Cyber Security Engineer (m/f/d)

Permanent full-time position, starting as soon as possible, in Freigericht.

Location: Freigericht (Hybrid – up to 3 days/week remote)

Languages: German & English (both required)

The Company

CID GmbH is an innovative and dynamically growing IT company that supports organizations worldwide in their digital transformation. With 14 locations across Europe, the United Kingdom, and the United States, we develop solutions that make companies more efficient along the entire digital value chain – from customized software and modern data stacks to cloud-native architectures and artificial intelligence.

Our work combines consulting, strategic planning, product design, and technical implementation. Through our “Smart Accelerators” framework, we support our customers from the initial idea through to the successful realization of complex IT and software solutions. In doing so, we place particular emphasis on security, scalability, and sustainable value creation.

Our expertise is based on five pillars: digital transformation consulting, modern data stacks and AI, cloud-native software and transformation, cloud operations and enablement, and cybersecurity. With this broad range of competencies, we design future-proof, data-driven, and scalable digital ecosystems that provide our customers with sustainable competitive advantages.

CID works across industries with global brands from manufacturing, retail, financial services, and telecommunications. Through close cooperation with science and research, we continuously develop new approaches to elevate information management and business processes to a new technological level.

Your Mission

You explain complex topics in a way that doesn’t leave people staring blankly but instead gets them thinking along. And when everyone says, “Looks fine to me,” you’re the person who smiles politely and asks: “But why, exactly?”

You don’t just accept that your EDR needs a kernel driver – you want to understand why. You know that “But we do have a firewall” sounds about as reassuring as “This ship is unsinkable.” And you can demonstrate how data still finds its way out.

Nmap, Burp, Responder, BloodHound – of course you know them. But what really gets our attention is when you’ve expanded your toolkit with tools of your own. Because the ready-made script didn’t quite do what you wanted. Because you could do it better. Or simply because Saturday night was still long.

You’re not here just to drop off a report – you’re here to understand where it really hurts and to build solutions together with the client (internal or external) that last beyond the next audit.

You become a sparring partner on equal footing: you listen, think along, and make security tangible – without fearmongering. Whether you simulate attacks, secure processes, or enable teams depends on the client. The important thing is that you leave them stronger than you found them.

Your Day-to-Day

Forget the image of the lone hoodie wearer in a dark basement. With us, cyber security is a team sport – just with better inside jokes.

Humor is mandatory. Anyone who spends their day chasing vulnerabilities, dissecting incidents, and explaining to developers why –privileged is not a lifestyle feature needs one thing: people around them who can laugh about it.

Real community instead of org-chart cosmetics. We’re not a team because a slide says so. We’re a team because we’ve got each other’s backs. Everyone knows everyone here, egos stay at the door, and knowledge is shared – not hoarded.

Motivation that doesn’t come from motivational posters. We’re driven by genuine curiosity, not buzzword bingo. New attack vectors, clever exploits, a tool nobody else has on their radar yet – that’s what makes us open our laptops in the morning. Voluntarily. Before the first coffee (okay, usually after the first coffee).

Your Responsibilities

No two days are the same – and no two profiles are either. Our security landscape is broad, and that’s exactly the point: you don’t need to know everything, but you should be eager to move across more than one area.

We’ll define your focus together, based on what you bring, what you want to learn, and where we need you most.

The Playing Field

  • Threat Hunting & Monitoring – Detect anomalies others miss and ensure our situational awareness never becomes a snapshot.
  • Internal Pentesting – Think like an attacker, act like an ally – and help us close gaps before they become real vulnerabilities.
  • OSINT & Threat Intelligence – Know what’s circulating about us out there – on the open web and in corners no search engine reaches.
  • Security Concepts – Work with developers, DevOps, NetOps and others to build security into architectures, not bolt it on afterward.
  • Firewall- & Active Directory Audits – Verify that what should be secure actually is – and clean things up where necessary.
  • Hardening – Strengthen our infrastructure step by step without bringing operations to a halt.
  • Workshops &Knowledge Transfer – Share your expertise – whether in security workshops, internal blog posts, or spontaneous whiteboard explanations.

And what’s not on this list today may be tomorrow. We constantly learn, evaluate new technologies, and adapt our scope to the evolving threat landscape – not to what last year’s concept said.

Standing still isn’t a feature here – it’s a finding.

The Deal: You tell us where you’re strong and where you want to go. We tell you where we need support. Then we find the overlap that works for both sides – not a rigid job description, but a role that grows with you.

What We Offer

Growth & Responsibility

  • Long-term career prospects – not a dead end, but real development.
  • The opportunity to shape the future, take on exciting challenges, and assume meaningful responsibility.
  • Extensive training and development opportunities – conferences, training, certifications, and the kind of learning no course can teach.

Culture & Collaboration

  • An open company culture with straightforward collaboration and a first-name basis across all levels – from interns to management.
  • Real sparring: a team that challenges you, not just nods along. Your ideas get better because we question them.
  • Regular team events, summer parties, and Christmas celebrations.

Work-Life Balance & Flexibility

  • Attractive working hours with core hours and hybrid work options – because good security work isn’t tied to a desk chair.
  • 30 days of vacation – even firewalls need maintenance windows.

Compensation & Benefits

  • Attractive, performance-based compensation – your impact is reflected.
  • Employer contribution to company pension scheme, company health insurance, and group accident insurance.

Workplace & Extras

  • A highly modern workplace with state-of-the-art IT equipment and ergonomic furniture – no battles with office gear from 2008.
  • Healthy and varied lunch options at reduced prices in the modern company restaurant, plus free hot and cold drinks.
  • Free parking and JobRad® bicycle leasing.

What Sets You Apart

  • Operating systems (Windows, Linux, macOS) feel like home to you.
  • Networking, scripting, and curiosity about IT infrastructure are your tools of the trade.
  • You’ve already looked behind the scenes of DevOps, SysOps, or NetOps and can navigate those environments.
  • Solid triage and risk-based decision-making are exactly your thing.

Nice to Have

  • Certifications such as OSCP or profiles on HackTheBox / TryHackMe show your passion – but what matters more is that you can actually do it.
  • Experience with hybrid cloud, containers (Kubernetes, Docker), or CTF successes? Tell us about it.
  • A GitHub portfolio? Show us what you can do instead of just talking about it.

In Short

You’re not a rule enforcer – you’re an enabler. You make security practical for everyday use: technically sound, operationally smart, and understandable for people.

Your opportunities at CID …

… are what you make of them. If you want to make a difference, we can help you do so. CID offers you opportunities, experience, and growth in a stable and constantly evolving company. In addition to daily tasks and responsibilities, working at CID provides greater challenges and the opportunity to actively shape the future of the company.

You will become part of a flexible, customer-oriented, and eager-to-learn team that values open communication and a welcoming culture. Our offices and workflows are designed to make onboarding as easy and productive as possible.

You will work on a wide range of groundbreaking projects and products for large companies across various industries, supported by continuous communication and your ability to make important decisions. From the nature of the tasks you are assigned to the opportunities for collaboration with leading technology providers, working at CID offers fantastic conditions to foster your professional development.

We offer a results-based remuneration package, with the opportunity to take on additional training to boost your personal development.

Other benefits include flexible working, 30 days annual vacation time, an optional company pension, regular team events, a modern canteen/cafeteria and free drinks.

If this sounds like the opportunity for you, we’d love to hear from you. Please send us a full application, in either German or English, and your salary expectations

Send your application and we’ll be in touch.