Join SRLabs as a Security Engineer to help clients ship software that stands up to attackers. We're hiring at the junior to mid-level, so whether you're early in your security career or have a couple of years of hands-on experience, we are looking for an ethical hacker at heart who thinks like an attacker.
🏢 About SRLabs
SRLabs is home to knowledge leaders in the areas of telco security, IoT hardware hacking, Blockchain, AI security, and software security more broadly. We focus on knowledge sharing and continuous learning – achieved through our research combined with the selection of interesting client projects, ranging from enterprise software to Web3 and AI-powered systems, that position us at the forefront of cutting-edge technologies. Our research regularly reaches a global audience through conference talks and publications, and widely used open-source tools.
🎯 The Role
As a Security Engineer at SRLabs, you'll build and improve the tooling behind our software assurance work, run attacker-mindset audits across enterprise, Web3, and AI-powered systems, and work directly with client teams to strengthen their SDLC. If you have a passion for security tooling, code assurance, AI security, and hands-on consulting, we want to hear from you!
✅ Key Responsibilities
Tooling: Build and maintain tooling that powers our security reviews, including our in-house fuzzing framework and static/dynamic analysis pipelines.
Code audits: Conduct attacker-mindset code audits across enterprise and Web3 systems, including blockchain runtimes and smart contracts, using and extending our fuzzing framework.
AI & agentic security: Assess AI/LLM-powered applications and agentic systems for exploitable weaknesses (e.g. prompt injection, insecure tool use, data leakage) and explore how AI can be used to augment our own audits and tooling.
Reporting: Produce high-quality technical reports and presentations.
Client advisory: Advise clients on SDLC improvements, verify remediations, and help track risk-reduction KPIs.
Remediation: Work closely with client developers of the client project team to report and remediate the discovered issues.
Community & training: Participate in hacking exercises, contribute to our Security Ambassador program, and conduct developer trainings.
📌 Required Qualifications
Security fundamentals: Understanding of software security fundamentals, secure architecture, and threat modeling across enterprise and Web3/blockchain systems.
AI/LLM security: Curiosity about AI/LLM security risks (prompt injection, model or data exfiltration, agentic tool misuse) or hands-on experience probing AI systems.
Vulnerability research: Track record of finding and exploiting real-world vulnerabilities (CTFs, bug bounties, pentests, or independent research): this role is for hands-on ethical hackers, security engineers.
Tooling & automation: Strong ability to automate and build tools for security review (static/dynamic analysis, fuzzing, CI integrations).
Communication: Excellent communication skills in English and German is a plus.
Languages: Familiarity with RUST, C/C++, GO and solidity are a plus.
Please let Security Research Labs know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.