Careers at turingpoint
Shape the future of cybersecurity with us. We are looking for people who want to combine technology, security, and innovation.
Who we are
Cybersecurity from Hamburg
turingpoint is a BSI-certified boutique consultancy specializing in penetration testing. We support organizations worldwide in implementing cyber security concepts — from pentests and red teaming to ISMS and incident response.
We are a growing team of security researchers, consultants, and developers based in Hamburg. With us, you work on real security problems, not theoretical scenarios.
Why turingpoint
What to Expect
Real Security Work
Penetration testing, source code reviews, and red team engagements for renowned national and international companies — you work directly on our clients' security.
Technical Depth
We invest in training, conference attendance, and certifications. From OSCP to cloud security — we support your professional development.
Flexible Working
Remote or at our office in Hamburg. Flexible hours, short decision paths, and a team that focuses on results.
Open Positions
Current Openings
As a senior penetration tester, you work in a dynamic environment and contribute to ensuring high security standards and data protection for our international clients.
Tasks
- Penetration testing and security source code reviews for renowned national and international companies
- IT security consulting for our clients
- Penetration testing for web applications, infrastructure, and mobile devices
- Social engineering, physical pentests, and red team engagements
- Contributing to the development of security software for automated security scans
Requirements
- Completed degree in computer science or a comparable qualification
- Strong willingness to acquire and apply new knowledge
- Good English skills for international communication
- A valid OSCP certification (Offensive Security Certified Professional) is required
- At least 3 years of professional experience in penetration testing or advanced OSCP certifications (OSEP, OSED, OSWE)
- European Union citizen
Benefits
- Remote or at our office in Hamburg
- Flexible working hours and mobile work
- Regular team events
- Constructive feedback for personal and collective growth
- Short decision paths
As a Senior Red Team Operator, you simulate real-world attackers and push our clients' defenses to their limits. You plan and execute complex, goal-oriented attack campaigns across technical, physical, and human attack vectors.
Tasks
- Planning and executing red team operations and adversary simulations
- Developing and adapting custom tooling, implants, and C2 infrastructure
- Initial access, lateral movement, privilege escalation, and persistence in production environments
- Bypassing EDR, SIEM, and detection mechanisms
- Close collaboration with blue teams during purple team engagements
- Detailed documentation of attack chains and remediation recommendations
Requirements
- Several years of experience in offensive security, with demonstrable red team engagements
- Deep understanding of Windows and Active Directory environments
- Experience with C2 frameworks (e.g. Cobalt Strike, Mythic) and malware development
- A certification such as OSEP, CRTO, or equivalent
- Knowledge of evasion techniques and OPSEC
- Excellent German and English skills
- European Union citizen
Benefits
- Remote or at our office in Hamburg
- Flexible working hours and mobile work
- Budget for training, certifications, and conferences
- Regular team events
- Short decision paths
As a Research Associate, you dedicate yourself to security research: you analyze software, discover new vulnerabilities, and help advance our tools and methods. Your findings feed directly into our client projects and publications.
Tasks
- Vulnerability research and reverse engineering of applications and libraries
- Developing proof-of-concept exploits and writing security advisories
- Coordinated disclosure of discovered vulnerabilities
- Contributing to the development of internal security automation and scanning tools
- Preparing research results for blog articles and conference talks
Requirements
- Solid programming skills (e.g. Python, C/C++, Rust, or Go)
- Experience with vulnerability research, fuzzing, or reverse engineering
- Understanding of modern attack and defense techniques
- An independent, curious way of working and enjoyment of deep technical work
- Good English skills for publications and international communication
- A completed degree in computer science is a plus, but not required
Benefits
- Remote or at our office in Hamburg
- Time and budget for your own research and publications
- Support for conference contributions and certifications
- Regular team events
- Short decision paths
As a Senior ISMS Consultant, you guide our clients through building, operating, and certifying information security management systems. You translate regulatory requirements into practical security concepts.
Tasks
- Consulting on building and operating ISMS according to ISO 27001 and BSI IT-Grundschutz
- Preparing for and supporting certification audits
- Conducting risk analyses and creating security policies
- Supporting the implementation of regulatory requirements (e.g. NIS2, DORA)
- Delivering awareness training and workshops
- Close collaboration with our technical teams
Requirements
- Several years of experience in information security consulting
- Solid knowledge of ISO 27001 and/or BSI IT-Grundschutz
- Experience preparing for and supporting audits
- A certification such as ISO 27001 Lead Auditor/Implementer is a plus
- Strong communication and consulting skills
- Excellent German and English skills
Benefits
- Remote or at our office in Hamburg
- Flexible working hours and mobile work
- Budget for training and certifications
- Regular team events
- Short decision paths
Ready for the Next Step?
Apply now for our open position or send us a speculative application at [email protected] — we look forward to hearing from you.
