Ihre zukünftigen Aufgaben
- Architektur & Strategie: Als wichtiger Teil des Teams gestalten Sie im direkten Austausch die Brücke zwischen unserer etablierten On-Premise-Welt und modernen Cloud-Services (M365, Azure). Sie übernehmen strategische Mitverantwortung und tragen zur Entwicklung eines zukunftssicheren Gesamtsystems bei.
- Innovation & Projekte: Sie treiben eigenverantwortlich Projekte rund um Microsoft 365, unterstützen bei Software-Implementierungen und sorgen durch kurze Entscheidungswege dafür, dass unsere technologische Landschaft sich kontinuierlich weiterentwickelt.
- Automatisierung & Effizienz: Sie optimieren unsere Prozesse durch Skripting und den Einsatz von Tools wie ManageEngine und heben Effizienzen – von der Softwareverteilung bis zum Identity Management.
- Security & Identity:Sie wirken bei der Konzeption und dem Ausbau unserer Sicherheitsarchitektur mit (PKI, Conditional Access, Microsoft Entra ID) und stellen einen sicheren Betrieb sicher.
|
Bei uns arbeiten Sie...
- Sie sind Teil eines Teams, das unsere IT-Security-Umgebung administriert (On‑Prem & Cloud)
- Absicherung von Active Directory, Identitäten und Zugriffen
- Betrieb, Konfiguration und Weiterentwicklung von EDR‑/XDR‑Lösungen
- Kontinuierliches Hardening von Servern, Firewalls und Netzwerken
- Planung und Umsetzung von DMZ‑ und Sicherheitsarchitekturen
- Schwachstellenmanagement: Analyse, Bewertung und Behebung
(inkl. Nessus, CVEs, VULDB) - Log‑ und Ereignisanalyse (SIEM, Firewall, Netzwerk)
- Unterstützung bei Security‑Incidents inkl. Analyse und Lessons Learned
- Härtung und Absicherung von OT‑Umgebungen
- Dokumentation, Reporting und Mitarbeit in IT‑ und Security-Projekten
|
Bei uns arbeiten Sie...
- Sie sind Teil eines Teams, das unsere IT-Security-Umgebung administriert (On‑Prem & Cloud)
- Absicherung von Active Directory, Identitäten und Zugriffen
- Betrieb, Konfiguration und Weiterentwicklung von EDR‑/XDR‑Lösungen
- Kontinuierliches Hardening von Servern, Firewalls und Netzwerken
- Planung und Umsetzung von DMZ‑ und Sicherheitsarchitekturen
- Schwachstellenmanagement: Analyse, Bewertung und Behebung
(inkl. Nessus, CVEs, VULDB) - Log‑ und Ereignisanalyse (SIEM, Firewall, Netzwerk)
- Unterstützung bei Security‑Incidents inkl. Analyse und Lessons Learned
- Härtung und Absicherung von OT‑Umgebungen
- Dokumentation, Reporting und Mitarbeit in IT‑ und Security-Projekten
|
DEINE MISSION:
- Eigenverantwortliche Bearbeitung und Analyse von Second-Level-Tickets sowie Eskalationsfällen
- Administration und Weiterentwicklung unserer Windows Server- und Microsoft 365-Umgebung
- Verwaltung und Pflege von Entra ID / Azure Active Directory sowie Gruppenrichtlinien und Berechtigungsstrukturen
- Unterstützung und Schulung des First-Level-Teams bei komplexeren Störungen
- Planung und Umsetzung von IT-Projekten in den Bereichen Netzwerk, Security, Cloud und Endpoint Management
- Automatisierung von Routineaufgaben mittels PowerShell-Scripting
- Erstellung und Pflege technischer Dokumentationen und Systemhandbücher
- Aufbau und Weiterentwicklung der internen Knowledge Base
- Aktive Mitarbeit bei IT-Sicherheits- und Datenschutzmaßnahmen
|
Your responsibilities
- You establish, operate and continuously develop the information security management system (ISMS) of the Austrian Academy of Sciences (ÖAW) in line with ISO/IEC 27001.
- You act as the central point of contact and coordination for all organisation-wide matters relating to information security management.
- You prepare decision papers and recommendations on appropriate information security measures for the Presidential Board and the Directorate for Institutes and Infrastructure (DII).
- You maintain the ISMS documentation framework and steer the drafting, consultation, approval and periodic review of strategies, policies, standards and procedures.
- You coordinate information security risk management, support the identification and assessment of risks, and monitor the implementation of approved risk treatment measures.
- Together with the relevant technical units, you define requirements for logging, security monitoring and incident management, and verify that these are implemented appropriately and remain effective.
- You plan and coordinate internal and external information security audits, security reviews and penetration tests, and follow up on the resulting actions.
- You produce regular reports on the risk landscape, security incidents, control effectiveness, the status of measures and the maturity of the ISMS for the Presidential Board and the DII, and you prepare the ISMS management review.
- You design and coordinate target-group-specific training and awareness programmes and help advance the ÖAW's information security culture.
- You monitor the implementation and effectiveness of the security measures in place and track deviations and improvement measures in a documented and auditable way.
- You work closely with the Legal and Compliance Department as well as with other internal teams and external partners to ensure compliance with legal requirements and sector-specific standards.
|