Bereits vergeben

Lass dir die nächste nicht entgehen — erhalte passende Stellen direkt per Mail.

Contract Penetration Tester (m/f/d) / Offensive Security Specialist (m/f/d) (Remote)

Remote
Vollzeit, Teilzeit
vor 1 Monat
Deutschland
Stellenbeschreibung

Engagement Overview

For a global science and technology organization headquartered in Germany, we are supporting a long-term Offensive Security and Attack Surface Management initiative.

The engagement focuses on the independent delivery of high-quality offensive security services, with a strong emphasis on penetration testing, attack surface discovery, and proactive risk reduction.

Engagement Details

  • Engagement Type: Freelance / Contract (Independent Consultant)
  • Work Model: 100% Remote
  • Duration: Long-term assignment (planned until end of 2026)

Scope of Work

Penetration Testing & Vulnerability Analysis

  • Execution of penetration tests across:
    • Web applications and APIs
    • Network infrastructures
    • Cloud environments
  • Application of black-box, gray-box, and white-box testing methodologies
  • Identification and technical documentation of vulnerabilities, including:
    • OWASP Top 10 risks
    • Security misconfigurations
    • Privilege escalation paths
  • Creation of comprehensive penetration test reports, covering:
    • Technical risk ratings
    • Clearly documented attack paths
    • Concrete, actionable remediation recommendations
  • Validation of remediation measures through structured re-testing activities

Attack Surface Discovery & Monitoring

  • Discovery and inventory of externally exposed assets
  • Identification of unmanaged or unknown assets, exposed services, and APIs
  • Continuous monitoring of attack surface changes
  • Documentation of exposure trends over time
  • Prioritization of findings based on:
    • Exploitability
    • Exposure level
    • Relevant threat intelligence

Technical Security Consulting & Tooling

  • Provision of hands-on remediation guidance to engineering and DevOps teams
  • Execution of threat modeling and technical security architecture reviews
  • Development of custom scripts and automation to support:
    • Offensive security activities
    • Attack Surface Management processes

Required Experience & Skills

  • Proven experience as a Penetration Tester / Offensive Security Consultant
  • Strong hands-on expertise in:
    • Web application and API security testing
    • Network and cloud security assessments
  • Solid understanding of modern attack techniques and exploitation paths
  • Experience documenting findings in clear, technically precise reports
  • Ability to work independently in a consulting-style engagement
  • Scripting or automation skills (e.g. Python, Bash, similar) are highly valued