About this role
Offensive Security Specialist (m/f/d)
description
-
Expected Responsibilities: Conducting offensive security activities, including penetration testing and Red Team operations, across web applications, enterprise infrastructure, cloud environments, and industrial systems. Planning, executing, and leading advanced penetration tests for: Custom and third-party web applications; Complex enterprise applications (e.g., ERP, legacy systems, industrial platforms). Cloud-native and hybrid architecture. Documenting findings in high-quality technical reports, including: Clear risk ratings; Business impact analysis; Actionable remediation recommendations. Presenting results to technical and non-technical stakeholders, including engineering teams, management, and customers. Advising on risk mitigation strategies, secure design principles, and defensive improvements.
-
Professional Experience & Background: Successfully completed university degree in (Business) Informatics, Computer Science, or a comparable IT-related field — or equivalent professional experience. Hands-on experience in: Web application penetration testing; Infrastructure and network penetration testing; Security testing of complex, business-critical applications. Experience working in industrial or chemical company environments is a plus.
-
Technical Skills & Knowledge: Strong understanding of Windows and Linux client/server environments. Practical experience with cloud platforms, including identity, networking, and cloud-native services. In-depth knowledge and hands-on usage of offensive security tools. Knowledge of secure software development lifecycle (SSDLC) and common vulnerability classes (e.g., OWASP Top 10). Programming and scripting skills are a plus. Experience with Red Teaming, adversary simulation, and attack-chain methodology. Familiarity with source code review and static/dynamic application security testing. Knowledge of OT / ICS security is desirable.