nationwide, , Germany
2 months ago

Job Overview

Job Type
Full-Time
Pay
Not disclosed

Job description

Location:
nationwide, Germany
Work arrangement:
On-site

Role Summary

  • In this role, you will take on demanding penetration tests in the areas of web, mobile, infrastructure, cloud, API or OT - depending on your profile
  • You plan and implement red teaming and purple teaming operations and carry out realistic attack simulations
  • Social engineering and evasion techniques are also used to test security mechanisms
  • In addition, you develop threat scenarios and carry out adversary emulation based on current TTPs

AI-powered methods for vulnerability detection, exploit synthesis, attack automation and code analysis are also part of your toolbox, which you continually develop

Together with the team, you will build an offensive security factory and design its automation, scripting and orchestration (CI/CD for offensive security)

You advise on security-related architectural and design decisions and contribute your expertise

You will also actively work on the further development of our offensive security portfolio, for example on projects such as the AI OffSec Lab, Adversarial AI or automated scanning pipelines

Consulting means flexibility: Your project assignment depends on our customers and your project situation - you work throughout Germany in our offices, at the customer's site and from home

Requirements

  • You have successfully completed a degree in (business) computer science, mathematics, engineering or a comparable qualification
  • In addition, you have already gained and successfully applied several years of experience in the areas of penetration testing or offensive security
  • You have very good knowledge of common OffSec methods and frameworks such as OWASP, PTES and MITER ATT&CK
  • You are familiar with tools such as Burp Suite, Metasploit, Cobalt Strike, Empire, BloodHound, Nmap, Nessus or Kali and are part of your everyday life
  • Not only are you familiar with red teaming methods, but ideally you also have practical experience in this area
  • Knowledge in the area of AI-supported offensive security, such as LLM-supported recon, automation, AI tooling or prompt exploitation, rounds off your profile
  • Experience with cloud security attack paths in Azure, AWS or GCP is a plus
  • Relevant certifications such as OSCP, OSCE3, OSEP, CRTO, OSEE, eCPPT, eWPT/X or CPSA/CTP are desirable
  • You are characterized by an analytical way of thinking, independent work and a high level of responsibility
  • Good knowledge of German (from B2 level) and knowledge of English round off your profile

Benefits

  • Further training: extensive technical and methodological training including certifications as well as diverse development prospects within the company
  • Work-life balance: hybrid working within Germany and for a limited period of time in defined EU countries, family service, company fitness and the opportunity for a sabbatical
  • Flexible vacation arrangement: 30 days vacation and the option to individually increase or decrease the annual vacation by up to 5 days
  • SpenditCard: In addition to your salary, you have 50 euros of tax-free credit available to you every month, which you can use flexibly for shops in your area
  • IT equipment: We support you in equipping you with the additional equipment you need for optimal location-flexible work
  • Mobility: Company car and company bicycle through salary conversion and subsidy for the Deutschlandticket
  • Our mindset: team spirit, open doors, first-name culture, lived diversity

Diversity is an important foundation of our corporate culture. We want to create an inclusive environment that takes into account the diversity of all of our 2,700 employees in Germany and Austria and in which you can develop to the best of your ability. Because we at Sopra Steria are convinced that your individuality is the key to sustainable business success.

  • We are committed to a sustainable future: whether with group-wide scholarship and corporate volunteering programs or with projects to promote education, equal opportunities and digital inclusion - we take responsibility for society.
  • We firmly believe that digital innovations are a key to equality, inclusion and climate protection.
  • imprint

About the Company

As one of the leading European management and technology consultancies, we are a real tech player. We see ourselves as thought leaders, act and think strategically, develop tailor-made solutions and precise processes with our customers and implement innovative technologies. We are over 50,000 tech-savvy and clever minds worldwide - together we shape the future of our customers and that of society.

Role:
Senior Consultant Offensive Security (m/w/d)
Industry Type:
Information Technology And Services
Job Type:
Full-Time

Company profile

Sopra Steria

soprasteria.com

Sopra Steria is a European technology company recognised for its consulting, digital services and software development. It helps large companies and organizations carry out their digital transformation by combining knowledge of their sectors and technologies with a collaborative approach. The group has 51,000 employees in nearly 30 countries and achieved a turnover of 5.6 billion euros in 2025. Its subsidiaries include CS Group, which develops and certifies safety-critical systems for the aerospace, electric and autonomous driving industries.

Company Size
50,000 - 100,000 employees
Headquarters
Annecy-le-Vieux, France
Founded
2015
Funding Stage
Public

More jobs at Sopra Steria

Similar Consultant jobs at other companies