Senior Penetration Tester – Product Security
Apply now →You test products, not perimeters. As a Senior Penetration Tester for Product Security at Redlings, you assess the software and infrastructure that are part of the product: web and mobile applications, APIs, cloud-native backends, Kubernetes environments and management interfaces, always with the product, not the checklist, as the frame.
The difference to a classic web pentest: the attack chain does not end at the API. It continues into the backend, onto a management interface, or into another component of the product. Thinking that chain through to the end is exactly this role, and what our clients pay for.
What you will work on
- Product penetration tests across applications, APIs, backend systems and network services, on real products, not staging copies.
- Authentication, authorization and complex business logic, the areas where product attacks actually succeed.
- Attack chaining across product layers: from a web finding to the backend, from an API to the management interface, from the cloud to the device.
- Honest exploitability assessment: what an attacker gains in this product, not what the CVSS number suggests.
- Reports whose findings are reproducible and whose recommendations survive contact with an engineering team.
What you must bring
- Several years of hands-on web/API pentesting experience.
- Deep understanding of authentication, authorization and complex business logic.
- Linux and network services, backend systems.
- Sound judgment on technical exploitability.
- Attack chaining across components, thinking in paths, not findings.
- Python/scripting for your own tooling.
- Excellent technical writing, in English.
A strong plus
- Kubernetes and container environments.
- Mobile applications.
- Basic embedded/firmware understanding.
- Product protocols, cloud-native product architectures.
What you will learn with us
- Hardware and firmware assessment, the layers below your usual scope.
- Product threat modelling with engineering teams.
- Coordinated disclosure with manufacturers.
Do not apply if …
- … you want to stop at the API when it gets interesting.
- … you see the report as a necessary evil. Here it is the product.
- … you want to run the same checklist against a new IP every week.
Honestly
- Client travel is the exception, not the model. Most work runs remote or from the lab in Mannheim.
- Small team: you will do things that larger companies have whole departments for, including the parts nobody demos.
- Report writing is real work here, taken as seriously as the exploit.
What we offer
- Permanent position, flexible hours, remote-first with lab days in Mannheim.
- Senior-led reviews, research time for tools and publications.
- Budget for certifications and conferences (OSCP, OSCE & co.).
- Technical roles without sales targets.
Anonymized examples of attack chains you have found are welcome. CV and a few lines via the form, we read everything ourselves. Not a 100% fit? Apply anyway.