Join the VamiSec Team
Join our team and help shape the future of cybersecurity. Want to bring your passion for cybersecurity to exciting client projects? Then VamiSec is the right place for you!
Why VamiSec?
Remote-First
Flexible work from anywhere – we trust in results.
Professional Development
Certifications, training, and conferences – we invest in your growth.
Responsibility
Autonomous work on exciting projects for renowned clients.
Team
Small, highly motivated team with flat hierarchies and direct communication.
Fair Compensation
Competitive salaries, bonuses, and benefits – transparent and performance-based.
Impact
Your work makes organizations and critical infrastructure more secure.
Current Job Openings
Information Security Consultant (m/f/d)
Your Tasks
- Building and certifying ISMS (e.g., ISO 27001, TISAX, BSI IT-Grundschutz)
- Conducting penetration tests and red teaming
- Security audits and gap analyses
- Developing cloud security concepts (Azure, AWS, etc.)
- Consulting on regulatory requirements such as NIS2, DORA, AI Act
- Risk management and incident handling
Your Profile
- Experience in information security management (ISMS)
- IT security and compliance
- Knowledge in network security and cloud security
- Understanding of regulatory requirements (NIS2, DORA, AI Act)
- Excellent German language skills (minimum C1 level)
- Certifications (e.g., ISO 27001 Lead Auditor, CISSP, OSCP) are an advantage
GRC Engineer (m/f/d) – NIS2, DORA, CRA, ISO 27001 & ISO 42001
You turn regulation into machine-readable controls and automated GRC processes – with VamiGRC, for clients in critical infrastructure, finance and industry.
Your responsibilities
- Build and evolve integrated management systems (ISMS to ISO 27001, AIMS to ISO 42001) – from scope and Statement of Applicability to certification readiness
- Implement regulatory requirements from NIS2, DORA, the CRA and the EU AI Act, including gap analyses and remediation plans
- Model controls, cross-mappings and frameworks in VamiGRC (OSCAL) and automate evidence and workflows with AI agents
- Quantitative risk management, supplier assessments (TPRM) and preparation of internal and external audits
- Work closely with the product team: requirements from client projects flow straight into the platform
Your profile
- Several years of experience in GRC, ISMS or IT compliance, ideally in regulated industries
- In-depth knowledge of ISO 27001 and at least two of NIS2, DORA, CRA, ISO 42001 or the EU AI Act
- Technical understanding (cloud, IAM, vulnerability management) and a passion for automation, e.g. with Python, APIs or OSCAL
- Excellent German (at least C1) and good English
- A plus: ISO 27001 or ISO 42001 Lead Auditor, CISA, CISM or BSI IT-Grundschutz Practitioner
IT Security Engineer (m/f/d) – Application Security, SBOM & CRA
You bring security into everyday development: from the first commit to a CRA-ready release – with VamiAppSec and VamiDAST.
Your responsibilities
- Integrate SAST, SCA, secrets, IaC and DAST scans (including Semgrep, Trivy, Grype, Gitleaks, Checkov and VamiDAST) into our clients' CI/CD pipelines
- Triage and assess findings, run reachability analyses and advise development teams on remediation
- Generate SBOMs (CycloneDX/SPDX), monitor vulnerabilities and prepare reporting obligations under CRA Art. 14
- Security reviews and assessments along OWASP ASVS, MASVS and SAMM, complemented by threat modeling
- Evolve VamiAppSec together with the product team
Your profile
- Several years of experience in application security, DevSecOps or security-focused software development
- In-depth knowledge of the OWASP Top 10 and ASVS, secure development processes and at least one programming language (e.g. Python, Java, TypeScript or Go)
- Hands-on experience with CI/CD (GitHub Actions, GitLab CI or Azure DevOps) and container and cloud environments
- Excellent German (at least C1) and good English
- A plus: knowledge of the CRA, IEC 62443-4-1 or ISO/SAE 21434 and certifications such as OSWE, GWEB or CSSLP
IT Security Engineer (m/f/d) – Threat Modeling & Agentic AI Security
You find attack paths before attackers do – across software, cloud, OT and AI architectures, supported by VamiThreat.
