655,248open jobs
38,129companies
91,967added this week
Browse all
Salary
$67k – $171k per year (Estimated)
Location
Remote/Hybrid (Cologne, Germany)
Seniority
Intern
Employment
Internship
Overview
Company
Impact
Profile match

Cologne, Germany (Hybrid)

Team: Engineering · Reports to: CTO · Format: Working Student (16-20h/week) or Internship (3-6 months)

Join our red team

ilert is a SaaS platform for alerting, on-call management and incident response that keeps digital services always on. Teams worldwide rely on us to stay up.

To keep it that way, we are building an internal red team that continuously tests our own products the way a real attacker would. And we're a genuinely interesting target: an attacker who silences ilert doesn't just steal data - they turn off the alarm while they work.

As a working student on our red team, you help us find, prove, and get security issues fixed in our own systems. You learn to think like an attacker, working closely with our team.

You don't need to arrive as a finished pentester. You need curiosity, a habit of taking things apart to understand them, and the care to handle what you find responsibly.

Tasks

  • Test Our Apps and APIs: Hunt for vulnerabilities in our web and mobile apps and APIs - from authentication and access control (IDOR) to injection, misconfigurations, and exposed secrets.
  • Re-test Past Findings: Go back over findings from previous penetration tests and verify the fixes actually hold.
  • Automate Security Checks in CI: Help build secret, dependency, and code scanning into our pipelines so issues surface early instead of late.
  • Review New Features Before They Ship: Support security reviews as features are being built, not after.
  • Run Authorized Social Engineering: Design and run phishing and pretexting exercises against our own team - always under a written scope signed off by the CTO beforehand, always debriefed as a learning exercise, never punitive. Then help us fix what the exercise exposed.
  • Poke at the AI: We're building an AI SRE that investigates incidents and can execute actions on approval. Prompt injection, tool abuse, and agent-boundary testing are wide-open ground.
  • Document and Follow Through: Write up findings clearly and reproducibly, then follow them through to a fix. We care as much about closing the gap as finding it.

What you bring

  • Enrolled student, ideally in computer science, IT security, or similar.
  • Genuine interest in offensive security - you tinker, you break things to understand them, maybe you already play CTFs / Hack The Box / TryHackMe.
  • Basic grasp of how web apps and HTTP work - requests, headers, auth, cookies/tokens.
  • Comfortable on the command line and with at least one scripting language (Python, JS/TS, Go).
  • Careful and responsible with sensitive information. This role comes with access and trust: you stay inside the agreed scope and handle what you find responsibly.
  • Fluent English (our working language).
  • Able to be in our Cologne office regularly - the role is hybrid, not remote.

Bonus

  • Burp Suite or OWASP ZAP
  • OWASP Top 10
  • AWS / Kubernetes / CI-CD exposure
  • Mobile app testing
  • LLM and agent security - prompt injection, tool-use boundaries
  • Your own CVEs or bug-bounty reports
  • German language skills

Benefits

  • A Real Attack Surface: Not a lab, not a CTF box. Production software that companies worldwide depend on during their worst moments.
  • Get In Early: The red team is being built right now. You're not inheriting someone else's checklist - you help shape how we do this.
  • Unexplored Ground: Agentic AI security is barely a discipline yet. You'd be doing original work on it, on a product that's actually shipping.
  • Hybrid Freedom: Our office in Cologne Rheinauhafen (3 days/week) plus work from home (2 days/week).
  • Student-Centric: Flexible hours around lectures and exam periods.
  • Direct Mentorship: You report to the CTO and work alongside experienced engineers who want to be shown where they got it wrong.
  • Focus Culture: We protect maker time, favor async, and keep meetings rare.

We hire for curiosity and a builder's mentality, not a checklist. If you have a writeup, a CTF profile, a disclosed vulnerability, or a tool you built - bring it. But if you're early and hungry and can show us something you took apart, we want to hear from you too.

Keywords: Werkstudent IT-Security, Penetration Testing, Praktikum Cyber Security, Red Team, Application Security, Köln.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
655,248 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Cologne
$85k – $171k per year (Estimated) • Equity • Remote • Full-Time • 7+ years exp • Bachelor's Degree
Python
TypeScript
Python
Flask
FastAPI
Django
Databases
Snowflake
Databricks
Google BigQuery
Amazon Redshift
BigQuery
AI/ML
Cursor
AI Agents
LLM
RAG
Human-in-the-Loop
LLM Guardrails
Agentic Workflows
DevOps
CI/CD
AWS
Docker
Kubernetes
Apply
$200k – $300k per year • Remote/Hybrid • Full-Time • 8+ years exp • San Francisco • New York
Python
Databases
Redis
Amazon DocumentDB
DevOps
Terraform
GitHub Actions
Terragrunt
CI/CD
AWS
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
Cybersecurity
HIPAA
Apply
DevOps Engineer 1 day ago
Remote/Hybrid • 3+ years exp
Python
PowerShell
DevOps
Terraform
GitHub Actions
New Relic
CloudFormation
Prometheus
CI/CD
Git
AWS
Kubernetes
Grafana
Bamboo
Amazon EKS
AWS Lambda
Amazon EC2
Amazon S3
IAM
Cybersecurity
SonarQube
Veracode
Management
Jira
Agile
Apply
$87k – $175k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
C++
C++
CMake
DevOps
GitHub Actions
CI/CD
Jenkins
Docker
Buildkite
Bazel
Management
Agile
Apply
Data Editor 1 day ago
$64k – $161k per year (Estimated) • Remote • Full-Time • Bachelor's Degree
Python
MATLAB
AI/ML
SciPy
Pandas
NumPy
DevOps
Azure DevOps
Azure
GitHub
Management
Jira
Agile
Apply
$29k – $66k per year (Estimated) • Remote/Hybrid • Part-Time • Cologne
Apply
$68k – $156k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Cologne
AI/ML
AI Agents
DevOps
Vercel
Datadog
Incident Management
Design
Figma
Management
Linear
Notion
Apply
$56k – $126k per year (Estimated) • Remote/Hybrid • Full-Time • Cologne
DevOps
Incident Management
Apply
VP of Sales 1 year ago
$99k – $230k per year (Estimated) • In office • Full-Time • Cologne
AI/ML
AI Agents
Edge AI
Web3
Rollup
Apply
$55k – $130k per year (Estimated) • Remote/Hybrid • Full-Time • Cologne
Apply
$75k – $98k per year • Remote/Hybrid • Full-Time • Cologne • Berlin
AI/ML
Copilot
Apply
$32k – $50k per year (Estimated) • Remote/Hybrid • Part-Time • Cologne
Management
Jira
Apply
$50k – $119k per year (Estimated) • In office • Munich • Cologne • Frankfurt am Main
Apply
$33k – $52k per year (Estimated) • In office • Internship • Cologne
Apply
See all jobs
This is one of many
655,248 more open roles from verified company boards, updated every day.