Your tasks
CLARK is one of the worlds leading insurtechs. As the first unicorn company from Frankfurt were dedicated to building the insurance expert in our customers pockets to keep for a lifetime. Leveraging cutting-edge technology and intuitive mobile apps we empower private customers to effortlessly manage compare and optimize their insurance situation online. Our digital platform seamlessly integrates personalized consultation from expert advisors ensuring a holistic customer experience at their fingertips.
Our culture fosters simplicity reliability and care for our customers and their needs uniting employees under a shared purpose: to protect their world and give them peace of mind.
We are supported by investors such as Allianz X Portage Tencent White Star Capital and Yabeo. Our team representing 40 nationalities operates across Germany Switzerland the UK France and the Netherlands. We pioneer to reinvent insurance day by day.
Join our diverse team and contribute to our vision to give every single customer peace of mind with their insurance situation. Take the next step in your career with us at CLARK!
Your main tasks will include:
- Be the to-go expert for security assessments during the product development lifecycle
- Be the technical expert within the security team
- Develop automate or enhance internal security tools and services in different areas such as:
- CI/CD (Github Jenkins)
- Web and Mobile Application Security Testing (DAST SAST Container Security)
- Cloud Infrastructure (IaC setup Security Hub)
- Incident Detection and Response (Splunk SOAR EDR)
- Discover analyse prioritise and orchestrate remediation of technical risks on Clark Groups products andinfrastructure
Requirements
- 5 to 8 years of tactical operational experience in Information Security
- You consider yourself as a technical element
- You have hands on experience in at least 2 of the following topics:
- Vulnerability assessment - Identifying and analysing
- technical risks and vulnerabilities in applicationsproducts features.
- Securing infrastructure as code setups
- including CI/CD deployments with git and docker andinfrastructure automation (e.g. Terraform Ansible)
- Pentest or technical security assessment.
- Mobile Application Security.
- Implementation of Security Incident Management and Business Continuity Management.
- Security Architecture.
- DevSecOps
- Container Security (Kubernetes Docker)
- Cloud Security ideally AWS.
- Automation and shifting security left are no brainers for you
- Principle Engineer or Architect role are your main considerations for a career path
- Know-how in programming especially in one of the following languages: Python Bash Ruby on Rails
- Fluent English language skills (German is a plus) in speaking and writing.