Penetration Tester
Penetration Tester
About the role
As a Penetration Tester, you will conduct simulated cyberattacks on internal and external systems, applications, or networks. Using a variety of tools and techniques, you will identify security vulnerabilities that could be exploited by attackers. These tests are performed either independently or in a small team, depending on the project. You will document the results and conditions of the penetration test in a report delivered to the client as the outcome of the audit.
Responsibilities
- Plan and execute security tests for various applications, systems, and (cloud) infrastructures.
- Coordinate with clients and involved penetration testers.
- Document security and compliance issues.
- Write technical reports and communicate results to both technical and non-technical stakeholders.
- Advise on mitigating identified security risks.
- Verify security improvements.
- Research and stay updated on different attack methods.
- Develop new and enhanced methods for penetration testing.
- Improve internal tools and automate common testing procedures to enhance efficiency.
- Occasionally, and based on your interests and skills, you may also:
- Review code for security vulnerabilities (Code Review).
- Participate in Red Teaming operations, focusing on realistic, undetected attack simulations.
- Conduct training sessions, coaching, and presentations.
- Perform reverse engineering of malware or spam.
- Design and execute emulated social-engineering attacks.
- Work on long-term mandates for individual client companies.
- Contribute to non-technical areas such as web presence, marketing, sales, and reporting.
- Create blog posts for the company website as part of your research and project activities.
Requirements
- Knowledge in cybersecurity and experience in penetration testing, application security testing, or other security auditing areas, ideally supported by certifications.
- Resident in Switzerland.
- Fluent in German and proficient in English (both written and spoken).
- Impeccable reputation (verified by a current criminal and debt enforcement register extract).
Benefits
- Transparent salary bands with generous compensation.
- Modern and well-equipped workplaces.
- Spacious offices with numerous shopping and dining options nearby, easily accessible by public transport.
- Efficient reporting using an advanced reporting engine with AI support.
- Flexible working conditions (e.g., part-time and home office).
- Mobile phone subscription.
- Free coffee, mate tea, and company merchandise.
- Generous social benefits.
Pay
- Starting salary with a Master’s degree, no professional experience or certifications: CHF 105,000 gross per year.
- Starting salary with a Master’s degree and general IT work experience: CHF 123,000 gross per year.
- Senior Penetration Tester (Master’s degree, 5 years of penetration testing experience, 3 years of general IT work experience, certifications such as OSCP, BSCP, CRTO, OSEP, CRTL, CAPE): CHF 147,000 gross per year.
Professional Development
- Generous continuing education budget and 10 working days per year for training (adjusted for part-time employees).
- Opportunities for internal training on specific topics or project types.
- Emphasis on knowledge sharing within the company from both personal and business perspectives.
Software Developer
About the role
As a Software Developer, you will be responsible for planning, developing, and enhancing web applications for both internal use and customer projects. You will actively participate in the entire software development process, from requirements analysis and design to implementation, testing, and maintenance. Working closely with penetration testers and other team members, you will develop scalable, secure, and high-performance applications that support both our clients and internal processes.
Responsibilities
- Develop and maintain web applications using Python (Django) and PostgreSQL.
- Deploy and operate on Azure (App Services and VMs), including containerization with Docker.
- Use GitHub for version control, code reviews, and CI/CD.
- Technical conception of new features in coordination with customers and internal stakeholders.
- Enhance existing internal tools and automation solutions.
- Implement security requirements in collaboration with the penetration testing team.
- Document code and architecture.
- Support the establishment and maintenance of DevOps processes.
- Occasionally, and based on your interests and skills, you may also:
- Develop offensive tools and security software in C, C#, or Python.
- Contribute to security-relevant projects, such as integrating vulnerability scanners or internal analysis tools.
- Assist with reverse engineering or security automation.
- Contribute to open-source projects.
- Create technical blog posts about interesting projects or developments.
- Conduct training sessions or technical coaching.
- Take responsibility beyond your core area, such as optimizing development and deployment processes or contributing to the company’s web presence.
Requirements
- Several years of experience in software development, ideally with a focus on web applications.
- Strong knowledge of Python (Django), PostgreSQL, Docker, and ideally Azure App Service.
- Experience with version control (Git/GitHub) and modern DevOps processes.
- Interest in IT security or experience in secure application design is a plus.
- Resident in Switzerland.
Benefits
- Transparent salary bands with generous compensation.
- Modern and well-equipped workplaces.
- Spacious offices with numerous shopping and dining options nearby, easily accessible by public transport.
- Efficient reporting using an advanced reporting engine with AI support.
- Flexible working conditions (e.g., part-time and home office).
- Mobile phone subscription.
- Free coffee, mate tea, and company merchandise.
- Generous social benefits.
Professional Development
- Generous continuing education budget and 10 working days per year for training (adjusted for part-time employees).
- Emphasis on internal knowledge sharing and technical depth.