Senior Security Engineer, Offensive Security

Jobgether

Deutschland

Remote

EUR 119.000 - 170.000

Vollzeit

Vor 12 Tagen
Bewerbungsgenerator

Mach aus dieser Rolle ein Bewerbungsgespräch — ein Lebenslauf und ein Anschreiben, die darauf ausgerichtet sind, was dieser Arbeitgeber sucht.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Fully remote
Equity
Learning stipend
Parental leave
Technology stipend
Learning and development support

Zusammenfassung

Partner company is seeking a Senior Security Engineer, Offensive Security in Germany. You will join a remote-first security team focused on proactively identifying and eliminating threats across products, platforms, and cloud infrastructure.

You will apply offensive security expertise to penetration testing, red teaming, threat modeling, exploit development, and security architecture, partnering with engineering and leadership to implement durable security controls.

Qualifikationen

  • 3+ years of experience in security engineering and offensive security across apps and infra.

Aufgaben

  • Plan, scope, and execute penetration tests, red-team engagements, and adversary-emulation exercises.
  • Develop proof-of-concept exploits and deliver actionable remediation guidance.
  • Retest vulnerabilities to validate remediation.
  • Conduct security reviews and threat modeling across architecture, designs, code, and AI products.
  • Build and maintain offensive security tooling, automation, security tests, and exploit capabilities.
  • Partner with engineering to design security architecture, Zero Trust, and least-privilege controls.
  • Support security programs including automated security design reviews and vulnerability management.
  • Investigate security events, participate in incident response, and contribute to on-call rotations.
  • Collaborate with stakeholders to promote security-by-design practices.
  • Contribute to roadmaps, monitoring, anomaly detection, and security documentation.
  • Own recurring pentests and adversary-emulation activities with external researchers where appropriate.
  • Strengthen security practices for cloud, containerized environments, and AI/ML systems.

Kenntnisse

Penetration testing
Red teaming
Threat modeling
Exploit development
Security architecture
Zero Trust
Python
Golang
Cloud security
Automation

Ausbildung

OSCP
OSWE
OSEP
GXPN
GPEN
CRTO

Tools

Burp Suite
OWASP frameworks

Jobbeschreibung

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Offensive Security based in Germany.

Join a remote-first security team focused on proactively identifying and eliminating threats across products, platforms, and cloud infrastructure. In this role, you will apply offensive security expertise to penetration testing, red teaming, threat modeling, exploit development, and security architecture. You will work closely with engineering, product, and leadership teams to transform security findings into durable improvements and resilient controls. The scope spans cloud environments, containerized infrastructure, SaaS applications, APIs, and emerging AI/ML products. You will also help build scalable security automation and strengthen security programs as the organization grows. This is an opportunity to make a direct impact on the security of products used by millions of developers worldwide.

