Volver

Working Student / Intern: Offensive Security Engineer (Red Team & AppSec) (f/m/x)

CompraTica Empleos

EMP:Technology
Cologne
Tiempo Completo
Remoto
0 vistas

Descripción

Cologne, Germany (Hybrid) Team: Engineering · Reports to: CTO · Format: Working Student (16–20h/week) or Internship (3–6 months) Break the platform that wakes people up ilert helps thousands of DevOps & IT teams detect, fix, and communicate incidents.

When a critical system goes down, we're the thing that pages the on-call engineer at 3 AM.

Which makes us an unusually interesting target.

An attacker who silences ilert doesn't just steal data — they turn off the alarm while they work.

Alert suppression, tenant isolation, escalation-policy logic, the integrations that reach into our customers' infrastructure: every one of those is a place where a bug isn't just a bug.

We're looking for a Working Student or Intern to attack all of it.

You'll be our first dedicated security hire — not a ticket-taker on an existing security team, but the person who builds the offensive security practice here from zero, with the CTO backing you and the whole engineering team as your counterpart.

If you spend your evenings on CTFs, HackTheBox, or bug bounty programs and want to point that at real production software used by real companies, this is that job.

Tasks Attack Our Product: Pentest the ilert platform end to end — web app, public API, webhooks, and integrations.

Hunt for what actually matters in multi-tenant SaaS: broken auth and authz, tenant isolation failures, IDOR, SSRF, injection, and abuse of our alerting and escalation logic.

Red Team Our Infrastructure: Probe our cloud and Kubernetes configuration, secrets handling, CI/CD pipelines, and software supply chain.

Find the path from "small misconfiguration" to "real access.

" Run Authorized Social Engineering: Design and run phishing and pretexting exercises against our own team — always under a written scope signed off by the CTO before you start, always debriefed as a learning exercise, never punitive.

Then help us fix what the exercise exposed.

Break the AI, Too: We're building an AI SRE that investigates incidents and can.

¿Te interesa? Aplicá ahora