Senior Offensive Security Engineer
ExternalPrepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
About the role
We simplify wealth creation. Founded in 2014 in Vienna, Austria by Eric Demuth, Paul Klanschek and Christian Trummer, we're here to help people trust themselves enough to build their financial freedom - for now and the future. Our user-friendly, trade-everything platform empowers both first-time investors and seasoned experts to invest in the cryptocurrencies, crypto indices, stocks*, precious metals and commodities* they want - with any sized budget, 24/7. Our global team works across different cultures and time zones, bringing our products to more than 6 million customers, making us one of Europe's safest and most secure platforms that powers modern investing. Headquartered in Austria but operating across Europe, our products are built by fast-moving, talented, "roll-up-your-sleeves-and-make-it-happen" kind of people. It's these diverse perspectives and innovative minds operating as ONE TEAM that keep Bitpanda at the cutting edge of our industry. So if you're someone who thinks big, moves fast and wants to make an impact right from day one, then get ready to join our industry-changing team. Let's go! Your Mission You operate as a trusted adversary within our systems identifying, exploiting, and helping eliminate the risks that matter most. You don't just find vulnerabilities; you shape how we think about security at a product and platform level. You'll embed offensive thinking across the SDLC, partnering with engineering, product, and DevOps to challenge designs, raise the bar, and ensure we're secure by default, not by accident. If you're the kind of person who sees an attack path where others see "low risk," and you know how to turn that into real change, you'll feel right at home.
Responsibilities
- Lead sophisticated, end-to-end penetration tests across complex systems; uncovering deep, chained vulnerabilities others miss
- Design and demonstrate impactful exploit scenarios that drive prioritisation at both engineering and leadership levels
- Own offensive security engagements from scoping through remediation validation, acting as the technical authority
- Influence architecture through threat modeling and design review; shifting security left and preventing classes of vulnerabilities
- Build and evolve offensive tooling, methodologies, and playbooks to scale security testing across teams
Requirements
- 5+ years in offensive security with a proven track record of finding high-impact, non-trivial vulnerabilities in real-world systems
- Strong depth in application and product security, with the ability to think across layers (app, API, infra, auth, logic)
- Recognised for your hands-on expertise; whether through certifications (OSCP, OSWE, GPEN) or demonstrated offensive work
- Able to influence without authority; translating complex attack paths into clear, actionable risk for diverse stakeholders
- Naturally curious and adversarial; you think in attack chains, not isolated bugs, and push until you find what really matters
Benefits
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at bitpanda? Share your experience