- Help mature and expand our red teaming capabilities, contributing to methodology, rules of engagement, tooling and reporting
- Plan and execute penetration tests and red team engagements against applications, cloud services, infrastructure and critical systems
- Develop and apply AI-assisted penetration testing using AI to accelerate reconnaissance, exploitation, payload generation and reporting across the engagement lifecycle
- Test the security of our internal AI platforms, including prompt injection, model abuse, data exfiltration and other AI-specific attack techniques
- Work with the blue team to optimise detection and response, feeding real attack scenarios we were able to exploit into new detections; run adversary emulation and purple team exercises to validate detection and response capabilities
- Document findings clearly, prioritise by risk and drive remediation with the affected teams; contribute to security standards, KPIs and reporting
- Support incident handling and root-cause analysis where offensive security expertise adds value
- Work closely with infrastructure, development, operations, governance and risk teams to embed offensive testing into the wider security lifecycle
Requirements
- Several years of hands-on experience in penetration testing, red teaming or offensive security
- Proven penetration testing skills across at least two areas such as web and application testing, network and infrastructure, cloud (Azure / M365), AI, Active Directory / identity, or social engineering
- Practical experience with offensive tooling and frameworks such as Metasploit, Burp Suite or comparable, and familiarity with MITRE ATT&CK
- Experience with scripting and exploit development, for example Python, PowerShell, Golang or similar
- Solid understanding of how to use AI in offensive security and awareness of AI-specific attack surfaces (e.g. prompt injection, model and data abuse); knowledge of common frameworks such as OWASP, MITRE ATT&CK or NIST
- Structured, reliable and solution-oriented way of working
- Strong communication skills and the ability to make technical findings understandable and actionable for technical and non-technical audiences
- Very good English skills; German is an advantage
- Willingness to participate in 24/7 on-call duty
- Nice to Have: Experience in regulated environments or financial services
- Offensive security certifications such as OSCP, OSEP, CRTO, CRTP or GPEN
Core Competencies
Demonstrates expertise in penetration testing and red teaming, with a strong focus on AI-assisted security techniques and collaboration with blue teams to enhance detection and response capabilities. Proficient in offensive security methodologies and frameworks, with a commitment to clear documentation and risk prioritization.
Highest-signal resume keywords
- Penetration Testing
- Red Teaming
- AI-Assisted Security
- Offensive Security Certifications
- Offensive Tooling and Frameworks
ATS Optimization Keywords
Hard Skills
- Penetration Testing
- Red Teaming
- Scripting
- Exploit Development
- AI-Specific Attack Techniques
- Web and Application Testing
- Network and Infrastructure Testing
- Cloud Security (Azure / M365)
- Active Directory / Identity Testing
- Social Engineering
Soft Skills
- Strong Communication Skills
- Solution-Oriented Working
- Ability to Simplify Technical Findings
Certifications & Qualifications
Industry Keywords
- Offensive Security
- Incident Handling
- Root-Cause Analysis
- Regulated Environments
- Financial Services
Tools & Technologies
- Metasploit
- Burp Suite
- MITRE ATT&CK
- OWASP
- NIST