Your responsibilities
- Run threat modeling workshops for software, cloud, OT and AI architectures (STRIDE, MAESTRO, MITRE ATT&CK and ATLAS)
- Analyse agentic AI systems: prompt injection, tool and MCP abuse, data exfiltration, autonomy and permission risks
- Derive prioritised action plans and security requirements, aligned with the OWASP LLM Top 10 and the EU AI Act
- Contribute to threat libraries and analysis models in VamiThreat
- Share knowledge in workshops, webinars and articles
Your profile
- Several years of experience in security architecture, threat modeling or penetration testing
- In-depth knowledge of established threat modeling methods and current attack techniques against cloud and AI systems
- Hands-on experience with LLM applications, RAG or agent frameworks (e.g. MCP or LangGraph)
- Excellent German (at least C1) and good English
- A plus: experience with IEC 62443, ISO/SAE 21434 or medical device security
IT Security Engineer (m/f/d) – Penetration Testing & Red Teaming
You think like an attacker and work like an engineer – in classic pentests, red team engagements and AI system testing, supported by VamiRedteam.
Your responsibilities
- Penetration tests of web applications, APIs, cloud environments, internal networks and Active Directory
- Red team engagements and assumed-breach scenarios, including reporting for management and engineering
- Pentests of AI applications and agents (prompt injection, jailbreaks, tool abuse), rated with CVSS and AIVSS
- Steer and validate agentic pentests with VamiRedteam – human in the loop, every finding with a proof of concept
- Evolve methodology and playbooks along the OWASP standards (WSTG, ASVS)
Your profile
- Several years of experience in penetration testing or red teaming
- In-depth knowledge of web and API security, Active Directory and common attack techniques (MITRE ATT&CK)
- Confident with tools such as Burp Suite, BloodHound, Nuclei or Metasploit and scripting in Python or PowerShell
- Excellent German (at least C1) and good English
- A plus: OSCP, OSEP, OSWE, CRTO or comparable certifications
IT Security Engineer (m/f/d) – Reverse Engineering & Malware Analysis
You look inside binaries, firmware and malware where others only see black boxes – and turn that into solid findings, supported by VamiReverse.
Your responsibilities
- Static and dynamic analysis of binaries, firmware and mobile apps (PE, ELF, APK) with Ghidra, IDA, jadx and Frida
- Malware analysis: behavioural assessment, IOC extraction and authoring of YARA and Sigma rules
- Vulnerability research in closed-source components and assessment of possible exploit paths
- Validate and evolve VamiReverse's AI-assisted analysis pipeline
- Support incident response, forensics and product security assessments (e.g. under the CRA)
Your profile
- Several years of experience in reverse engineering, malware analysis or exploit development
- In-depth knowledge of x86/x64 and ARM assembly, operating system internals (Windows, Linux, Android) and obfuscation techniques
- Solid programming skills in C/C++ and Python
- Excellent German (at least C1) and good English
- A plus: GREM, OSED or your own publications and CTF experience
IT Security Engineer (m/f/d) – Agentic AI Security & GenAI Data Protection
You make sure companies can use ChatGPT, Claude, Copilot and AI agents without giving away sensitive data – with VamiGuard.
Your responsibilities
- Evolve the detection and redaction logic for sensitive data in AI prompts (personal data, credentials, source code, trade secrets)
- Design policies and controls for the secure use of generative AI and AI agents in organisations
- Assess GenAI risks against the OWASP LLM Top 10, the EU AI Act and the GDPR, and advise on AI governance under ISO 42001
- Test against bypass attempts and extend coverage to new AI channels
- Work closely with pilot customers and the open-source community
Your profile
- Several years of experience in data loss prevention, privacy engineering or AI/ML security
- In-depth knowledge of data classification, GDPR requirements and the risks of generative and agentic AI
- Development skills in TypeScript/JavaScript (e.g. browser extensions) or Python
- Excellent German (at least C1) and good English
- A plus: experience with Microsoft Purview, named entity recognition or ISO 42001
No Matching Position?
We welcome unsolicited applications from security enthusiasts!
Shaping the Future of IT Security Together
Have questions about a position or want to introduce yourself? Write to us – we look forward to hearing from you.