Senior Red Teamer / Pentester – Cybersecurity Audit (m/f/d) – DISW
As part of the global Cybersecurity Assurance function, we help Siemens achieve their goals by providing objective, factual and independent assurance to the Siemens Managing Board and Audit Committee. As a business partner to Siemens executive management, we leverage our expertise in a wide range of topics to create an impact that drives change. We offer a vibrant and inclusive environment which ensures a variety of perspectives and enables big picture thinking.
Our Cybersecurity team provides core assurance over the Cybersecurity health of the company which includes IT infrastructures, product security, software development and cloud environments. We are on the lookout for people with a great skillset, an international mindset and new ideas who understand Siemens businesses and how Cybersecurity helps enable and increase market value.
Responsibilities
- Conduct and drive cybersecurity assessments across the entire Siemens landscape, including products, services, IT systems, and software development centers.
- Plan, perform and lead ethical hacking activities and design attack scenarios for state‑of‑the‑art technologies.
- Apply advanced hacking principles and red‑team methodologies, tools and techniques to mimic real‑world threat behaviours faced by Siemens’s digital environment, e.g. cloud applications, on‑premise infrastructure, digital products and services.
- Collaborate closely with cybersecurity experts from multiple industries to improve solutions by tackling root causes of issues and finding innovative solutions to modern challenges.
- Independently conduct research on the latest developments in cybersecurity technologies and threats, and understand how these impact the Siemens environment.
- Drive continuous improvement of internal audit processes, tools, documentation and coach junior team members.
Qualifications
- Strong academic background (bachelor’s degree) in IT, computer science or related fields; certifications such as OSCP, OSWE, OSEP, CRTO, CRTL, etc. are a plus.
- Good scripting and programming skills and experience with languages such as Bash, Python, PowerShell, and C++/C#.
- Minimum 7+ years of professional full‑time experience in penetration testing / red teaming with a proven record of continuous career development.
- Demonstrated affinity to learn about the latest trends in cybersecurity and keep up to date in a continuously challenging environment.
- Extensive experience with one or more aspects of penetration testing / red teaming: application and software security, EDR and antivirus evasion, C2 setup, automation and scaling of security testing, Active Directory attacks, etc.
- Experience with capture‑the‑flag events, bug hunting or vulnerability research (CVEs) is a plus.
- Experience with leveraging and integrating AI into day‑to‑day work is considered an advantage.
- Fluent in English; German or other languages are a plus.
- International mindset and willingness to travel and work in a diverse team.
Benefits
- 2 to 3 days of mobile working per week as a future global standard.
- Inclusive environment that values diversity and belonging.
- 30 days leave and flexible working models (for Germany).
- Share‑matching program to become a shareholder of Siemens AG.
- Pension plan for financial security.
- 50+ learning hours per year for personal and professional growth.
- Salary range: 79 700 EUR to 135 400 EUR (eligible for incentive compensation).
Equal Employment Opportunity
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment.