Security Operations Manager
Listed on 2026-01-11
-
IT/Tech
Cybersecurity, Information Security
Location: Germany
Exasol’s Analytics Engine accelerates insights from the world’s data. It is purpose-built to handle the most demanding data workloads at an unmatched price/performance ratio. Our in‑memory, massively parallel processing (MPP) technology is specifically designed for analytics, enabling businesses to turn data into actionable insights.
At Exasol, we are committed to pushing the boundaries of what is possible in data analytics, and we are looking for enthusiastic individuals to join our team and help shape the future of data technology. Join our diverse, remote‑first team where more than 30+ languages (and counting!) are spoken, and every voice is valued. We are looking for passionate individuals who thrive on collaboration, innovation, and a shared commitment to help shape the future of data technology.
OverviewThe Security Operations Manager leads and continuously improves security operations across Exasol’s cloud, infrastructure, endpoints, and SaaS environments, with a strong focus on AWS‑based environments, incident response, and regulatory aligned security operations. The role owns day‑to‑day security operations, major incidents, and security initiatives. This role reports directly to the Information Security Lead and focuses on delivering measurable security improvements through projects, leadership, and cross‑functional collaboration.
ResponsibilitiesYou will take on a leadership role in driving and continuously improving Exasol’s security operations capabilities across cloud, infrastructure, endpoint, and SaaS environments within regulated European operating environments. This includes, but is not limited to:
- Improving Exasol’s vulnerability management processes, including triage, risk‑based prioritization, remediation tracking, and reporting in line with EU regulatory expectations.
- Leading security incident response activities and acting as the primary escalation point for complex or high‑impact incidents, including incident classification, regulatory notification preparation, and post‑incident reporting aligned with DORA and NIS
2. - Improving visibility into threats and attacks through effective logging, monitoring, and detection capabilities that support regulatory incident reporting timelines.
- Leading major security initiatives and programs, such as data loss prevention (DLP), penetration testing, and security vulnerability remediation, supporting operational resilience requirements.
- Providing high‑level technical oversight for the configuration, operation, and continuous improvement of security platforms and tools (SIEM, EDR/XDR, MDM, IAM), ensuring they support EU incident detection and response obligations.
- Improving cloud security, particularly in AWS environments, by applying security best practices and working closely with IT and engineering teams to meet EU regulatory and resilience requirements.
- Leading threat intelligence activities, monitoring global and cloud‑specific threat trends, and assessing their relevance to Exasol from a European regulatory risk perspective.
- Supporting security architecture reviews and ensuring security‑by‑design principles are applied across all cloud systems and environments subject to EU regulatory oversight.
- Supporting governance, risk management, and compliance activities, including security controls, risk assessments, and audits related to ISO 27001, DORA, and NIS
2. - Leading information security awareness activities, including phishing simulations and security training, aligned with EU compliance and supervisory expectations.
- Strong practical experience with AWS security services, such as Cloud Trail, Cloud Watch, Guard Duty, Security Hub, and IAM.
- Direct experience interacting with European regulators or supervisory authorities as part of security incident handling, audits, or compliance reviews.
- Proven experience acting as an accountable incident lead to security incidents subject to mandatory EU regulatory notification and supervisory follow‑up.
- Hands‑on experience executing DORA and NIS2 incident handling obligations, including formal incident classification, regulatory notification preparation, timeline management, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).