IT Security Specialist | IT Security Spezialist (m/w/d)

FERCHAU GmbH Niederlassung Nürnberg City

Nürnberg, Mittelfranken, Bayern, Deutschland
Published Apr 13, 2026
Full-time
No information

Job Summary

As an IT Security Specialist at FERCHAU, you will be responsible for implementing and monitoring security measures for automation systems within critical infrastructure (KRITIS) environments. Your daily activities will involve conducting risk assessments in Measurement, Control, and Regulation (MSR) environments, performing vulnerability analyses, and executing penetration tests on industrial control networks. You will play a pivotal role in ensuring compliance with ISO/IEC 27001, NIS2 directives, and BSI-KRITIS requirements. Beyond technical implementation, you will develop security guidelines, coordinate audits, and lead incident response efforts for industrial security breaches. This role is highly attractive for professionals seeking to work at the intersection of IT security and industrial automation, offering flexible working hours through flextime, comprehensive professional development opportunities, and the chance to shape security protocols for critical systems in a family-owned engineering leader.

Required Skills

Education

Completed degree in Computer Science, Automation Technology, Electrical Engineering, or a comparable qualification.

Experience

  • Professional experience in IT Security with a focus on automation or industrial systems
  • Experience in implementing security measures according to ISO/IEC 27001 and KRITIS regulations
  • Practical experience with industrial automation tools such as Beckhoff TwinCAT or Siemens S7/TIA Portal
  • Proven track record in conducting risk assessments and vulnerability analyses in technical environments
  • Experience in managing incident response and reporting obligations under NIS2 or BSI laws

Languages

German (Fluent)English (Basic)

Additional

  • Must have knowledge of German at B2 level or higher as it is the primary working language. Position involves handling critical infrastructure (KRITIS) requirements and mandatory reporting under NIS2.