The Role
A Hamburg-based health-tech company building AI-driven clinical software used by hospitals across Germany is looking for an IT Platform Engineer who will design and build the IT compliance framework from scratch - not maintain an existing one. This person will own the internal platform, drive BSI C5 and ISO 27001 certification, and set up the ISMS that underpins the company's medical AI products.
This is not a ticket-taker role. Administering a mature environment is not what this requires. The company needs someone who builds, shapes, and drives.
What You Will Actually Do
- Design and implement the ISMS from the ground up: policies, controls, risk register, audit readiness - for BSI C5 and ISO 27001 certification
- Own Microsoft Entra ID / Azure AD: SSO, Conditional Access, MFA, identity lifecycle, licensing
- Manage and harden the Atlassian stack (Jira, Confluence), Git platforms (GitHub, GitLab), and Microsoft 365
- Implement RBAC, SAML/OIDC/SCIM integrations, and audit trails that satisfy C5, ISO 27001, and ISO 13485
- Automate user provisioning, license allocation, and policy enforcement via scripting and infrastructure as code
- Set up monitoring, alerting, and availability tracking for core platforms
- Act as first-line internal IT support for a small, fast-moving team
- Manage SaaS vendors, track licenses, and optimize spend
Who You Are
3+ years in IT administration, systems engineering, or platform engineering. More important than years is what you have actually built. A track record of taking ownership - designing and implementing systems and processes, not just operating them. Experience in a startup or similarly dynamic environment where you had to figure things out without a playbook.
Must-Haves
- Deep hands-on expertise with Microsoft Entra ID / Azure AD (Conditional Access, SSO, MFA, identity governance)
- Strong administration experience with Jira, Confluence, GitHub or GitLab, and Microsoft 365
- Solid identity and access management knowledge: RBAC, SAML, OIDC, SCIM
- Experience designing and implementing compliance frameworks (BSI C5, ISO 27001, or similar) - not just working within them
- Proactive, ownership-driven mindset: you see problems and fix them without being told
- German language proficiency B2+ (the team works in German)
- Comfortable working in a small team with high autonomy
Nice-to-Haves
- Scripting and automation: PowerShell, Bash, Terraform, Ansible
- Experience in regulated environments (healthcare, medical devices, ISO 13485)
- MDM / endpoint management
- Monitoring stack experience (Grafana, Prometheus, Azure Monitor)
- Networking basics (DNS, VPN, firewalls)
Why This Is Worth Your Time
- Full ownership of the internal platform domain - you build it, you run it
- Growth path to IT Security / Compliance Lead as the company grows
- Hybrid setup in Hamburg-Eppendorf (2-3 days on-site), flexible hours, 30 vacation days
- Training budget and conference attendance
- Direct impact on patient care through German-made medical AI
- Non-profit with stable funding, not a burn-through startup
- Salary: EUR 65,000 - 90,000 (fixed, no variable component)
What Will Not Be Considered
- No German language capability
- No Entra ID / Azure AD experience
- Less than 3 years relevant experience
- Pure operations or maintenance background without examples of building or redesigning systems
5 CV Screening Criteria (every CV is checked against these)
1. Entra ID depth - Have they configured Conditional Access policies, SAML/OIDC integrations, and identity lifecycle management themselves? "Worked with Azure AD" in a bullet point is not enough. Specific examples required.
2. Compliance building, not compliance operating - Have they designed and implemented an ISMS, run a certification process (C5, ISO 27001, BSI Grundschutz), or built a compliance program from scratch? Administering an existing certified environment does not count.
3. Ownership evidence - Can a specific system, process, or platform be pointed to that they built, redesigned, or drove from concept to production? If the CV reads like a list of systems "supported" or "maintained," it is rejected.
4. Startup / small-team signal - Have they worked in a company under 50 people, or been the sole IT/platform person? In a small team there is no backup. Candidates who have operated without a safety net are preferred.
5. Automation and infrastructure-as-code - Do they script (PowerShell, Bash) and use Terraform or Ansible? Not a hard must-have per the client, but it is the difference between someone who builds and someone who clicks. No automation examples equals a weaker profile.
EU AI Act Compliance in Recruitment
This company uses AI-assisted screening tools as part of their recruitment process. As a provider and deployer of AI systems for recruitment (Annex III, high-risk under the EU AI Act), they maintain full compliance with the applicable obligations under Regulation 2024/1689. This includes:
- Transparency: All AI-assisted screening decisions are disclosed to candidates
- Human oversight: Every AI-generated assessment is reviewed by a human before any hiring decision
- Non-discrimination: AI models are tested for bias and demographic fairness
- Data governance: Candidate data is processed in accordance with GDPR and AI Act data governance requirements
- Documentation and traceability: The screening process is fully documented, auditable, and logged
Application data will be processed in compliance with the EU AI Act and GDPR. Questions about how AI is used in this process can be raised at any stage.

