in Singapore, London, Chicago, Luxembourg or Dubai – working with us means collaborating with like-minded colleagues and teams across over 60 locations from more than 100 nations.
Security and growth
Our company is experiencing healthy growth, not least due to our diversified business model. As a globally active exchange organiser, we provide market participants with consistently safe infrastructures that stimulate growth along the entire value chain. For you this means: a secure and promising workplace!
Diversity & Inclusion
We embrace diversity. As the cornerstone of our success, your contribution counts – irrespective of gender, nationality, ethnic or social background, religion or worldview, disability, age, sexual preference and identity.
We at Deutsche Börse create trust in the markets of today and tomorrow. We want to achieve this common goal with performance, reliability, integrity, openness and responsibility. Mutual respect and appreciation are of particular importance. Our values shape our culture and behaviour – both within our organisation and externally.
Our employees work in great teams that drive positive change – and therefore they enjoy working with us. This is reflected in our annual employee surveys. No matter how great the challenges posed by the markets might be – we support each other, work together closely to successfully complete projects and face change with a positive, collaborative approach.
We offer a work environment, in which professional and private life can interact individually. Flexible working time models, allowance for childcare, working remotely, studying alongside your job or part-time models – we give you the opportunity to adapt your job to your life situation.
Careers with a future
Whether you are an apprentice, a trainee, a young or experienced professional – with us your career is off to a good start that holds many different paths to develop and reach the next level. Your professional future is in your hands – as a manager, expert or project manager. You can count on our support as well as further education and training measures.
Our hybrid work model
personal exchange and the collaborative atmosphere at our offices are an important part of our corporate culture. At the same time, we also offer our employees more flexibility regarding their workplace by giving the opportunity to work remotely for two days during the week. Please note that deviations to this model may arise - in addition to operational reasons - e. g. due to local regulation or legislation.