Enter a job title or keyword

Working Student Intern Offensive Security Engineer (Red Team & AppSec) (fmx)

Ilert GmbH


Job Location:

Cologne - Germany

Monthly Salary: Not provided by the employer
Posted: 26 August 2026 (12 hours ago)
Application Deadline: 23 November 2026
Vacancies: 1 Vacancy

Job Summary

Cologne Germany (Hybrid)

Team: Engineering Reports to: CTO Format: Working Student (1620h/week) or Internship (36 months)

Break the platform that wakes people up

ilert helps thousands of DevOps & IT teams detect fix and communicate incidents. When a critical system goes down were the thing that pages the on-call engineer at 3 AM.

Which makes us an unusually interesting target. An attacker who silences ilert doesnt just steal data they turn off the alarm while they work. Alert suppression tenant isolation escalation-policy logic the integrations that reach into our customers infrastructure: every one of those is a place where a bug isnt just a bug.

Were looking for a Working Student or Intern to attack all of it. Youll be our first dedicated security hire not a ticket-taker on an existing security team but the person who builds the offensive security practice here from zero with the CTO backing you and the whole engineering team as your counterpart.

If you spend your evenings on CTFs HackTheBox or bug bounty programs and want to point that at real production software used by real companies this is that job.

Tasks
  • Attack Our Product: Pentest the ilert platform end to end web app public API webhooks and integrations. Hunt for what actually matters in multi-tenant SaaS: broken auth and authz tenant isolation failures IDOR SSRF injection and abuse of our alerting and escalation logic.
  • Red Team Our Infrastructure: Probe our cloud and Kubernetes configuration secrets handling CI/CD pipelines and software supply chain. Find the path from small misconfiguration to real access.
  • Run Authorized Social Engineering: Design and run phishing and pretexting exercises against our own team always under a written scope signed off by the CTO before you start always debriefed as a learning exercise never punitive. Then help us fix what the exercise exposed.
  • Break the AI Too: Were building an AI SRE that investigates incidents and can execute actions on approval. Prompt injection tool abuse and agent-boundary testing are wide-open ground here and largely unexplored.
  • Harden the SDLC: Bring dependency secrets and static analysis into CI where it earns its place. Threat-model new features with the engineers building them. Review the security-relevant PRs.
  • Write Findings People Can Act On: A reproducible proof of concept an honest severity call and a concrete fix then pair with the engineer who ships it. We care as much about closing the gap as finding it.
Requirements
  • Current Student: Enrolled in Computer Science IT Security Informatics or a related technical field.
  • Demonstrable Offensive Work: Not coursework or certificates things youve actually done. CTF results HackTheBox/TryHackMe progression bug bounty reports a home lab you built a writeup you published a CVE you found. Show us one and walk us through it.
  • You Can Read and Write Code: Enough to navigate a real codebase (we run Java Rust TypeScript/React) understand why a bug exists and propose the fix not just report that a scanner flagged something.
  • Web Security Fundamentals: OWASP Top 10 as a working tool not a memorized list. Authentication and session handling access control injection classes SSRF and what makes multi-tenancy hard.
  • Comfortable With the Tooling: Burp Suite or equivalent plus the usual recon and exploitation kit and the judgment to know when manual beats automated.
  • Judgment and Discretion: This role comes with access and trust. You stay inside the agreed scope you dont test things you werent authorized to test and you handle what you find responsibly. Non-negotiable.
  • Language: Fluent English (our working language).
  • Location: Able to be in our Cologne office regularly the role is hybrid not remote.

Bonus points

  • Cloud or Kubernetes security Infrastructure-as-Code scanning
  • CI/CD and supply chain security (SAST DAST SCA SBOM)
  • LLM and agent security prompt injection tool-use boundaries agent sandboxing
  • Detection engineering: not just getting in but noticing when someone else does
  • German language skills
  • A published CVE security blog meetup talk or open source security tooling
Benefits
  • A Real Attack Surface: Not a lab not a CTF box. Production software that companies worldwide depend on during their worst moments.
  • Build the Practice: Youre the first security hire. What offensive security looks like at ilert is genuinely yours to define with the CTO in your corner.
  • Unexplored Ground: Agentic AI security is barely a discipline yet. Youd be doing original work on it on a product thats actually shipping.
  • Hybrid Freedom: Our office in Cologne Rheinauhafen (3 days/week) plus work from home (2 days/week).
  • Student-Centric: Flexible hours around lectures and exam periods.
  • Direct Mentorship: You report to the CTO and work alongside experienced engineers who want to be shown where they got it wrong.
  • Focus Culture: We protect maker time favor async and keep meetings rare.

We hire for talent and a builders mentality not a checklist. If you have a writeup a CTF profile a disclosed vulnerability or a tool you built bring it. That tells us more than any certification will.

Keywords: Werkstudent IT-Security Penetration Testing Praktikum Cyber Security Red Team Application Security Köln.


About Company

Company Logo

ilert is a SaaS company for alerting, on-call management and status pages and helps companies to operate always-on services and respond faster to incidents.

View Profile View Profile