Your role at OTOKO®
You help development teams identify security issues earlier and resolve them effectively. This includes modern SaaS and AI applications as well as established software. You combine architecture and code analysis with pragmatic improvements to the development process.
Security in code and the development workflow
A scanner finding must be checked against the reachable code path and the required level of protection. You review data flows and server-side authorisation and support concrete fixes. Dependency and container findings are prioritised according to their deployment context. AI applications also introduce prompt injection, tool permissions and data sharing. Appropriate regression tests prevent fixed defects from returning in later releases.
Your responsibilities
- Create threat models for applications, APIs and AI workflows and prioritise relevant attack surfaces.
- Conduct code and architecture reviews and implement technical security measures with development teams.
- Integrate SAST, DAST and dependency checks effectively into CI/CD and assess findings according to their actual relevance.
- Support developers with secure authentication, authorisation checks, secrets management and vulnerability remediation.
- Review code paths with tests for authorisation, inputs and data access.
- Prioritise findings by reachability and impact and support developers through remediation.
What you bring
What matters is demonstrable experience that is relevant to the role. It may come from appropriate vocational training, a degree, professional practice or a well-founded career change. We will align the specific level of responsibility with your knowledge and experience.
- Solid software development experience and an understanding of common application vulnerabilities.
- Ability to trace security findings in code and propose actionable improvements.
- Understanding of development processes, APIs and testing security-relevant behaviour.
Additional strengths
This knowledge is helpful, but you do not need to have all of it at once. In your application, describe where you have already gained practical experience and which areas you would like to explore in greater depth.
- Experience with secure SDLC, security champions or securing AI applications.
- Knowledge of supply-chain security, container security or cloud identity.
What matters in this role
You make secure development practical in day-to-day work. Success lies in demonstrably reduced risks and usable standards, not in a growing number of unprocessed scanner alerts.
Your workplace: Cologne or remote
This role can be based in Cologne or performed remotely. We will agree the specific form of collaboration, project requirements and any necessary customer appointments before you start.
Your employment
This role is offered as permanent employment on a full-time or part-time basis. We will agree the responsibilities, working hours, start date and compensation to suit the role and your level of experience.
Your application
Show us in your application which experience or interests you bring to this role. A CV and relevant project examples, certificates or work samples will help us assess your professional background. Please do not send confidential customer data, credentials or protected source code.
Tell us your preferred working model, your possible start date and whether you would like to work full-time or part-time.
If you have questions about the role, contact our recruitment team at hr@otoko.com. Inclusion in the applicant pool is voluntary and takes place only with separate consent; it is not a prerequisite for reviewing your application.
