Job offer
IT Security Specialist (Offensive Security / TIBER-EU)
The IT security specialist (Offensive Security / TIBER-EU) is responsible for the operational coordination and quality assurance of penetration tests, security assessments, and other security measures. The position is advertised as a 12-month contract with the possibility of extension in Zurich.
Tasks
- Leading scoping discussions for internal and external penetration tests, defining objectives, scope, ROE, and technical requirements
- Evaluating vendor proposals for security assessments, assessing scope, methodology, quality, costs, and schedules
- Identifying gaps and risks in vendor proposals, working with stakeholders to develop recommendations
- Conduct thorough reviews of pen test reports to ensure technical accuracy, clear evidence, appropriate severity rating, and actionable remediation guidance.
- Ensure that all results are reproducible, well documented, and effectively communicated; coordinate clarifications with suppliers when necessary.
- Manage the vulnerability lifecycle with Jira ServiceNow, including tracking, prioritizing, following up, and escalating overdue or blocked items.
- Monitor remediation progress with a risk-based focus, providing regular updates on key metrics such as critical outcomes, MTTR, and recurrence trends.
- Providing technical support to coordinators and engineers, assisting with the interpretation of results and the planning of corrective measures
- Organize and conduct internal retests to verify the effectiveness of corrections and contribute to root cause analysis to prevent future vulnerabilities.
- Supporting TIBER-EU commitments, where applicable, ensuring compliance with governance, traceability, and follow-up of measures after evaluation
- Continuous improvement of assessment standards, checklists, and processes for scoping, reporting, and retesting activities
Requirements
- Bachelor's degree in computer science, information security, or equivalent practical experience
- 3-6 years of experience in IT security delivery, AppSec, SecOps, or security assessment coordination
- Solid understanding of web application security and API security (OWASP Top 10), vulnerability classes, and risk assessment
- Strong knowledge of common penetration testing methods and deliverables (scope, ROE, test plan, report, results)
- Experience with Jira and/or ServiceNow for issue and vulnerability management
- Professional language skills in English (written and spoken), German is an advantage
We offer
No information available.Job details