Penetration Tester / Ethical Hacker

Hhw Group

Deutschland

Vor Ort

EUR 65.000 - 100.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Verschicke keinen generischen Lebenslauf — erstelle einen Lebenslauf und ein Anschreiben, die genau auf diese Rolle zugeschnitten sind.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Hhw Group is seeking a skilled Penetration Tester / Ethical Hacker to assess security across systems, apps, networks, and cloud infrastructure. You will simulate real-world attacks, identify vulnerabilities, and deliver remediation guidance to strengthen defenses.

You will perform testing with Burp Suite, Metasploit, Nmap, Kali Linux, and scripting in Python/PowerShell/Bash, while aligning with OWASP Top 10 and NIST frameworks. Collaboration with security engineers and IT teams is essential.

Qualifikationen

  • 2–5+ years of penetration testing experience.
  • Proficiency with offensive security methodologies and tools.
  • Strong experience testing web apps, APIs, networks, and cloud environments.
  • Ability to clearly document vulnerabilities and explain exploitation steps to both technical and non-technical stakeholders.

Aufgaben

  • Perform penetration tests on web applications, APIs, mobile apps, cloud platforms, networks, and infrastructure.
  • Conduct internal and external vulnerability assessments and exploit identified weaknesses.
  • Simulate advanced persistent threat (APT) attack behaviors to evaluate detection and response capabilities.
  • Conduct social engineering assessments (phishing, vishing, physical tests) when approved and in scope.
  • Document findings clearly and concisely, including exploit techniques, impact, and severity ratings.
  • Provide actionable remediation recommendations to reduce risks and prevent exploitation.
  • Present results to engineering, leadership, and executive stakeholders as needed.

Kenntnisse

Penetration testing
Red teaming
Web apps & APIs testing
Documentation & communication
Security mindset & threat modeling

Tools

Burp Suite
Metasploit
Nmap
Kali Linux
Cobalt Strike
Python
PowerShell
Bash
JavaScript

Jobbeschreibung

Position Summary

The Penetration Tester / Ethical Hacker is responsible for assessing the security posture of the organization’s systems, applications, networks, and infrastructure by simulating real‑world cyberattacks. This role identifies vulnerabilities, exploits weaknesses in a controlled manner, and provides detailed remediation recommendations to improve overall security defenses. Penetration Testers work closely with security engineers, compliance teams, and IT operations to ensure risks are understood and mitigated.

Key Responsibilities
Offensive Security Testing
  • Perform penetration tests on web applications, APIs, mobile apps, cloud platforms, networks, and infrastructure.
  • Conduct internal and external vulnerability assessments and exploit identified weaknesses.
  • Simulate advanced persistent threat (APT) attack behaviors to evaluate detection and response capabilities.
  • Conduct social engineering assessments (phishing, vishing, physical tests) when approved and in scope.
Reporting & Remediation Guidance
  • Document findings clearly and concisely, including exploit techniques, impact, and severity ratings.
  • Provide actionable remediation recommendations to reduce risks and prevent exploitation.
  • Present results to engineering, leadership, and executive stakeholders as needed.
Security Tooling & Techniques
  • Use industry-standard offensive tools (e.g., Burp Suite, Metasploit, Nmap, Kali Linux, Cobalt Strike, custom scripts).
  • Develop custom scripts or tools in languages like Python, PowerShell, Bash, or JavaScript to support advanced testing.
  • Apply manual testing techniques to identify business logic flaws and complex vulnerabilities not detected by scanners.
Security Standards & Compliance
  • Conduct testing aligned with frameworks such as OWASP Top 10, NIST 800-115, MITRE ATT&CK, or OSSTMM.
  • Ensure testing activities follow legal, ethical, and compliance guidelines (e.g., SOC 2, PCI-DSS).
  • Support security audits by providing technical interpretations of penetration test results.
Continuous Improvement
  • Stay updated on emerging threats, vulnerabilities, and offensive security techniques.
  • Participate in responsible disclosure programs and threat research to improve internal defensive strategies.
  • Collaborate with incident response teams to validate security incidents and provide threat insights.
Qualifications
Required
  • 2–5+ years of penetration testing, red teaming, or offensive security experience.
  • Proficiency with offensive security methodologies and tools.
  • Strong experience testing web apps, APIs, networks, and cloud environments.
  • Solid understanding of security protocols, authentication mechanisms, and common vulnerabilities (XSS, SQLi, RCE, CSRF, etc.).
  • Ability to clearly document vulnerabilities and explain exploitation steps to both technical and non‑technical stakeholders.
Preferred
  • Certifications: OSCP, OSWE, OSEP, CEH, GPEN, GXPN, or equivalent offensive security credentials.
  • Experience with cloud security testing (AWS, Azure, GCP).
  • Familiarity with DevSecOps pipelines, CI/CD testing methods, and automated scanning solutions.
  • Background in scripting or tool development for advanced exploitation.
  • Experience performing red team operations and purple team collaboration.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Pentester
Pentester

Cloudheed • Frankfurt

Vor Ort
EUR 60.000 - 80.000
Penetration Tester (Offensive Security) (Mid-Level Funnel)
Penetration Tester (Offensive Security) (Mid-Level Funnel)

Sentrabyte Digital Solusi • Deutschland

Remote
EUR 51.000 - 103.000
Cyber Security Pentester (m/f/d)
Cyber Security Pentester (m/f/d)

ECSO • Mülheim an der Ruhr

Vor Ort
EUR 45.000 - 65.000
Penetration Tester - Europe (m/f/d)
Penetration Tester - Europe (m/f/d)

NeuVerge-Tron GmbH • München

Vor Ort
EUR 68.000 - 100.000
Offensive Security Engineer (Hybrid Role / Broader Reach)
Offensive Security Engineer (Hybrid Role / Broader Reach)

Sentrabyte Digital Solusi • Deutschland

Remote
EUR 51.000 - 103.000
Vulnerability Management / Incident Response Specialist
Vulnerability Management / Incident Response Specialist

Hhw Group • Deutschland

Vor Ort
EUR 70.000 - 90.000
Senior Red Team Operator – Enterprise Offensive Security
Senior Red Team Operator – Enterprise Offensive Security

Sentrabyte Digital Solusi • Deutschland

Remote
EUR 72.000 - 141.000
Flexible work environment
Growth-oriented culture
Fully remote work
Senior/Staff Application Security Engineer
Senior/Staff Application Security Engineer

Nebius B.V. • Deutschland

Remote
EUR 90.000 - 130.000
Cyber Security Consultant - Penetration Testing
Cyber Security Consultant - Penetration Testing

Bitdefender • Deutschland

Vor Ort
EUR 90.000 - 130.000
Annual training budget
Dedicated research time
Global collaboration
Associate Security Consultant
Associate Security Consultant

IOActive, Inc. • Deutschland

Hybrid
EUR 40.000 - 50.000
Remote work
Travel opportunities
Competitive compensation