Senior Penetration Tester (m/w/d) in der IT-Beratung

Nur für registrierte Mitglieder
Köln
Remote
EUR 70.000 - 90.000
Jobbeschreibung

Join to apply for the Senior Penetration Tester (m/w/d) in der IT-Beratung role at carmasec GmbH & Co. KG

Job Description

We are seeking a Senior Penetration Tester to conduct targeted penetration tests and realistic attack simulations on web, network, and cloud infrastructures. You will identify vulnerabilities before they can be exploited and develop risk-based reports with clear recommendations. Your role involves advising clients at all levels, developing threat-informed defense strategies, and working closely with other experts and teams to enhance our offensive security capabilities.

Responsibilities

  1. Perform penetration tests and attack simulations on various infrastructures.
  2. Create understandable reports with technical details and management summaries.
  3. Advise clients effectively and communicate complex technical content clearly.
  4. Develop defense strategies based on attacker TTPs.
  5. Translate attack logic into robust defense measures and evaluate existing security controls.
  6. Collaborate with teams and contribute to presales activities.
  7. Contribute to the development of our offensive security offerings, aiming for technical leadership.

Qualifications

Essential Skills

  • Deep understanding of attack techniques in web, network, or cloud security.
  • Experience in conducting manual penetration tests, OSINT assessments, or vulnerability analyses, preferably with direct clients.
  • Proficiency with tools like Burp Suite, Metasploit, Kali Linux, and familiarity with frameworks such as OWASP and Mitre ATT&CK.
  • Ability to explain complex technical issues clearly, both written and spoken.
  • Self-organized work style with good time management, capable of handling multiple projects.
  • Willingness to share knowledge and support team development.
  • Experience in technical leadership roles or willingness to grow into such roles.

Nice-to-Have Skills

  • Experience in Red or Purple Teaming.
  • Certifications like OSCP, OSCE, CRTP, PNPT.
  • Interest in interdisciplinary work and strategic security development.

Benefits

  • Creative freedom, open feedback culture, and opportunity to shape company structures.
  • Mentorship and personal development support.
  • Flexible working hours and work-life balance.
  • Various perks like Jobticket, Urban Sports Club, company bike, and training budgets.
  • Remote work options, minimal travel, and team-building events.
  • Potential for long-term growth and leadership within the team.

Additional Details

We value passionate cybersecurity professionals eager to join a diverse and engaging team. Our application process is straightforward—just send us your relevant CV, and we’ll arrange a friendly interview via Microsoft Teams.