ATIX AG
29 minutes ago
Security & QA Engineer (m/f/d)
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- ATIX AG
- Location
- Garching Germany
- Posted
- 29 minutes ago
Job description
Do you want to find security vulnerabilities, improve the quality of complex open-source software, and build automated test environments for it? Then support us with security testing, quality assurance, and test automation for our Linux-based software solutions.
Tasks
- Planning Planning and execution of white-box and grey-box penetration tests
- Security analysis of Linux systems, web applications, APIs, network services, and configurations
- Identification, assessment, and documentation of vulnerabilities and attack scenarios
- Execution and further development of vulnerability scanning, dependency scanning, static application security testing, dynamic application security testing, and fuzzing
- Derivation of concrete recommendations for action and verification of implemented bug fixes
- Execution of manual, exploratory, and automated functional, integration, and regression tests
- Development and maintenance of test strategies, test cases, and automated security and QA tests
- Setup and maintenance of reproducible test infrastructures with Ansible and OpenTofu
- Integration of tests and security checks into GitLab CI/CD pipelines
- Close collaboration with software development
Qualification
- University degree, vocational training, or comparable practical experience in computer science, IT security, or software development
- Experience in penetration testing, security testing, or technical vulnerability analysis
- Experience with tools and methods such as vulnerability scanning, dependency scanning, static application security testing, dynamic application security testing, or fuzzing
- Very good knowledge of working with Linux systems
- Knowledge in the areas of web, API, network, and server security
- Experience with test automation and quality assurance
- Experience with container technologies such as Podman or Docker
- Knowledge of Python and shell scripting
- Experience with Ansible as well as OpenTofu or Terraform
- Confident use of Git, GitLab, and CI/CD pipelines
- Analytical, structured, and independent way of working
- Good German and English skills
Benefits
Here's what you can look forward to
Onboarding: thorough and individual induction
- Further development: varied tasks as well as internal and external training and further education offers
- Work-life balance: flexible working hours and possibility of home office
- Employee offers: fitness, Jobrad (company bicycle scheme), fruit, contribution to pension provision, free parking and proximity to the subway
- Company culture: likeable, open, and motivated team with flat hierarchies and short decision-making paths, where your own ideas and co-creation are desired
- Awarded employer "Great Place to Work"
Advantageous
We are particularly pleased if you have already worked with security tools such as Burp Suite, OWASP ZAP, Nmap, Trivy, or Grype. Additional experience with Kubernetes, virtualization, or cloud platforms as well as Puppet is also welcome. Knowledge of Ruby on Rails, React, Foreman, or Katello will help you get started, but is not a prerequisite. We also welcome contributions to open-source projects.
Required skills
- docker
- gitlab
- test automation
- ci/cd
- react
- python
- kubernetes
- git
- apis
- terraform
- linux
- ansible
- open source
- cloud platforms
- shell scripting
- web applications
- it security
- ruby on rails
- penetration testing
- foreman
- qa
- container technologies
- test cases
- podman
- burp suite
- virtualization
- puppet
- owasp zap
- security testing
- white-box testing
- fuzzing
- vulnerability scanning
- opentofu
- trivy
- network services
- nmap
- dependency scanning
- test strategies
- static application security testing
- dynamic application security testing
- grype
- grey-box testing
- katello
Interested in this position?
Create your free account and tailor your CV to match this job.