
Security Research Labs · Berlin
ABOUT US: SRLabs is home to knowledge leaders securing critical infrastructures in finance, energy, and telecommunications. We focus on hands-on hacking resili...
SRLabs is home to knowledge leaders securing critical infrastructures in finance, energy, and telecommunications. We focus on
hands-on hacking resilience – not compliance – by combining cutting-edge hacking research with impactful consulting work for
innovation-driven organizations.
What makes us unique?
We are a diverse, international team of experts who thrive on solving complex problems. Our backgrounds span coding, reverse
engineering, penetration testing, exploit scripting, research, and consulting. This broad mix enables us to influence the security
design of large-scale organizations.
As our team grows, we are expanding our Defensive Capabilities and are looking for an experienced Senior Digital Forensic
Specialist to strengthen our work in incident response, forensics, and client resilience.
In this role, you will take the lead on technical forensic investigations , applying deep expertise to analyze attacks, uncover
evidence, and provide resolution strategies. You will operate in complex, large-scale environments, handling unique incidents and
helping organizations recover while building long-term resilience. You will also help clients improve their defensive capabilities
and their cyber security maturity by doing assessments, threat hunting and technical analysis.
You will work alongside hackers, researchers, and consultants to investigate attacks, contain incidents, and strengthen defenses
within organizations.
expertise and guidance.
research, incident remediation, vulnerability research, cloud security, security architecture, SIEM, SOC, ...)
We are looking forward to getting to know you and discuss the opportunity. We value diversity and encourage candidates from all
backgrounds – especially those from underrepresented groups in IT security
ABOUT US: SRLabs is home to knowledge leaders securing critical infrastructures in finance, energy, and telecommunications. We focus on hands-on hacking resilience – not compliance –, which we shape by combining our hacking research with impactful consulting work for innovation leaders that have a natural thrive for cutting-edge technologies. What makes us unique? We come from diverse backgrounds from all over the world, and that's just the way we like it. From coding, reverse engineering, penetration testing, exploit scripting, process design, research and consulting skills, our mix of colleagues possesses a vast set of qualifications, that equips us to influence design decisions of large-scale organisations. YOUR RESPONSIBILITIES Job brief: As a Red teamer at SRLabs, you work in a small and specialised team simulating infiltrations of corporate environments with high levels of protection for our clients. From obtaining initial access via external vulnerabilities or phishing, over lateral movement and to a domain takeover, you take part in the full chain of emulating adversarial cyber attacks. To remain undetected and complete your mission, you are able to avoid noise and bypass detection solutions and other protection measures. You analyze protection and monitoring gaps for their technical and operational root causes, and provide actionable steps for closing these gaps, bearing in mind the customer specific constraints our clients are facing. Your strategic advice supports the management in defining the security roadmap and employing security budget most effectively. Your Responsibilities: * Participate in red team engagements at SRLabs' clients * Perform external penetration testing and run phishing campaigns * Bypass protection measures and move undetected inside corporate networks * Develop tools, scripts and exploits for red team engagements * Create presentations to communicate risk and provide strategic advice on process optimizations * Support the client in addressing findings, in both, written and verbal communication * Develop methodologies to extrapolate from Red Team insights to generic security assurance checks * (Optional) Lead red team exercises and take responsibility for what comes with it (scoping, task management, escalations, ...) WHAT DO YOU BRING? What do you bring: * Strong foundational knowledge of information technology, including (Operating systems, Networking and Web technologies) * Hands-on experience in offensive security and red teaming * Solid experience with Active Directory and Entra ID security * Experience in client-facing roles or security consulting, including (presenting technical findings to diverse audience and provide strategic advice to clients) * Infrastructure and web penetration testing * Proficiency in programming languages such as: * Python, C/C++, Go, Java * Excellent communication skills in English (written and verbal) Nice to have Relevant expertise from areas like * Malware delivery and development * Incident response * Vulnerability research and exploit development * Reconnaissance, OSINT and social engineering * Operational security and bypassing of security measures (AV/EDR, endpoint and infrastructure hardening, SIEM generated alerts, Honeypots, ...) * Detection engineering and SOC operation * Experience in management consulting and communication WHAT AWAITS YOU WITH US? What awaits you with us: * Diverse team of highly motivated and competent security experts * Culture of constant learning and improvement * Flexible home office. * You can work from anywhere in Germany * Yearly company retreat * Urban Sports Club membership * Deutschlandticket (public transportation) * 30 days paid vacation APPLY NOW We are looking forward to receiving your application.
