Working Student / Intern: Offensive Security Engineer (Red Team & AppSec) (f/m/x)
Cologne, Germany (Hybrid)
Team: Engineering · Reports to: CTO · Format: Working Student (16–20h/week) or Internship (3–6 months)
Join our red team
ilert is a SaaS platform for alerting, on-call management and incident response that keeps digital services always on. Teams worldwide rely on us to stay up.
To keep it that way, we are building an internal red team that continuously tests our own products the way a real attacker would. And we're a genuinely interesting target: an attacker who silences ilert doesn't just steal data — they turn off the alarm while they work.
As a working student on our red team, you help us find, prove, and get security issues fixed in our own systems. You learn to think like an attacker, working closely with our team.
You don't need to arrive as a finished pentester. You need curiosity, a habit of taking things apart to understand them, and the care to handle what you find responsibly.
Tasks
- Test Our Apps and APIs: Hunt for vulnerabilities in our web and mobile apps and APIs — from authentication and access control (IDOR) to injection, misconfigurations, and exposed secrets.
- Re-test Past Findings: Go back over findings from previous penetration tests and verify the fixes actually hold.
- Automate Security Checks in CI: Help build secret, dependency, and code scanning into our pipelines so issues surface early instead of late.
- Review New Features Before They Ship: Support security reviews as features are being built, not after.
- Run Authorized Social Engineering: Design and run phishing and pretexting exercises against our own team — always under a written scope signed off by the CTO beforehand, always debriefed as a learning exercise, never punitive. Then help us fix what the exercise exposed.
- Poke at the AI: We're building an AI SRE that investigates incidents and can execute actions on approval. Prompt injection, tool abuse, and agent-boundary testing are wide-open ground.
- Document and Follow Through: Write up findings clearly and reproducibly, then follow them through to a fix. We care as much about closing the gap as finding it.
What you bring
- Enrolled student, ideally in computer science, IT security, or similar.
- Genuine interest in offensive security — you tinker, you break things to understand them, maybe you already play CTFs / Hack The Box / TryHackMe.
- Basic grasp of how web apps and HTTP work — requests, headers, auth, cookies/tokens.
- Comfortable on the command line and with at least one scripting language (Python, JS/TS, Go).
- Careful and responsible with sensitive information. This role comes with access and trust: you stay inside the agreed scope and handle what you find responsibly.
- Fluent English (our working language).
- Able to be in our Cologne office regularly — the role is hybrid, not remote.
Bonus
- Burp Suite or OWASP ZAP
- OWASP Top 10
- AWS / Kubernetes / CI-CD exposure
- Mobile app testing
- LLM and agent security — prompt injection, tool-use boundaries
- Your own CVEs or bug-bounty reports
- German language skills
Benefits
- 🎯 A Real Attack Surface: Not a lab, not a CTF box. Production software that companies worldwide depend on during their worst moments.
- 🧨 Get In Early: The red team is being built right now. You're not inheriting someone else's checklist — you help shape how we do this.
- 🤖 Unexplored Ground: Agentic AI security is barely a discipline yet. You'd be doing original work on it, on a product that's actually shipping.
- 🏡 Hybrid Freedom: Our office in Cologne Rheinauhafen (3 days/week) plus work from home (2 days/week).
- 🕒 Student-Centric: Flexible hours around lectures and exam periods.
- 🎓 Direct Mentorship: You report to the CTO and work alongside experienced engineers who want to be shown where they got it wrong.
- 🌴 Focus Culture: We protect maker time, favor async, and keep meetings rare.
We hire for curiosity and a builder's mentality, not a checklist. If you have a writeup, a CTF profile, a disclosed vulnerability, or a tool you built — bring it. But if you're early and hungry and can show us something you took apart, we want to hear from you too.
Keywords: Werkstudent IT-Security, Penetration Testing, Praktikum Cyber Security, Red Team, Application Security, Köln.
Find more English Speaking Jobs in Germany on Arbeitnow
Skills
- IT
Similar roles
Manufacturing Engineering Assistant (1 year contract)
Rockwell Automation·Singapore, Singapore
Rockwell Automation is a global technology leader focused on helping the world’s manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing companies that help feed the world, provide life-saving medicine on a global scale, and focus on clean water…
- Contract
- Tech.Pass — self-sponsored, 2-yr
Tecnico di manutenzione / Coordinatore
Adecco·Italy
Adecco Italia Spa, per importante azienda operante nel settore siderurgico e costruzioni metalliche leader nel suo settore, è alla ricerca di un/a: Tecnico di manutenzione / Coordinatore La figura a supporto del capo reparto si occuperà di: • Analizzare macchinari e impianti produttivi al fine di individuare criticità e aree di miglioramento; • Individuare le cause di malfunzionamenti e pianificare…
- Full-time
Cyber Security Engineer - Red Team - Remote within UK
Immersivelabs·United Kingdom
A platform you can believe in: Immersive One is the leading cyber resilience solution across the globe. Build and scale a best in class platform alongside a team of the brightest minds in cybersecurity! At Immersive, we’re uniquely positioned to future-proof organizations against any cyber challenge. If that excites you, read on! Immersive helps prove and improve your cyber resilience,…
- On-site
- Full-time
Estetista / Onicotecnica Qualificata
SOLARIO·Catania, Italy
Centro estetico leader nel settore, seleziona estetista qualificata per rapporto lavorativo part time o full time Contratto di lavoro: Tempo pieno, Part-time, Tempo indeterminato Retribuzione: €600,00 - €1.200,00 al mese Disponibilità: - Turno diurno Esperienza: - estetista: 1 anno (Preferenziale) Abilitazione/Certificazione: - Abilitazione professionale (Preferenziale)
- Full-time
Transformation Manager
ADP·Hyderabad, India
ADP is interviewing now for Oracle Order-to-Cash (OTC) Transformation Leaders. This future ADP Leader will have deep experience driving order to cash transformation discussions with line of business stakeholders, developing a roadmap and implementation strategy using next generation Oracle Order-to-Cash solutions and articulating clear business outcomes and benefits. The ideal candidate should have experience in Oracle or SAP implementations or…
- Full-time
Technical Support Engineer
Pax2Pay Ltd·Bristol, United Kingdom
Paxport Group UK - Pax2pay's parent company are recruiting! Title: Technical Support Engineer Location: UK ( Hybrid - 3 days Bristol office & 2 days remote ) Employment Type: Full Time Experience Level: 1+ Years Relevant Experience Paxport Group UK Ltd is a dynamic and growing leader in airline distribution and travel technology. We connect airlines with travel sellers through…
- Hybrid
- Full-time
Tutor di Digital Marketing — Lezioni Online
Letuelezioni·Italy
Letuelezioni, piattaforma leader in Italia, cerca specialisti del marketing digitale per offrire lezioni private online. Se hai esperienza in web marketing, SEO o strategia digitale, questa è un'opportunità flessibile per trasmettere le tue conoscenze a studenti e professionisti...
- Part-time
Senior Staff Engineer (Machine Learning) - 45391
Turing·Italy
Based in San Francisco, California, Turing is the world’s leading research accelerator for frontier AI labs and a trusted partner for global enterprises deploying advanced AI systems. Turing supports customers in two ways: first, by accelerating frontier research with ...
- Temp