Working Student / Intern: Offensive Security Engineer (Red Team & AppSec) (f/m/x)
Team
Reports to
Format
Join our red team
internal red team
find, prove, and get security issues fixed
Tasks
Test Our Apps and APIs
Re-test Past Findings
Automate Security Checks in CI
Review New Features Before They Ship
Run Authorized Social Engineering
Poke at the AI
Document and Follow Through
What you bring
Enrolled student
Genuine interest in offensive security
Basic grasp of how web apps and HTTP work
Comfortable on the command line
Careful and responsible with sensitive information.
Fluent English
Able to be in our Cologne office regularly
Bonus
- Burp Suite or OWASP ZAP
- OWASP Top 10
- AWS / Kubernetes / CI-CD exposure
- Mobile app testing
- LLM and agent security — prompt injection, tool-use boundaries
- Your own CVEs or bug-bounty reports
- German language skills
Benefits
- 🎯
A Real Attack Surface
Not a lab, not a CTF box. Production software that companies worldwide depend on during their worst moments.
- 🧨
Get In Early
The red team is being built right now. You're not inheriting someone else's checklist — you help shape how we do this.
- 🤖
Unexplored Ground
Agentic AI security is barely a discipline yet. You'd be doing original work on it, on a product that's actually shipping.
- 🏡
Hybrid Freedom
Cologne Rheinauhafen
(3 days/week) plus work from home (2 days/week).
- 🕒
Student-Centric
Flexible hours around lectures and exam periods.
- 🎓
Direct Mentorship
You report to the CTO and work alongside experienced engineers who want to be shown where they got it wrong.
- 🌴
Focus Culture
We hire for curiosity and a builder's mentality, not a checklist.
Not included in the source posting: what you'll do, qualifications.
Skills
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.