This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Security Operations Manager leads and continuously improves security operations across Exasol’s cloud, infrastructure, endpoints, and SaaS environments, with a strong focus on AWS-based environments, incident response, and regulatory aligned security operations. The role owns day-to-day security operations, major incidents, and security initiatives. This role reports directly to the Information Security Lead and focuses on delivering measurable security improvements through projects, leadership, and cross-functional collaboration.
Job Responsibility:
Improving Exasol’s vulnerability management processes, including triage, risk-based prioritization, remediation tracking, and reporting in line with EU regulatory expectations
Leading security incident response activities and acting as the primary escalation point for complex or high-impact incidents, including incident classification, regulatory notification preparation, and post-incident reporting aligned with DORA and NIS2
Improving visibility into threats and attacks through effective logging, monitoring, and detection capabilities that support regulatory incident reporting timelines
Leading major security initiatives and programs, such as data loss prevention (DLP), penetration testing, and security vulnerability remediation, supporting operational resilience requirements
Providing high-level technical oversight for the configuration, operation, and continuous improvement of security platforms and tools (SIEM, EDR/XDR, MDM, IAM), ensuring they support EU incident detection and response obligations
Improving cloud security, particularly in AWS environments, by applying security best practices and working closely with IT and engineering teams to meet EU regulatory and resilience requirements
Leading threat intelligence activities, monitoring global and cloud-specific threat trends, and assessing their relevance to Exasol from a European regulatory risk perspective
Supporting security architecture reviews and ensuring security-by-design principles are applied across all cloud systems and environments subject to EU regulatory oversight
Supporting governance, risk management, and compliance activities, including security controls, risk assessments, and audits related to ISO 27001, DORA, and NIS2
Leading information security awareness activities, including phishing simulations and security training, aligned with EU compliance and supervisory expectations
Requirements:
Strong practical experience with AWS security services, such as CloudTrail, CloudWatch, GuardDuty, Security Hub, and IAM
Direct experience interacting with European regulators or supervisory authorities as part of security incident handling, audits, or compliance reviews
Proven experience acting as an accountable incident lead to security incidents subject to mandatory EU regulatory notification and supervisory follow-up
Hands-on experience executing DORA and NIS2 incident handling obligations, including formal incident classification, regulatory notification preparation, timeline management, and post-incident supervisory follow-ups
Strong SOC / security operations background with SIEM and EDR/XDR platforms
Experience supporting EU regulatory audits or supervisory reviews (e.g. ISO 27001)
Ability to translate regulatory requirements into effective security operations and processes
Experience with threat intelligence, detection engineering, or MITRE ATT&CK
Strong communication skills across technical teams and senior stakeholders