ABOUT US: SRLabs is home to knowledge leaders securing critical infrastructures in finance, energy, and telecommunications. We focus on hands-on hacking resilience – not compliance –, which we shape by combining our hacking research with impactful consulting work for innovation leaders that have a natural thrive for cutting-edge technologies. We come from diverse backgrounds from all over the world, and that's just the way we like it. From coding, reverse engineering, penetration testing, exploit scripting, process design, research and consulting skills, our mix of colleagues possesses a vast set of qualifications, that equips us to influence design decisions of large-scale organisations. YOUR RESPONSIBILITIES Job brief: In this role, you lead a team of security consultants delivering consulting and assessment services such as offensive assessments, resilience improvements, or AI security engagements for some of the world's most complex organisations. You are equally comfortable in front of a client board and in the weeds of a red team debrief. Your responsibilities: * Lead and oversee security engagements including red teaming, TIBER/DORA resilience assessments, penetration testing, and AI-focused security reviews and others * Act as the primary point of contact for senior client stakeholders – translating technical findings into business risk and actionable recommendations * Manage project delivery across scope, timeline, quality, and team utilisation * Mentor and develop junior and mid-level consultants, providing hands-on guidance on complex engagements * Drive business development by contributing to proposals, scoping, and client relationships * Shape our AI security offering – including LLM red teaming, model security assessments, and AI risk frameworks * Contribute to research and thought leadership that keeps SRLabs at the cutting edge WHAT DO YOU BRING? * Proven hands-on background in security with the credibility to lead technical teams * Experience leading or managing security consulting engagements, including client-facing delivery at senior levels * Solid understanding of enterprise and resilience frameworks * Familiarity with AI/ML security concepts * Ability to communicate complex security issues clearly to both technical and non-technical audiences * Strong communication skills in English and German is nice to have * Experience writing proposals, scoping engagements, and managing expectations WHAT AWAITS YOU WITH US? * A senior role with real influence over how we build and grow our offensive security practice * Diverse team of motivated security experts from many countries and backgrounds * Opportunity to shape cutting-edge AI security work before it becomes mainstream * Annual company retreat – a week of working holiday packed with fun, team building, and knowledge sharing * Professional development: conference speaking, research publication, and training budget * Competitive salary and flexible home office * 30 days vacation period * A wide range of benefits (discounts on Urban sports gym and Public transport ticket) APPLY NOW We are looking forward to getting to know you! SRLabs is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for our team.
ABOUT EYE SECURITY Eye Security is providing cybersecurity with embedded cyber insurance solutions for organizations in Europe. Headquartered in the Netherlands, we are already over 170 FTEs and continue to grow internationally. We combine cutting-edge technology with hands-on expertise to detect, respond to, and recover from cyber threats in real time. Our team brings together talent from intelligence, military, tech, and consulting backgrounds — all united by a shared mission: to make enterprise-grade cybersecurity accessible to every business, not just the big players. At Eye, you’ll work on projects with an international footprint, solving real-world challenges and helping to build a safer digital future for our clients. ABOUT THIS ROLE We are looking for a Staff Cyber Security Specialist (f/m/x) to strengthen our Incident Response and Security Operations capabilities. This is a senior individual contributor role for an experienced incident responder who enjoys solving complex security challenges and helping organizations navigate critical cyber incidents. In this role, you will lead incident response engagements from investigation through recovery, working directly with customers during some of their most challenging moments. You will act as a trusted technical authority within the team, mentor less experienced responders, and help drive improvements across our security operations. Unlike traditional consultancy environments, you will operate within a product-driven MDR organization serving more than 1,000 customers across Europe. This gives you the opportunity to work at scale, leverage large security datasets, and contribute improvements that strengthen protections across our entire customer base. You will work with state-of-the-art security tooling while collaborating with security professionals from intelligence, military, consulting, national CERT, and technology backgrounds. Alongside operational response work, you'll have opportunities to contribute to internal research initiatives, Bug Bounty Fridays, Capture The Flag events, and other technical projects that help push our capabilities forward. This position is based in the Netherlands and reports directly to the Director of Security Operations. WHAT YOU WILL DO * Act as a leading technical authority within Security Operations, taking ownership of strategic improvement initiatives and helping shape the future direction of our incident response and security operations capabilities. * Lead cyber incident response engagements from intake through recovery. * Act as the technical lead during investigations, coordinating response activities and driving outcomes. * Conduct forensic investigations to determine attack scope, root cause, and impact. * Support customers during active cybersecurity incidents and provide clear technical guidance. * Support MDR and Security Operations activities when not engaged in active incident response cases. * Work with internal and external stakeholders, including management, legal counsel, law enforcement, and regulators when required. * Mentor junior and medior responders and help raise the technical maturity of the team. * Contribute to the continuous improvement of incident response methodologies, playbooks, and operational processes. WHAT YOU WILL NEED * 6+ years of experience in cybersecurity with significant hands-on experience in Incident Response, Digital Forensics, Security Operations, or related disciplines. * Proven ability to independently lead and manage cybersecurity incidents end-to-end. * In-depth knowledge of Windows, Linux, and macOS operating systems, file systems, security architecture, and attack surfaces. * Strong knowledge of enterprise infrastructure, networking, and network security principles. * Experience with EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, or similar technologies. * Knowledge of cloud environments and cloud security concepts across Microsoft 365, Azure, AWS, or Google Cloud. * Strong investigative and analytical skills with experience collecting and analysing evidence during security incidents. * Ability to communicate technical findings clearly to both technical and non-technical stakeholders. * Experience mentoring or coaching other security professionals. * Strong ownership, collaboration, and communication skills. * Fluency in English (internal working language) * Fluency in Dutch (required for client communication) Nice-to-have * Experience developing scripts, tools, or automations to support investigations and response activities. * Experience conducting technical security research. * Knowledge of threat actors and attacker tactics, techniques, and procedures (TTPs). * Experience working in a CERT, CSIRT, MDR, or DFIR environment. WHAT WE OFFER * A meaningful mission: protect organizations across Europe from real-world cyber threats * Work with top-tier professionals from national CERTs, intelligence agencies, and leading tech backgrounds * A remote-friendly culture with quarterly meetups and annual company retreats (in Spain, Portugal, Italy…) * Thursday socials to stay connected * A generous time-off policy, including wellbeing and volunteering days