Stellenbeschreibungpul /brliHelp mature and expand our red teaming capabilities, contributing to methodology, rules of engagement, tooling and reporting /li /brliPlan and execute penetration tests and red team engagements against applications, cloud services, infrastructure and critical systems /li /brliDevelop and apply AI-assisted penetration testing using AI to accelerate reconnaissance, exploitation, payload generation and reporting across the engagement lifecycle /li /brliTest the security of our internal AI platforms, including prompt injection, model abuse, data exfiltration and other AI-specific attack techniques /li /brliWork with the blue team to optimise detection and response, feeding real attack scenarios we were able to exploit into new detections; run adversary emulation and purple team exercises to validate detection and response capabilities /li /brliDocument findings clearly, prioritise by risk and drive remediation with the affected teams; contribute to security standards, KPIs and reporting /li /brliSupport incident handling and root-cause analysis where offensive security expertise adds value /li /brliWork closely with infrastructure, development, operations, governance and risk teams to embed offensive testing into the wider security lifecycle /li /br /ul /brh3bRequirements /b /h3 /brul /brliSeveral years of hands-on experience in penetration testing, red teaming or offensive security /li /brliProven penetration testing skills across at least two areas such as web and application testing, network and infrastructure, cloud (Azure / M365), AI, Active Directory / identity, or social engineering /li /brliPractical experience with offensive tooling and frameworks such as Metasploit, Burp Suite or comparable, and familiarity with MITRE ATTCK /li /brliExperience with scripting and exploit development, for example Python, PowerShell, Golang or similar /li /brliSolid understanding of how to use AI in offensive security and awareness of AI-specific attack surfaces (e.g. prompt injection, model and data abuse); knowledge of common frameworks such as OWASP, MITRE ATTCK or NIST /li /brliStructured, reliable and solution-oriented way of working /li /brliStrong communication skills and the ability to make technical findings understandable and actionable for technical and non-technical audiences /li /brliVery good English skills; German is an advantage /li /brliWillingness to participate in 24/7 on-call duty /li /brliNice to Have: Experience in regulated environments or financial services /li /brliOffensive security certifications such as OSCP, OSEP, CRTO, CRTP or GPEN /li /br /ul /brh3bCore Competencies /b /h3 /brpDemonstrates expertise in penetration testing and red teaming, with a strong focus on AI-assisted security techniques and collaboration with blue teams to enhance detection and response capabilities. Proficient in offensive security methodologies and frameworks, with a commitment to clear documentation and risk prioritization. /p /brh3bHighest-signal resume keywords /b /h3 /brul /brliPenetration Testing /li /brliRed Teaming /li /brliAI-Assisted Security /li /brliOffensive Security Certifications /li /brliOffensive Tooling and Frameworks /li /br /ul /brh3ATS Optimization Keywords /h3 /brh3Hard Skills /h3 /brul /brliPenetration Testing /li /brliRed Teaming /li /brliScripting /li /brliExploit Development /li /brliAI-Specific Attack Techniques /li /brliWeb and Application Testing /li /brliNetwork and Infrastructure Testing /li /brliCloud Security (Azure / M365) /li /brliActive Directory / Identity Testing /li /brliSocial Engineering /li /br /ul /brh3Soft Skills /h3 /brul /brliStrong Communication Skills /li /brliSolution-Oriented Working /br /liliAbility to Simplify Technical Findings /li /br /ul /brh3Certifications Qualifications /h3 /brul /brliOSCP /li /brliOSEP /li /brliCRTO /li /brliCRTP /li /brliGPEN /li /br /ul /brh3Industry Keywords /h3 /brul /brliOffensive Security /li /brliIncident Handling /li /brliRoot-Cause Analysis /li /brliRegulated Environments /li /brliFinancial Services /li /br /ul /brh3Tools Technologies /h3 /brul /brliMetasploit /li /brliBurp Suite /br /liliMITRE ATTCK /br /liliOWASP /li /brliNIST /li /br /ul /p #J-18808-Ljbffr