DE|EN
Careers · Security & Engineering

Technology that matters. Work with impact.

Work on real security and engineering projects. We are looking for people who work carefully, take ownership and communicate technical outcomes clearly.

Kiel & RemoteTechnical focusClear process
Security and engineering team collaborating on technical work
Codex OperationSecurity · Engineering · Training
5 roles
How we work

What matters in our collaboration

No buzzword bingo: we work systematically, document clearly and communicate technical risk in a way people can act on.

01

Technical quality

Reproducible work, reliable outcomes and a strong attention to detail.

02

Ownership

You get room to move topics forward independently and prepare decisions.

03

Clear communication

Findings, code and training must not only be correct — they also need to be understandable.

Open roles

Five roles across our services

These roles map directly to the services Codex Operation delivers to clients.

01

Penetration Tester – Web & API

You assess web applications and APIs manually, think in realistic attack paths and translate findings into clear technical remediation.

Kiel & RemoteSecurityStart by agreement

Your responsibilities

  • Plan and perform web, API and SaaS penetration tests
  • Assess authentication, authorization and business logic
  • Document and prioritize findings reproducibly
  • Support technical readouts and retesting

What you bring

  • Hands-on experience with HTTP, APIs, web security and common testing tools
  • Understanding of OWASP-relevant vulnerabilities and attack chains
  • Clear technical documentation and communication
  • Responsible handling of client systems

Apply directly with your resume or documents – confidential and straightforward.

02

Pentester – Active Directory & Infrastructure

You assess internal environments, identities and Windows infrastructure for realistic privilege-escalation and lateral-movement paths.

Kiel & RemoteAD / NetworkStart by agreement

Your responsibilities

  • Perform Active Directory and internal infrastructure assessments
  • Analyze misconfigurations, trusts and privilege paths
  • Evidence and prioritize attack paths
  • Support hardening recommendations and retesting

What you bring

  • Strong understanding of Windows, AD, Kerberos, NTLM and networking
  • Hands-on recon, enumeration and controlled exploitation experience
  • Comfortable with PowerShell and Linux tooling
  • Structured communication and high attention to detail

Apply directly with your resume or documents – confidential and straightforward.

03

Mobile Security Engineer / Pentester

You analyze Android and iOS applications, API integrations, local storage and mobile attack paths from an attacker perspective.

RemoteAndroid / iOSSecurity

Your responsibilities

  • Perform static and dynamic Android/iOS analysis
  • Assess storage, transport, authentication and API usage
  • Document mobile findings reproducibly
  • Support engineering teams with secure remediation

What you bring

  • Hands-on mobile security testing and reverse engineering experience
  • Understanding of Android/iOS security models and app lifecycle
  • Experience with proxying, instrumentation and analysis tooling
  • Interest in clean secure engineering

Apply directly with your resume or documents – confidential and straightforward.

04

Secure Software Engineer

You build web, backend or automation solutions with a strong focus on maintainable architecture, testing and security by design.

Kiel & RemoteEngineeringWeb / Backend

Your responsibilities

  • Implement web and backend functionality cleanly
  • Build APIs, data models and integrations
  • Integrate code review, tests and security controls
  • Support CI/CD, documentation and technical handover

What you bring

  • Strong skills in at least one modern backend/web stack
  • Understanding of APIs, databases, Git and automated tests
  • Security fundamentals such as input validation, AuthN/AuthZ and secrets handling
  • Clean, understandable and reviewable code

Apply directly with your resume or documents – confidential and straightforward.

05

Security Trainer & Secure-Coding Instructor

You make security practical and understandable — from awareness and secure coding to technical hands-on workshops.

Remote / On-siteTrainingSecurity

Your responsibilities

  • Prepare and deliver technical training and workshops
  • Develop hands-on labs, demos and exercises
  • Adapt content to audience, tech stack and learning objectives
  • Support participants during questions and practical exercises

What you bring

  • Very good technical security fundamentals
  • Ability to explain complex topics clearly
  • Confident communication with technical and non-technical audiences
  • Hands-on background in secure coding, penetration testing or security operations

Apply directly with your resume or documents – confidential and straightforward.

Send application

Required fields are marked with *.

Accepted: PDF, DOC, DOCX or ZIP · maximum 6 MB. The file is not extracted or executed and is not permanently stored by the application.
Applicant privacy

Your information and application documents are processed solely for the recruitment process. Details about the legal basis, recipients and deletion are provided in the dedicated applicant privacy notice.

Open applicant privacy notice →
The application is sent directly to info@codex-operations.com.
FAQ

Frequently asked application questions

Can I work fully remotely?

Many tasks can be delivered remotely. Whether on-site appointments in Kiel or at a client location are useful depends on the role and project and is agreed transparently.

What level of experience is required?

What matters most is demonstrable hands-on capability, clear technical thinking and the ability to document results in a reproducible way. Certifications can help, but they are not the only criterion.

What does the application process look like?

After your application, we review the information provided. If the profile matches the role, we arrange a short introductory call followed, depending on the position, by a technical discussion or a small practical task.

Which files can I upload?

PDF, DOC, DOCX and ZIP files up to 6 MB are accepted. The application does not extract or execute the file and does not move it into permanent website storage. PHP only buffers the upload temporarily for the request before it is sent to info@codex-operations.com as an email attachment.

No exact match?

Choose “Open application” in the form and briefly explain how you could strengthen Codex Operation technically.