Zürich
Penetration Tester
- 28 September 2026
- 80 – 100%
- Permanent position
- German (Fluent), English (Intermediate)
About the job
What to Expect
As a Penetration Tester, you find and analyse security vulnerabilities in systems, applications, and infrastructures of our clients. Using offensive security techniques, established methods, and clear reports, you contribute to specifically strengthening the cyber resilience of our clients.
You can expect a diverse project environment with companies from various industries: You work with offensive security techniques and modern tools, conduct technical security audits according to established methods such as OSSTMM, OWASP ASVS, or comparable testing procedures, and regularly communicate with our clients. Many projects last one to two weeks, while larger assessments are accompanied over several months – depending on the assignment, either alone or in a dynamically assembled team. This way, you apply your strengths purposefully, continuously learn, and benefit from strong knowledge exchange.
Your varied range of tasks includes the following:
- Searching for and analysing security vulnerabilities and weaknesses through penetration tests, code and configuration reviews, as well as reverse engineering inWeb applicationsNetworksCloud services and cloud componentsMobile apps (iOS, Android)Embedded devicesICS (SCADA / DCS)Complex infrastructuresetc.
- Developing appropriate measures and proposals
- Documenting the project in the form of reports, advisories, etc.
- Further developing supporting tools and aids
What We Offer You
You take on responsibility step by step from the start and are accompanied by your team. In case of challenges, you will always find someone who takes time for you and supports you. We also place great value on your personal development, which we support through various internal and external training opportunities.
You can also look forward to the following:
- Your voice counts! With us, you actively shape things: bring in your ideas, implement them independently, and use the freedom to make decisions and drive change
- A culture of informal address where mutual respect, tolerance, and appreciation are lived, and feedback is an important part of our daily routine. We also count on your constructive criticism
- A structured onboarding programme
- We offer you scope for action and decision-making so that you can gain your own experience and develop further
- Modern and spacious offices just a few minutes’ walk from the station
- Possibility for home office
- Contribution to health-promoting measures up to CHF 500
- 40-hour week and at least 5 weeks’ holiday
- Smartphone with flat-rate subscription
- Additional day off on your birthday
- …and much more
What You Bring
- Proven experience in penetration testing, application security testing, or technical security audits
- Knowledge of web applications, networks, infrastructures, cloud environments, and/or mobile security
- Experience with offensive security techniques, testing tools, and methods such as OSSTMM, OWASP ASVS, or comparable standards
- Analytical approach to identifying, assessing, and documenting vulnerabilities
- Experience in technical documentation, reports, and recommendations for measures
- Education or further training in computer science, cybersecurity, or a comparable technical field; relevant certifications (OSCP, OSSTMM, OPST, BSCP, etc.) are an advantage
- Fluent German and good English skills, both spoken and written
- Impeccable character, verifiable by criminal and debt register extracts
Application
Have we ignited the fire in you? We look forward to your call or your application documents directly. It is important to us that your passion for cybersecurity is clearly evident in your insightful application. Show us with your application what you have already worked on, what drives you, and why you want to continue on this path. We will close any professional or technical gaps together within the framework of our training programme.
Please only direct applications: enquiries from recruitment agencies / headhunters are not desired.