Accountabilities:
  • Plan, scope, and execute penetration tests, red-team engagements, and adversary-emulation exercises across products and services.
  • Develop proof-of-concept exploits and produce clear, risk-rated findings with actionable remediation guidance.
  • Retest vulnerabilities to validate that remediation has been successfully implemented.
  • Conduct security reviews and threat modeling across application architecture, designs, code, and emerging AI products.
  • Build and maintain offensive security tooling, automation, security tests, and exploit capabilities to expand testing coverage.
  • Partner with engineering teams to design and implement security architecture, controls, Zero Trust practices, and least-privilege access.
  • Support security programs including automated security design reviews and vulnerability management.
  • Investigate security events, participate in incident response, and contribute to a rotating on-call schedule.
  • Collaborate with product, engineering, and other stakeholders to promote security-by-design practices.
  • Contribute to security roadmaps, monitoring improvements, anomaly detection, compliance initiatives, and security documentation.
  • Own recurring penetration tests and adversary-emulation activities while engaging with external security researchers where appropriate.
  • Help strengthen security practices for cloud infrastructure, containerized environments, and AI/ML systems.
Requirements:
  • 3+ years of experience in security engineering, including hands-on offensive security and penetration testing across applications and infrastructure.
  • 2+ years of hands-on software development experience with Python or Golang.
  • Deep knowledge of authentication and authorization, including OAuth, applied cryptography, and Zero Trust principles.
  • Strong practical experience securing cloud environments such as AWS, GCP, or Azure.
  • Hands-on penetration testing experience across SaaS web applications and APIs, including manual exploitation beyond automated scanners.
  • Proficiency with offensive security tools and techniques, including Burp Suite and OWASP frameworks.
  • Ability to develop security tests, exploits, and proof-of-concepts that identify real-world vulnerabilities.
  • Understanding of AI/ML security risks and mitigations, including prompt injection, data poisoning, model extraction, and adversarial attacks.
  • Practical experience using LLMs and agentic tools to automate vulnerability discovery, reconnaissance, and penetration testing workflows.
  • Experience building security programs and automation from the ground up using risk-based prioritization.
  • Experience performing security reviews and developing or improving automated security review processes.
  • Excellent communication skills and the ability to explain complex security concepts to both technical and non-technical stakeholders.
  • Strong understanding of security standards and a commitment to keeping up with emerging security technologies and models.
  • Collaborative mindset with the ability to drive security improvements through cross-functional partnerships.
  • Offensive security certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, or CRTO are valued.
  • Published CVEs, original security research, or conference presentations are a plus.
  • Experience with container escapes, Kubernetes attack paths, cloud red teaming, or AI/ML security testing is advantageous.
  • Ability to work remotely and operate effectively with a high degree of autonomy.
  • This position does not offer visa sponsorship.
Benefits:
  • Fully remote, remote-first working environment.
  • EU compensation of €118,860–€169,800, plus equity.
  • Flexible scheduling designed to support autonomy and work-life balance.
  • Generous paid time off, quarterly Whaleness Days, and an end-of-year Whaleness break.
  • Home office support to help create a comfortable and effective workspace.
  • Technology stipend equivalent to US$100 net per month.
  • Annual learning and development stipend for conferences, courses, certifications, and professional development.
  • 16 weeks of paid parental leave after six months of employment.
  • Equity for all full-time employees.
  • Comprehensive medical, retirement, and paid holiday benefits, varying by country.
  • Opportunity to work on security challenges spanning cloud infrastructure, containers, AI/ML, and large-scale developer platforms.
  • Offices available in Seattle and Paris for connection and collaboration when relevant.
  • Company merchandise and team perks.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Application Security Engineer
Senior Application Security Engineer

upstart • Deutschland

Hybrid
EUR 144.000 - 199.000
Security Engineer (m/f/d)
Security Engineer (m/f/d)

Security Research Labs • Berlin

Hybrid
EUR 55.000 - 90.000
Gym discounts
Public transport pass
German lessons
+5
Senior Application Security Engineer (all genders)
Senior Application Security Engineer (all genders)

Meyandy LLC • Berlin

Hybrid
EUR 90.000 - 130.000
Remote-friendly policy
International opportunities
Office Berlin HQ
Senior Security Engineer
Senior Security Engineer

United States Digital Space LLC • Berlin, München

Vor Ort
EUR 90.000 - 125.000
Relocation support
Learning allowance
Health & wellness
+3
(Senior) Software Engineer (M/F/D) - Tools & Automation
(Senior) Software Engineer (M/F/D) - Tools & Automation

Meyandy LLC • Bochum

Vor Ort
EUR 70.000 - 110.000
Remote-first across Europe
Work from Bochum, Germany
Ownership of tools and projects
+1
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

EPAM Systems • Berlin

Hybrid
EUR 90.000 - 120.000
30 days holiday per annum
Company Pension Scheme
Employee Stock Purchase Plan (ESPP)
+2
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

EPAM Systems • Frankfurt

Hybrid
EUR 90.000 - 140.000
30 days holiday per annum
Company Pension Scheme
Regular performance assessments
+1
Senior Security Engineer (m/f/d)
Senior Security Engineer (m/f/d)

Yoummday GmbH • München

Hybrid
EUR 90.000 - 130.000
30 days vacation
Job lunch allowance (€69/mo)
Givve card (€50/mo)
+5
Senior Director, Product Security
Senior Director, Product Security

gainsight • Deutschland

Hybrid
EUR 80.000 - 88.000
Hybrid Poland-based role
Base salary PLN 31,000-34,000 per mês,
Annual bonus
+5
Founding Engineering Team Lead (HandsOn)
Founding Engineering Team Lead (HandsOn)

TechBiz Global GmbH • Berlin

Vor Ort
EUR 80.000 - 120.000
Founding Team Member Equity
Competitive Compensation
High Autonomy
+2