Job offer
IT Security Specialist (Offensive Security / TIBER-EU)
The IT security specialist is responsible for the operational coordination and quality assurance of penetration tests, security assessments, and TIBER-EU requirements. The position requires 3-6 years of experience in IT security, a solid understanding of web application security, and experience with Jira and/or ServiceNow.
Tasks
- Leading scoping discussions for internal and external penetration tests, defining objectives, scope, ROE, and technical requirements
- Evaluating vendor proposals for security assessments, assessing scope, methodology, quality, costs, and schedules
- Identifying gaps and risks in vendor proposals, collaborating with stakeholders to make informed selection decisions
- Conduct thorough reviews of pen test reports to ensure technical accuracy, clear evidence, appropriate severity rating, and actionable remediation guidance.
- Ensure that all results are reproducible, well documented, and effectively communicated; clarify with suppliers if necessary.
- Manage the vulnerability lifecycle with Jira/ServiceNow, including tracking, prioritizing, following up, and escalating overdue or blocked items.
- Monitor remediation progress with a risk-based focus, providing regular updates on key metrics such as critical outcomes, MTTR, and relapse trends.
- Providing technical support to coordinators and engineers, assisting with the interpretation of results and the planning of corrective measures
- Organize and conduct internal retests to verify the effectiveness of corrections and contribute to root cause analysis to prevent future vulnerabilities.
- Supporting TIBER-EU engagements, where applicable, ensuring compliance with governance, traceability, and follow-up of actions after evaluation
- Continuous improvement of assessment standards, checklists, and processes for scoping, reporting, and retesting activities
Requirements
- Bachelor's degree in computer science, information security, or equivalent practical experience
- 3-6 years of experience in IT security delivery, AppSec, SecOps, or security assessment coordination and scheduling
- Solid understanding of web application security and API security (OWASP Top 10), vulnerability classes, and risk assessment
- Comprehensive knowledge of common penetration testing methods and deliverables (scope, ROE, test plan, report, retest)
- Experience with Jira and/or ServiceNow for issue and vulnerability management
Nice to have
- Previous experience in a security or similar technical environment
- management level
- Professional English skills (written and spoken), German is an advantage
We offer
No information available.Job details