Your tasks
CLARK is one of the world's leading insurtechs. As the first unicorn company from Frankfurt, we're dedicated to building the insurance expert in our customer’s pockets to keep for a lifetime. Leveraging cutting-edge technology and intuitive mobile apps, we empower private customers to effortlessly manage, compare, and optimize their insurance situation online. Our digital platform seamlessly integrates personalized consultation from expert advisors, ensuring a holistic customer experience at their fingertips.
Our culture fosters simplicity, reliability and care for our customers and their needs, uniting employees under a shared purpose: to protect their world and give them peace of mind.
We are supported by investors such as Allianz X, Portage, Tencent, White Star Capital, and Yabeo. Our team, representing 40 nationalities, operates across Germany, Switzerland, the UK, France, and the Netherlands. We pioneer to reinvent insurance day by day.
Join our diverse team and contribute to our vision to give every single customer peace of mind with their insurance situation. Take the next step in your career with us at CLARK!
Your main tasks will include:
- Be the to-go expert for security assessments during the product development lifecycle
- Be the technical expert within the security team
- Develop, automate or enhance internal security tools and services in different areas, such as:
- CI/CD (Github, Jenkins)
- Web and Mobile Application Security Testing (DAST, SAST, Container Security…)
- Cloud Infrastructure (IaC setup, Security Hub)
- Incident Detection and Response (Splunk, SOAR, EDR)
- Discover, analyse, prioritise, and orchestrate remediation of technical risks on Clark Group’s products andinfrastructure
Requirements
- 5 to 8 years of tactical operational experience in Information Security
- You consider yourself as a technical element
- You have hands on experience in at least 2 of the following topics:
- Vulnerability assessment - Identifying and analysing
- technical risks and vulnerabilities in applications,products, features.
- Securing infrastructure as code setups
- including CI/CD deployments with git and docker andinfrastructure automation (e.g. Terraform, Ansible)
- Pentest or technical security assessment.
- Mobile Application Security.
- Implementation of Security Incident Management and Business Continuity Management.
- Security Architecture.
- DevSecOps
- Container Security (Kubernetes, Docker)
- Cloud Security, ideally AWS.
- Automation and shifting security left are no brainers for you
- Principle Engineer or Architect role are your main considerations for a career path
- Know-how in programming especially in one of the following languages: Python, Bash, Ruby on Rails
- Fluent English language skills (German is a plus) in speaking and writing.