Home / Jobs in Germany

W

Senior IT & Security Engineer (AI-Native)

Germany completa AI Solutions Lead
Interested in this role?

Apply or review the details on the original posting.

Apply for this role

Original posting on LinkedIn

🚀 We Don't Have an Office. We Still Have IT.

Most companies scale IT by hiring more admins to answer more tickets. We'd rather hire one engineer who automates the tickets out of existence.
WorkFlex is a remote-only company. Our "office" is ~140 laptops (half Windows, half Mac) spread across beaches, mountains, and home offices around the world. Your mission: build the identity, device, and security platform for a company that holds ISO 27001 and is heading toward C5 / SOC 2 Type 2.
The starting position is rare: no legacy Active Directory, no on-prem servers, no office network. A greenfield with a clear mandate to build.

🌍 The Lifestyle: 183 Days of Workations

We are a remote-only company. You can work from a beach, a mountain, or your home office. We offer 183 days of workations per year because we believe the best solutions come from people who are inspired by their surroundings. Your platform has to survive hotel Wi-Fi and captive portals. You'll be building for exactly the life you're living. Note: for data protection and security reasons, we hire EU-based only for this role.

🛠️ The Workflow: AI-Native IT

At WorkFlex, we operate differently. If your happy place is clicking through admin portals all day, you are the wrong profile.

Automation over administration: You script against the Microsoft Graph API, keep configuration as code, and let agents handle the routine.
Orchestration over grinding: You use Claude Code, self-hosted n8n, and agentic workflows to build internal tooling at a speed that was impossible two years ago.
End-to-end ownership: You design it, you build it, you run it. Spending decisions are made together with the Head of Technology. No committees.

🎯 What You Will Do

Mission #1: Zero-touch mixed fleet. Roll out device management across ~140 laptops in a dozen+ countries: Intune and Autopilot for Windows, Apple Business Manager plus the MDM of your choice for Mac. New devices ship straight from the supplier to the new hire and enroll themselves. This is as much change management as engineering.
Own the full device lifecycle. Procurement, cross-border shipping, retrieval, secure wiping, repairs, replacements, re-deployment. Hardware logistics without an office is hard. Whether the answer is a lifecycle partner or a better process is your call.
Make identity the control plane. Entra ID at the center: Conditional Access, phishing-resistant MFA (passkeys), just-in-time admin access, and a role-based permission model with recurring access reviews.
Own security engineering. Endpoint protection, email security, phishing simulations, patching and vulnerability management, hardening baselines, incident-response readiness. Deep forensics stays with our external partner on retainer.
Own IT onboarding and the whole joiner-mover-leaver lifecycle. HRIS-triggered provisioning (Personio), built with our People & Culture team: accounts, groups, licenses, and hardware ordered automatically by role. A new hire's first day should just work. Offboarding is one trigger that revokes everything, everywhere.
Own the internal SaaS landscape. Tool administration grew organically across teams. You centralize it, then run it for good: inventory, admin ownership, access management, governance, and licensing. SCIM where possible, shadow-IT discovery, license optimization as routine. Functional ownership of each tool stays with the teams.
Own real architecture debates. We hold a few deliberate, non-obvious positions on identity and blast radius. We share specifics in the interviews, not in a public job ad. You get to challenge or harden them.
Evolve our zero-trust network. A self-hosted, WireGuard-based overlay provides defense in depth. DevOps operates it; you shape access policy and device posture. There is no VPN estate to babysit.
Build our internal IT agent. An AI assistant in Teams that handles routine requests and runs safe self-service actions behind approval gates, with a full audit trail.
Feed the auditors automatically. Evidence pipelines (device compliance, access reviews, JML logs) for ISO 27001 surveillance and our path toward C5 / SOC 2 Type 2. The ISMS is already in place.
Set AI guardrails without killing the culture. We use Claude Team, Gemini, and self-hosted n8n heavily, and people choose their own tools. You add the data boundaries that keep it that way.

⭐ What You Need to Succeed

Experience: 4+ years running modern Microsoft-stack IT (Entra ID / M365, ideally Intune). You have designed and operated environments, not just closed tickets in them. Mixed-fleet experience with macOS, or a credible plan to get there.
An engineer's toolkit: Fluent in PowerShell, Python, or TypeScript and comfortable with the Microsoft Graph API. If you do something twice in a portal, you script it before the third time.
Security engineering chops: You have rolled out EDR, hardened email authentication, and know your way around CIS baselines.
AI-native instincts: You are already a power user of Claude and LLM tools. You know how to prompt, chain, and audit AI output, and you know when generated code is robust and when it's a hallucination.
Zero-trust literacy: Conditional Access, device posture, least privilege, break-glass procedures. Familiarity with WireGuard-based tools (NetBird, Tailscale) is a plus.
Communication mastery: You can sit with a non-technical colleague, listen to their frustrations, and translate them into a solution. You can say no without condescension. You are a listener first, an engineer second.
Self-sufficiency: You define your own roadmap based on where you create the most value. You report directly to the Head of Technology. Your peers are Applied AI Engineers who do for single departments what you do for the whole company.
Trustworthiness: You will hold the keys to everything. Least privilege applies to you, too.
EU-based, English C1+. The whole company runs in English.

➕ Bonus Points

Dedicated Apple MDM experience (Jamf, Kandji, Mosyle)
ISO 27001 / C5 / SOC 2

Listing structured with AI support from LinkedIn. Always confirm the conditions with the company before applying.
FAQ

Frequently asked questions

Who offers this AI Solutions Lead role in Germany?

The role is posted by WorkFlex from LinkedIn. aiManagerJobs is a directory that collects, structures and links to the original source, it is not the employer. Hiring is handled by the company.

What type of role is it?

This is a ai solutions lead position on a completa basis in Germany. The exact schedule and conditions are in the original posting from the company.

How do I apply for this role in Germany?

Use the apply button to go to the original source (LinkedIn) and follow the company instructions. You can also create an alert and receive new Germany roles by email.

Keep looking

Similar roles

N

Manager, Solutions Architecture - NVIDIA AI Cloud PartnersFeatured

NVIDIA
Germany
AI Solutions Leadcompleta
hace 1 sem
C

Strategic Sales Executive - AI & Agentic

Cornerstone OnDemand
Germany
AI Solutions Leadcompleta
hace 5 días
N

Technical AI Engagement Lead

Neurons Lab
Germany
AI Solutions Leadcompleta
hace 1 sem
M

Enterprise Sales Director (m/w/d) - Data & AI Solutions (m/w/d)

Michael Page
Germany
Head of AIcompleta
hace 1 sem
Admin