Offensive Security Engineer
ExternalPrepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
About the role
We simplify wealth creation. Founded in 2014 in Vienna, Austria by Eric Demuth, Paul Klanschek and Christian Trummer, we're here to help people trust themselves enough to build their financial freedom - for now and the future. Our user-friendly, trade-everything platform empowers both first-time investors and seasoned experts to invest in the cryptocurrencies, crypto indices, stocks*, precious metals and commodities* they want - with any sized budget, 24/7. Our global team works across different cultures and time zones, bringing our products to more than 6 million customers, making us one of Europe's safest and most secure platforms that powers modern investing. Headquartered in Austria but operating across Europe, our products are built by fast-moving, talented, "roll-up-your-sleeves-and-make-it-happen" kind of people. It's these diverse perspectives and innovative minds operating as ONE TEAM that keep Bitpanda at the cutting edge of our industry. So if you're someone who thinks big, moves fast and wants to make an impact right from day one, then get ready to join our industry-changing team. Let's go! Your Mission As an Offensive Security Engineer, you'll act as an in-house attacker; finding and proving the risks that matter before anyone else can. You'll play a key role in helping us build secure-by-default products by bringing an offensive mindset into everyday engineering decisions. Working closely with engineers, product managers, and DevOps, you'll uncover real-world attack paths, challenge assumptions, and help teams fix issues in a practical, scalable way. If you enjoy getting hands-on, digging deep into systems, and turning complex vulnerabilities into clear action, this is where you'll thrive.
Responsibilities
- Perform in-depth penetration tests across web apps, APIs, and infrastructure-going beyond automated tools to uncover meaningful flaws
- Develop clear, impactful PoCs that demonstrate real risk and help teams prioritize fixes effectively
- Collaborate closely with engineers to guide remediation and validate fixes through re-testing
- Contribute to threat modeling and design reviews, helping identify security gaps early in the SDLC
- Build and refine scripts, tools, and testing approaches to improve coverage and efficiency
Requirements
- 3-5+ years of hands-on experience in offensive security, penetration testing, or product security
- Strong understanding of common vulnerabilities (OWASP Top 10, SANS 25) and how they manifest in real systems
- Practical, hands-on mindset; comfortable testing, exploiting, and explaining vulnerabilities end-to-end
- Able to clearly communicate technical findings and recommended fixes to engineering teams
- Curious and persistent; you enjoy digging deeper, connecting dots, and understanding how things break
Benefits
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at bitpanda? Share your experience