Point your AI agent at freehire and let it find you a job.

Get the CLI →

TÜV SÜD

New

Penetration Tester

Posted Updated
Discussion

We are seeking an experienced and highly technical Senior Cybersecurity Specialist to lead and execute comprehensive security assessments across industrial (OT/ICS), IoT, and automotive domains. You will drive hands-on penetration testing (VAPT), technical conformity assessments, threat modeling, and code reviews, while acting as a subject matter expert for client engagements, regulatory compliance, and team growth.

Key Responsibilities:

  • Conduct comprehensive vulnerability assessments and penetration testing of networks, web/mobile applications, cloud environments, and specialized OT/ICS components (e.g., PLCs, SCADA, IoT, IIoT devices).
  • Perform cybersecurity testing for automotive vehicles, including VAPT of ECUs and in-vehicle networks.
  • Threat Modeling & Code Review: Conduct threat modeling, source code reviews for control flow/security flaws, and evaluate risk assessments to identify technical gaps.
  • Develop, refine, and maintain audit-ready cybersecurity testing methodologies, procedures, and VAPT documentation.
  • Lead cybersecurity assessments (e.g. VAPT, code review, threat modelling) across IIoT, OT, and ICS products and systems
  • Deep Architectural Knowledge: Strong understanding of component and system architectures across both IT and OT environments, including common operating systems (Windows, Linux) and their respective security features.
  • Network & Industrial Protocols: Strong grasp of network protocols and typical industrial communication protocols (e.g., Modbus, Profinet, OPC, DNP3.0, CAN).

Education & Experience:

  • Bachelor’s degree in computer science, Information Security, Computer/Information Engineering, or a related technical field.
  • 8-15+ years of overall cybersecurity experience, featuring a minimum of 5–8 years of dedicated security testing on industrial control systems (ICS), IoT, IIoT, or automotive product environments.
  • Standards, Frameworks & Compliance
    • Industrial & General OT Standards: Practical application of ISA/IEC 62443, NIST 800-82, NERC-CIP, MITRE ATT&CK, and NIST CSF.
    • Specialized & Maritime Standards: Proficiency in developing VAPT methodologies specifically aligned with IEC 61162-460:2024 (maritime navigation and radiocommunication equipment) and ISO/IEC 27001.
    • Automotive Standards: Strong compliance and threat modeling expertise aligned with ISO/SAE 21434.
    • Regulatory & Conformity Frameworks: Familiarity with global regulations and assessment methodologies (e.g., CRA, RED, NIST SP 800-115, PTES, ISSAF, IEC 61508, NIST 800-53 CA-8)
    • Industry Tools: High proficiency with standard penetration testing tools and frameworks (e.g., Nessus, Burp Suite, Nmap, and other ethical hacking utilities).
    • Possession of at least one (or more) professional certification is highly advantageous:
      • Offensive/Testing: OSCP, CREST, GPEN, CEH
      • Audit/Management: CISA, CISM, CISSP, ISA/IEC 62443 Certified Specialist
  • Exceptional verbal and written communication skills; ability to translate complex technical findings, risks, and recommended mitigations into clear reports for both technical teams and non-technical stakeholders.

Skills

Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available