Red Teamer/Pentester (m/f/d)
- Luxemburg
- Unbefristet
- Vollzeit
- Work on diverse offensive security engagements covering web apps, internal infrastructure, Active Directory, phishing/vishing, physical intrusion, Red Team and Purple Team exercises, and advanced assessments in modern environments.
- Produce sharp, actionable deliverables for technical teams and executive stakeholders.
- Support proposal writing, scoping, and the design of tailored technical engagements.
- Help improve our labs, tooling, knowledge base, and offensive capabilities.
- Contribute to a culture of continuous learning through mentoring, technical exchanges, and shared research.
- Collaborate with local and global colleagues across our cybersecurity network.
- Evolve in a high-performing team that values trust, flexibility, and balance.
- Be part of a team where R&D is not marketing language but a real part of the job. We invest time in hands-on research, practical experimentation, reproducing emerging attacks, and refining attacker tradecraft.
- Join colleagues who attend and contribute to leading cybersecurity events including DEF CON, Hack.lu, leHACK, BruCON, Black Alps, and BSides Luxembourg, and who publish and share their expertise with the wider community. In 2025, four team members presented internal research at Hack.lu. The next one could be you!
- Have a strong academic background in Computer Science, Cybersecurity, Network Engineering, Offensive Security, or a related field.
- Are technically curious and driven to understand how systems fail and how attackers operate.
- Enjoy learning by doing and want to sharpen your offensive skills in real-world assignments.
- Can communicate clearly and professionally in English, both verbally and in writing.
- Value ethics, discretion, and professionalism.
- Thrive both autonomously and as part of a strong team.
- Bring experience according to your level, from strong potential and first hands-on exposure for junior candidates to proven offensive security experience for senior profiles.
- Have prior experience in offensive security, cybersecurity consulting, or hands-on security testing.
- Hold recognised certifications such as OSCP, OSEE, GPEN, GXPN, CRTO, CRTL, or equivalent.
- Have shared knowledge with the community through talks, blogs, tools, open source, research, or CVEs.
- Have an interest in offensive R&D and staying close to the evolution of attacker techniques.
- Know the Luxembourg market and/or its regulatory environment.