Yekta IT GmbH
11 hours ago
OT-Security Consultant / Penetration Tester (m/f/d)
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- Yekta IT GmbH
- Location
- Dortmund Germany
- Posted
- 11 hours ago
Job description
Have you already tested in control rooms, substations, or production halls and know why certain things shouldn't be touched there? Do you want to recreate attack paths on real devices before they go into a production environment? Then you're in the right place with us.
Yekta IT is a family-owned company for manufacturer-independent IT and OT security consulting based in Dortmund. We test and harden critical infrastructures, from small and medium-sized businesses to corporations.
You will work predominantly remotely from Germany. You will be on-site for customer deployments and when you work in our OT lab. Additionally, you'll have flexible working hours, access to further training and certifications.
Tasks
- You conduct penetration tests and assessments in OT and ICS environments: SCADA, RTUs, IEDs, protective relays, HMIs, Engineering Workstations, PLCs (including Siemens S7-300/1200/1500) and IT/OT transitions
- You analyze industrial protocols: IEC 61850 (GOOSE, MMS, SV), IEC 60870-5-104, Modbus TCP, S7comm and S7commPlus, PROFINET
- You recreate and validate attack paths in our OT lab before they go into a production environment
- You coordinate scope, safety, and test windows directly with the operator
- You document findings with reproduction steps, assess risks (CVSS, Mapping to IEC 62443-3-3), and derive hardening measures that the operator can also implement
- You hand over to the operator side: results discussion, detection ideas for SOC and SIEM, knowledge transfer
- You participate in a research project on OT security
- You contribute to our testing methodology and tool development, and if you wish, to publications
Qualification
- You have several years of experience in penetration testing, with a solid portion in OT or ICS environments
- You have practically worked with at least one of the industrial protocols mentioned above, beyond just using tools
- You are familiar with the operational reality in OT: why availability takes precedence over confidentiality, how to work within maintenance windows, when not to touch something
- You write reports that can be read equally by a plant manager and a CISO
- You have very good German language skills (at least C1) and fluent English
- You work in a structured and analytical manner and take responsibility for your own work
- You are motivated, reliable, and show initiative
Optional:
- Certifications in OT/ICS, ideally OT background
- Experience in the energy sector or railway industry
- Own tools, research, Responsible Disclosures, or publications
- Detection Engineering: SIEM rules, anomaly detection on industrial protocols
Benefits
- Your own OT lab with physical testbeds. YekCity for energy, YekTrain for rail, YekCar for automotive, plus a Siemens S7 lab, industrial switches, SCADA workstations, and HMIs. Real devices, not just virtualized environments.
- You have the opportunity to participate in exciting research projects and are given the space for it
- With us, you can truly be a techie. You don't have to do sales here.
- You can work predominantly remotely from all over Germany, with flexible working hours.
- You get access to various learning portals, certifications, and can attend tech events.
- An agile, positive corporate culture with flat hierarchies awaits you
- You have great freedom to contribute your own ideas
Have we piqued your interest? But you're not sure if you meet all the criteria? Then apply anyway and together we'll find a good solution.
Find Jobs in Germany on Arbeitnow
Required skills
- remote work
- automotive
- further training
- agile
- certifications
- risk assessment
- flexible working hours
- energy sector
- penetration testing
- scada
- siem
- publications
- plcs
- cvss
- profinet
- anomaly detection
- siemens s7
- soc
- mms
- modbus tcp
- railway industry
- iec 61850
- rtus
- ics
- flat hierarchies
- knowledge transfer
- research project
- hardening measures
- hmis
- iec 60870-5-104
- sv
- detection engineering
- tool development
- protective relays
- ot security
- industrial protocols
- testing methodology
- attack paths
- goose
- ieds
- engineering workstations
- it/ot transition
- s7comm
- s7commplus
- ot lab
- iec 62443-3-3
Interested in this position?
Create your free account and tailor your CV to match this job.