About this job
<p><strong>Cologne, Germany (Hybrid)</strong></p>
<p><strong>Team:</strong> Engineering · <strong>Reports to:</strong> CTO · <strong>Format:</strong> Working Student (16–20h/week) or Internship (3–6 months)</p>
<p><strong>Join our red team</strong></p>
<p>ilert is a SaaS platform for alerting, on-call management and incident response that keeps digital services always on. Teams worldwide rely on us to stay up.</p>
<p>To keep it that way, we are building an <strong>internal red team</strong> that continuously tests our own products the way a real attacker would. And we're a genuinely interesting target: an attacker who silences ilert doesn't just steal data — they turn off the alarm while they work.</p>
<p>As a working student on our red team, you help us <strong>find, prove, and get security issues fixed</strong> in our own systems. You learn to think like an attacker, working closely with our team.</p>
<p>You don't need to arrive as a finished pentester. You need curiosity, a habit of taking things apart to understand them, and the care to handle what you find responsibly.</p>
<h2>Tasks</h2>
<ul>
<li><strong>Test Our Apps and APIs:</strong> Hunt for vulnerabilities in our web and mobile apps and APIs — from authentication and access control (IDOR) to injection, misconfigurations, and exposed secrets.</li>
<li><strong>Re-test Past Findings:</strong> Go back over findings from previous penetration tests and verify the fixes actually hold.</li>
<li><strong>Automate Security Checks in CI:</strong> Help build secret, dependency, and code scanning into our pipelines so issues surface early instead of late.</li>
<li><strong>Review New Features Before They Ship:</strong> Support security reviews as features are being built, not after.</li>
<li><strong>Run Authorized Social Engineering:</strong> Design and run phishing and pretexting exercises against our own team — always under a written scope signed off by the CTO beforehand, always debriefed as a learning exercise, never punitive. Then help us fix what the exercise exposed.</li>
<li><strong>Poke at the AI:</strong> We're building an AI SRE that investigates incidents and can execute actions on approval. Prompt injection, tool abuse, and agent-boundary testing are wide-open ground.</li>
<li><strong>Document and Follow Through:</strong> Write up findings clearly and reproducibly, then follow them through to a fix. We care as much about closing the gap as finding it.</li>
</ul>
<h2>What you bring</h2>
<ul>
<li><strong>Enrolled student</strong>, ideally in computer science, IT security, or similar.</li>
<li><strong>Genuine interest in offensive security</strong> — you tinker, you break things to understand them, maybe you already play CTFs / Hack The Box / TryHackMe.</li>
<li><strong>Basic grasp of how web apps and HTTP work</strong> — requests, headers, auth, cookies/tokens.</li>
<li><strong>Comfortable on the command line</strong> and with at least one scripting language (Python, JS/TS, Go).</li>
<li><strong>Careful and responsible with sensitive information.</strong> This role comes with access and trust: you stay inside the agreed scope and handle what you find responsibly.</li>
<li><strong>Fluent English</strong> (our working language).</li>
<li><strong>Able to be in our Cologne office regularly</strong> — the role is hybrid, not remote.</li>
</ul>
<p><strong>Bonus</strong></p>
<ul>
<li>Burp Suite or OWASP ZAP</li>
<li>OWASP Top 10</li>
<li>AWS / Kubernetes / CI-CD exposure</li>
<li>Mobile app testing</li>
<li>LLM and agent security — prompt injection, tool-use boundaries</li>
<li>Your own CVEs or bug-bounty reports</li>
<li>German language skills</li>
</ul>
<h2>Benefits</h2>
<ul>
<li>🎯 <strong>A Real Attack Surface:</strong> Not a lab, not a CTF box. Production software that companies worldwide depend on during their worst moments.</li>
<li>🧨 <strong>Get In Early:</strong> The red team is being built right now. You're not inheriting someone else's checklist — you help shape how we do this.</li>
<li>🤖 <strong>Unexplored Ground:</strong> Agentic AI security is barely a discipline yet. You'd be doing original work on it, on a product that's actually shipping.</li>
<li>🏡 <strong>Hybrid Freedom:</strong> Our office in <strong>Cologne Rheinauhafen</strong> (3 days/week) plus work from home (2 days/week).</li>
<li>🕒 <strong>Student-Centric:</strong> Flexible hours around lectures and exam periods.</li>
<li>🎓 <strong>Direct Mentorship:</strong> You report to the CTO and work alongside experienced engineers who want to be shown where they got it wrong.</li>
<li>🌴 <strong>Focus Culture:</strong> We protect maker time, favor async, and keep meetings rare.</li>
</ul>
<p><strong>We hire for curiosity and a builder's mentality, not a checklist.</strong> If you have a writeup, a CTF profile, a disclosed vulnerability, or a tool you built — bring it. But if you're early and hungry and can show us something you took apart, we want to hear from you too.</p>
<p><em>Keywords: Werkstudent IT-Security, Penetration Testing, Praktikum Cyber Security, Red Team, Application Security, Köln.</em></p>
<p>Find <a href="https://www.arbeitnow.com">Jobs in Germany</a> on Arbeitnow</a>