Responsibilities
- Test our web and mobile applications and APIs for vulnerabilities, including authentication flaws, access control issues like IDOR, injection attacks, misconfigurations, and exposed secrets.
- Re-examine findings from previous penetration tests to confirm that fixes are effective.
- Integrate security checks for secrets, dependencies, and code into our CI pipelines to catch issues early.
- Conduct security reviews of new features during development, not after release.
- Design and execute authorized social engineering exercises, such as phishing and pretexting, against our team under a written scope approved by the CTO, followed by debriefing and remediation.
- Test our AI SRE for prompt injection, tool abuse, and agent-boundary vulnerabilities, as it investigates incidents and executes actions upon approval.
- Document findings clearly and reproducibly, and follow through until vulnerabilities are fixed.
Benefits
- Work on a real attack surface involving production software used by companies worldwide during critical incidents.
- Join the red team at its inception and help shape its processes and methodologies.
- Explore the emerging field of agentic AI security with a product that is actively shipping.
- Enjoy hybrid work with three days per week at our Cologne Rheinauhafen office and two days remote.
- Benefit from flexible hours that accommodate lectures and exam periods.
- Receive direct mentorship from the CTO and collaborate with experienced engineers open to feedback.
- Experience a focus culture that protects maker time, favors asynchronous communication, and minimizes meetings.
Compensation
Not specified
Work Arrangement
Hybrid — Cologne, Germany
Team
You will report to the CTO and work alongside experienced engineers.
Other
- Fluent English is required as it is our working language.
- You must be able to regularly attend our Cologne office due to the hybrid arrangement.
- Hours are flexible around lectures and exam periods.
Not specified