IT Administrator - #2683133
WhyHireWrong?
Date: vor 20 Stunden
Stadt: Hamburg
Vertragstyp: Ganztags
Arbeitsplan: Volle Tag
The Role
A Hamburg-based health-tech company building AI-driven clinical software used by hospitals across Germany is looking for an IT Platform Engineer who will design and build the IT compliance framework from scratch - not maintain an existing one. This person will own the internal platform, drive BSI C5 and ISO 27001 certification, and set up the ISMS that underpins the company's medical AI products.
This is not a ticket-taker role. Administering a mature environment is not what this requires. The company needs someone who builds, shapes, and drives.
What You Will Actually Do
3+ years in IT administration, systems engineering, or platform engineering. More important than years is what you have actually built. A track record of taking ownership - designing and implementing systems and processes, not just operating them. Experience in a startup or similarly dynamic environment where you had to figure things out without a playbook.
Must-Haves
This company uses AI-assisted screening tools as part of their recruitment process. As a provider and deployer of AI systems for recruitment (Annex III, high-risk under the EU AI Act), they maintain full compliance with the applicable obligations under Regulation 2024/1689. This includes:
A Hamburg-based health-tech company building AI-driven clinical software used by hospitals across Germany is looking for an IT Platform Engineer who will design and build the IT compliance framework from scratch - not maintain an existing one. This person will own the internal platform, drive BSI C5 and ISO 27001 certification, and set up the ISMS that underpins the company's medical AI products.
This is not a ticket-taker role. Administering a mature environment is not what this requires. The company needs someone who builds, shapes, and drives.
What You Will Actually Do
- Design and implement the ISMS from the ground up: policies, controls, risk register, audit readiness - for BSI C5 and ISO 27001 certification
- Own Microsoft Entra ID / Azure AD: SSO, Conditional Access, MFA, identity lifecycle, licensing
- Manage and harden the Atlassian stack (Jira, Confluence), Git platforms (GitHub, GitLab), and Microsoft 365
- Implement RBAC, SAML/OIDC/SCIM integrations, and audit trails that satisfy C5, ISO 27001, and ISO 13485
- Automate user provisioning, license allocation, and policy enforcement via scripting and infrastructure as code
- Set up monitoring, alerting, and availability tracking for core platforms
- Act as first-line internal IT support for a small, fast-moving team
- Manage SaaS vendors, track licenses, and optimize spend
3+ years in IT administration, systems engineering, or platform engineering. More important than years is what you have actually built. A track record of taking ownership - designing and implementing systems and processes, not just operating them. Experience in a startup or similarly dynamic environment where you had to figure things out without a playbook.
Must-Haves
- Deep hands-on expertise with Microsoft Entra ID / Azure AD (Conditional Access, SSO, MFA, identity governance)
- Strong administration experience with Jira, Confluence, GitHub or GitLab, and Microsoft 365
- Solid identity and access management knowledge: RBAC, SAML, OIDC, SCIM
- Experience designing and implementing compliance frameworks (BSI C5, ISO 27001, or similar) - not just working within them
- Proactive, ownership-driven mindset: you see problems and fix them without being told
- German language proficiency B2+ (the team works in German)
- Comfortable working in a small team with high autonomy
- Scripting and automation: PowerShell, Bash, Terraform, Ansible
- Experience in regulated environments (healthcare, medical devices, ISO 13485)
- MDM / endpoint management
- Monitoring stack experience (Grafana, Prometheus, Azure Monitor)
- Networking basics (DNS, VPN, firewalls)
- Full ownership of the internal platform domain - you build it, you run it
- Growth path to IT Security / Compliance Lead as the company grows
- Hybrid setup in Hamburg-Eppendorf (2-3 days on-site), flexible hours, 30 vacation days
- Training budget and conference attendance
- Direct impact on patient care through German-made medical AI
- Non-profit with stable funding, not a burn-through startup
- Salary: EUR 65,000 - 90,000 (fixed, no variable component)
- No German language capability
- No Entra ID / Azure AD experience
- Less than 3 years relevant experience
- Pure operations or maintenance background without examples of building or redesigning systems
- Entra ID depth - Have they configured Conditional Access policies, SAML/OIDC integrations, and identity lifecycle management themselves? "Worked with Azure AD" in a bullet point is not enough. Specific examples required.
- Compliance building, not compliance operating - Have they designed and implemented an ISMS, run a certification process (C5, ISO 27001, BSI Grundschutz), or built a compliance program from scratch? Administering an existing certified environment does not count.
- Ownership evidence - Can a specific system, process, or platform be pointed to that they built, redesigned, or drove from concept to production? If the CV reads like a list of systems "supported" or "maintained," it is rejected.
- Startup / small-team signal - Have they worked in a company under 50 people, or been the sole IT/platform person? In a small team there is no backup. Candidates who have operated without a safety net are preferred.
- Automation and infrastructure-as-code - Do they script (PowerShell, Bash) and use Terraform or Ansible? Not a hard must-have per the client, but it is the difference between someone who builds and someone who clicks. No automation examples equals a weaker profile.
This company uses AI-assisted screening tools as part of their recruitment process. As a provider and deployer of AI systems for recruitment (Annex III, high-risk under the EU AI Act), they maintain full compliance with the applicable obligations under Regulation 2024/1689. This includes:
- Transparency: All AI-assisted screening decisions are disclosed to candidates
- Human oversight: Every AI-generated assessment is reviewed by a human before any hiring decision
- Non-discrimination: AI models are tested for bias and demographic fairness
- Data governance: Candidate data is processed in accordance with GDPR and AI Act data governance requirements
- Documentation and traceability: The screening process is fully documented, auditable, and logged
Wie bewerbe ich mich?
Um sich für diesen Job zu bewerben, müssen Sie auf unserer Website autorisieren. Wenn Sie noch kein Konto haben, registrieren Sie sich bitte.
Veröffentlichen Sie einen LebenslaufÄhnliche Jobs
Hörakustiker / Hörgeräteakustiker - Meister (m/w/d)
OnTarget-Search GmbH,
vor 37 Sekunden
Ihre neue Herausforderung in der Hörakustik Für ein etabliertes Unternehmen im Bereich Hörakustik und Hörgeräte suchen wir einen leidenschaftlichen Hörakustiker / Hörgeräteakustiker - Meister am Standort 21073 Hamburg Harburg. Was Sie bekommen: Einen hochmodernen Arbeitsplatz, ein überdurchschnittliches Gehalt + Bonus...
Geschäftsführer, Manager, Quereinsteiger, Macher als Franchisepartner in Eimsbüttel
Franchise Business Club,
€72,000
-
€214,000
/ Jahr
vor 1 Stunde
... dann haben Sie es gerade GEFUNDEN! Der Franchise Business Club bietet Ihnen viele spannende Herausforderungen verbunden mit einer unternehmerischen Tätigkeit regional, an Ihrem Standort! Sie wollen sich selbstständig machen – haben aber keine eigene Idee? Dann ist Franchising goldrichtig...
Area Manager (m/w/d) in Hamburg
Amplifon,
vor 2 Stunden
Wir sind Amplifon, der Weltmarktführer im Hörgeräte-Einzelhandel. In Deutschland agieren wir mit mehr als 2.000 Mitarbeitenden bundesweit in über 600 eigenen Fachgeschäften und gemeinsam machen wir jeden Tag mehr möglich. Wir verändern mehr Leben. Wir arbeiten mehr an innovativen Projekten...