OPEN TO WORK ⁄⁄ PENETRATION TESTER ⁄⁄ REMOTE EU ⁄⁄ 20+ VERIFIED FINDINGS ⁄⁄ SECURITY+ CERTIFIED ⁄⁄ OT/ICS BACKGROUND ⁄⁄ OPEN TO WORK ⁄⁄ PENETRATION TESTER ⁄⁄ REMOTE EU ⁄⁄ 20+ VERIFIED FINDINGS ⁄⁄ SECURITY+ CERTIFIED ⁄⁄ OT/ICS BACKGROUND ⁄⁄ 
[ CLEARANCE: ROOT · OFFEN FÜR ANGEBOTE ][ CLEARANCE: ROOT · OPEN TO OFFERS ]

ICH FINDE,
WAS SCANNER
ÜBERSEHEN.
I FIND WHAT
SCANNERS
MISS.

Penetration Tester & Bug-Bounty-Researcher. 20+ verifizierte Findings seit 2020 — RCE, SQLi, IDOR, Auth-Bypass, Business-Logic-Chains. Manuell gefunden, nicht gescannt. Ich suche eine Junior-/Trainee-Position im Offensive Security, remote in der EU.

Penetration tester & bug-bounty researcher. 20+ verified findings since 2020 — RCE, SQLi, IDOR, auth bypass, business-logic chains. Found by hand, not by scanner. Looking for a junior / trainee role in offensive security, remote across the EU.

20+
Verifizierte Findings · NDAVerified findings · NDA
9.9
Max CVSS · patchedMax CVSS · patched
Sec+
CompTIA · SY0-701
2020
Offensive Praxis seitOffensive practice since
01ProfilProfile

Wer hinter dem Balken steckt.

Who's behind the bar.

~/whoami.sh
josef@sec:~$ cat profile.txt
Offensive-Security-Spezialist mit 5+ Jahren praktischer Erfahrung in Bug Bounty, Web-/API-Pentesting und Active-Directory-Angriffen. Seit 2020 in privaten / invite-only Programmen auf HackerOne und Bugcrowd — 20+ verifizierte Schwachstellen, Schwerpunkt Business-Logic-Flaws und Exploit-Chains. CompTIA Security+ (SY0-701) zertifiziert. Eigenes Security-Lab, dokumentierte Methodik, laufender Zertifizierungspfad (PenTest+, CEH v13, OSCP für Q4 2026). Zusätzlich ausgebildeter Mechatroniker (Siemens S7, SCADA) — direkter Draht zu OT/ICS-Security. Offensive-security specialist with 5+ years of hands-on experience in bug bounty, web/API penetration testing and Active Directory attacks. Active since 2020 in private / invite-only programs on HackerOne and Bugcrowd — 20+ verified vulnerabilities, focused on business-logic flaws and exploit chains. CompTIA Security+ (SY0-701) certified. Own security lab, documented methodology, certification path in progress (PenTest+, CEH v13, OSCP planned Q4 2026). Also a trained mechatronics engineer (Siemens S7, SCADA) — a direct line into OT/ICS security.
josef@sec:~$ _
02Technische SchwerpunkteTechnical Skills

Was ich mitbringe.

What I bring.

Offensive Security

Penetration TestingWeb & APIBug BountyRecon & EnumPrivilege EscalationAD AttacksPost-Exploitation

Tools

Burp Suite ProMetasploitNmapBloodHoundCrackMapExecImpacketffufsqlmapWireshark

Scripting

PythonBashPowerShellJavaScript

NetzwerkeNetworking

TCP/IPDNSDHCPSubnettingRoutingFirewalls

Systeme

Kali LinuxParrot OSWindows ServerActive DirectoryDocker

OT / ICS

Siemens S7SCADAModbusOPC UAIT/OT-SchnittstellenIT/OT interfaces
03ArbeitsprobeWork Sample

So sieht meine Arbeit aus.

What my work looks like.

Anonymisierter Auszug aus einem realen Bug-Bounty-Report (HackerOne, disclosed & patched). Kein Hochglanz-PDF — Methodik, reproduzierbar, nach OWASP & MITRE ATT&CK.

Anonymised excerpt from a real bug-bounty report (HackerOne, disclosed & patched). No glossy PDF — methodology, reproducible, mapped to OWASP & MITRE ATT&CK.

Severity CriticalCVSS v3.1 · 9.9CVSS v4.0 · 9.3Status · Patched
Chained Exploit · SQLi → Stored XSS → SSTI → RCE
01 · SQL Injection
Public form · unauth
CWE-89
02 · Stored XSS
Admin-Dashboard · Session-HijackAdmin dashboard · session hijack
CWE-79
03 · SSTI → RCE
Report generator · Jinja2
CWE-1336 · 94
04 · Root Shell
uid=0(root) · <60s
T1190 · T1059
Report-ID · JBSEC-2026-001CWE · 89 · 79 · 1336 · 94MITRE ATT&CK · T1190 · T1059

▸ Vollständiger Report als PDF: assets/sample-finding.pdf · Weitere dokumentierte Angriffsketten: HTB-Writeups & Study-Notes.

▸ Full report as PDF: assets/sample-finding.pdf · More documented attack chains: HTB-Writeups & Study-Notes.

04ZertifizierungenCertifications

Der Weg zum OSCP.

The road to OSCP.

CompTIA Security+ (SY0-701)bestanden · 05/2026passed · 05/2026
CompTIA PenTest+in Vorbereitungin progress
EC-Council CEH v13in Vorbereitungin progress
CompTIA Network+ / Linux+in Vorbereitungin progress
OffSec OSCPgeplant · Q4 2026planned · Q4 2026

Kurse abgeschlossen über New Horizons (zertifizierter Bildungsträger).

Courses completed via New Horizons (accredited training provider).

05EhrenamtVolunteer

Ich rede auch drüber.

I also talk about it.

8
Schulen seit 2024. Ehrenamtliche Vorträge zu LLMs, KI-Sicherheitsrisiken, Phishing und Cybersecurity-Grundlagen — für Schüler:innen und Lehrkräfte. Komplexe Themen so erklären, dass sie hängenbleiben: das gehört zum Job dazu.
Schools since 2024. Volunteer talks on LLMs, AI security risks, phishing and cybersecurity fundamentals — for students and teachers. Explaining complex topics so they stick is part of the job.
06KontaktContact

Reden wir.

Let's talk.

Offen für Junior-/Trainee-Positionen und Werkstudenten-Rollen im Penetration Testing — remote in der EU oder hybrid. Antwort meist innerhalb von 48 Stunden.

Open to junior / trainee and working-student roles in penetration testing — remote across the EU or hybrid. I usually reply within 48 hours.

Lebenslauf herunterladenDownload CV
Deutschland · Remote (EU)Germany · Remote (EU)