Security Engineer (m/f/d)
Summary
Security Engineer at a Berlin-based lab performing hands-on audits of enterprise, Web3, and AI systems, building security tooling, and advising clients on secure development practices.
- Tooling: Build and maintain tooling that powers our security reviews, including our in-house fuzzing framework and static/dynamic analysis pipelines.
- Code audits: Conduct attacker-mindset code audits across enterprise and Web3 systems, including blockchain runtimes and smart contracts, using and extending our fuzzing framework.
- AI & agentic security: Assess AI/LLM-powered applications and agentic systems for exploitable weaknesses (e.g. prompt injection, insecure tool use, data leakage) and explore how AI can be used to augment our own audits and tooling.
- Reporting: Produce high-quality technical reports and presentations.
- Client advisory: Advise clients on SDLC improvements, verify remediations, and help track risk-reduction KPIs
- Remediation: Work closely with client developers of the client project team to report and remediate the discovered issues
- Community & training: Participate in hacking exercises, contribute to our Security Ambassador program, and conduct developer trainings
- Security fundamentals: Understanding of software security fundamentals, secure architecture, and threat modeling across enterprise and Web3/blockchain systems.
- AI/LLM security: Curiosity about AI/LLM security risks (prompt injection, model or data exfiltration, agentic tool misuse) or hands-on experience probing AI systems.
- Vulnerability research: Track record of finding and exploiting real-world vulnerabilities (CTFs, bug bounties, pentests, or independent research): this role is for hands-on ethical hackers, security engineers.
- Tooling & automation: Strong ability to automate and build tools for security review (static/dynamic analysis, fuzzing, CI integrations.
- Communication: Excellent communication skills in English and German is a plus.
- Languages: Familiarity with RUST, C/C++, GO and solidity are a plus.
- Consulting mindset: Comfortable advising clients directly, explaining risk clearly, and guiding remediation.
- Hacker mindset: A passion to grow in security.
- Unique opportunity to join the world of cybersecurity in Berlin
- Diverse team of motivated Security Experts with people from many countries
- A wide range of benefits: discounts on gym membership, public transport (BVG pass), German lessons
- Annual company retreat
- Further education, training, and certificate opportunities
- Opportunity to contribute to research
- Flexible home office
- 30 days of paid vacation
SRLabs is an equal-opportunity employer. We welcome applicants of all backgrounds.