It Security Ai-Redteamer

Dkb Code Factory Gmbh
Santiago de Compostela, Spain
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Automation of Tests Bash Shell Burp Suite Cloud Computing Cloud Computing Security Cyber Security Python (Programming Language) Kali Linux
+19 more
Natural Language Processing Nmap Open Web Application Security Systems Development Life Cycle Cloud Services Red Team (Cyber Security) Security Information and Event Management Systems Integration Web Applications Data Logging Cloud Platform System Grafana Software Security Git Gitlab-ci Kubernetes Metasploit Nessus GPT

Job description

Job SummaryUse AI driven offensive security techniques to proactively identify, validate, and communicate exploitable vulnerabilities across DKB’s digital banking products, cloud platforms, APIs, and internal systems. In this high impact role you will run redteam engagements, shape remediation priorities, and help establish a scalable offensive security capability that protects millions of customers.ResponsibilitiesPlan and execute AI-assisted red team engagements across web applications, APIs, cloud workloads and infrastructure, and deliver prioritized technical reports and executive summaries.Provide clear remediation guidance and validate fixes, prioritizing critical and high findings.Configure, tune and maintain offensive tooling and develop automation playbooks that reduce manual triage and false positives.Integrate recurring security checks into CI/CD pipelines and platform processes to enable continuous testing and attack-surface reduction.Run remediation workshops and knowledge transfers, and produce reusable runbooks for product and platform teams.Coordinate triage and handoff with SOC, IT Ops, product teams and central IT Security, and support governance and compliance mapping (OWASP, API Security Top 10, CVSS).QualificationsProven hands on experience in red team or offensive security testing across web apps, APIs, and cloud environments.Solid understanding of OWASP Top 10, API Security Top 10, CVSS, secure SDLC, threat modeling.Experience with AI assisted offensive tooling or demonstrable integration of ML/NLP techniques into offensive workflows (e.g., Mythos, GPT Cyber).Strong practical experience with Burp Suite, OWASP ZAP, Nmap, Metasploit, Nessus/OpenVAS, and Kali Linux.Solid cloud security knowledge, particularly AWS, and experience with Kubernetes and container security.Scripting and automation skills (Python, Bash) and experience integrating security checks in Git/GitLab CI or equivalent CI systems.Excellent written and verbal communication skills in English.Experience with SIEM/logging platforms, OpenSearch, Grafana, or production monitoring stacks and prior experience in financial services or regulated environments are a plus.ConsiderationGot the feeling not to match every single requirement? Don’t worry! We encourage you to apply anyways, even if your qualifications do not align perfectly. You might still be just the right candidate for us!Culture & BenefitsFrom Morning Daily to Afterwork Drink, team spirit is essential to us. The heart of our togetherness is that we truly are connected with each other: We not only share fun & laughter, but also honest opinions - because that’s how we grow: We exchange ideas, give support in our personal development, and celebrate success together! Besides our great community, we also offer numerous other benefits.#J-*****-Ljbffr

Requirements

Proven hands on experience in red team or offensive security testing across web apps, APIs, and cloud environments. Solid understanding of OWASP Top 10, API Security Top 10, CVSS, secure SDLC, threat modeling. Experience with AI assisted offensive tooling or demonstrable integration of ML/NLP techniques into offensive workflows (e.g., Mythos, GPT Cyber). Strong practical experience with Burp Suite, OWASP ZAP, Nmap, Metasploit, Nessus/OpenVAS, and Kali Linux. Solid cloud security knowledge, particularly AWS, and experience with Kubernetes and container security. Scripting and automation skills (Python, Bash) and experience integrating security checks in Git/GitLab CI or equivalent CI systems. Excellent written and verbal communication skills in English. Experience with SIEM/logging platforms, OpenSearch, Grafana, or production monitoring stacks and prior experience in financial services or regulated environments are a plus. Consideration

About the company

Culture & Benefits From Morning Daily to Afterwork Drink, team spirit is essential to us. The heart of our togetherness is that we truly are connected with each other: We not only share fun & laughter, but also honest opinions - because that’s how we grow: We exchange ideas, give support in our personal development, and celebrate success together! Besides our great community, we also offer numerous other benefits. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 · WWC 2024

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all