Trade Republic logo

Senior Security Engineer - Purple Teaming

Trade Republic

Berlin, GermanyFull-timeNo compensation foundPosted 3mo agoVerified open 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Berlin, Germany
Schedule
Full-time
Work Authorization
Not specified

Job overview

Trade Republic is hiring a Senior Security Engineer - Purple Teaming. As a Senior Security Engineer in Purple Teaming, you will plan and execute purple team exercises aligned to real-world threat actors to protect Trade Republic's critical systems and customer data. This role involves designing attack scenarios, coordinating with business and engineering teams, and assessing existing security controls. You will also develop and tune SIEM detections, validate alert quality, and support incident response playbooks.

Key focus areas include Design attack scenarios covering initial access, persistence, lateral movement, privilege escalation, command-and-control, and exfiltration, Coordinate with business and engineering teams to gather requirements, understand operational constraints, and ensure testing activities align with business risk, and Assess existing security controls to ensure they aren't just "active," but actually effective.

Successful candidates bring 5+ Years Security Engineering Experience, 3+ Years Purple/Red/Blue Teaming Experience, and Regulated Environment Experience. Important skills include Purple Teaming, Attack Scenarios Design, Security Controls Assessment, Internal Networks Assessment, Applications Assessment, and Cloud Infrastructure Assessment. Preferred (not required): Red Teaming, Blue Teaming, Google SecOps, and SentinelOne.

Skills & qualifications

RequiredNice to have

Skills

Purple TeamingAttack Scenarios DesignSecurity Controls AssessmentInternal Networks AssessmentApplications AssessmentCloud Infrastructure AssessmentSIEM Detections DevelopmentAnalytics Rules DevelopmentAlerts DevelopmentAlert Quality ValidationFalse Positives ReductionSignal-to-Noise Ratio ImprovementDetections Coverage ValidationDetection Gaps IdentificationIncident Response Playbooks EnhancementEscalation Paths EnhancementResponse Automation EnhancementHypothesis-Driven Threat HuntsAttacker Behavior UnderstandingCloud SecurityAWSKubernetes SecuritymacOS SecuritySIEM SolutionsEndpoint Detection & ResponsePythonGoScripting LanguageRed TeamingBlue TeamingGoogle SecOpsSentinelOneCrowdStrikeMulti-Cloud ExperienceGCPAzure

Qualifications

5+ Years as a Security Engineer3+ Years Specializing in Purple/Red/Blue TeamingExperience Running or Leading Purple Team Exercises in Enterprise EnvironmentsExperience Operating in Regulated or Compliance-Driven EnvironmentsMaRiskBAITGDPR

Full job description

THE BEST WORK OF YOUR CAREER Trade Republic is the largest savings platform in Europe - we operate in 18 countries, serving +10 million customers who trusted us with over 150B in assets. But we’re striving for more.

We have a bold mission to empower everyone to build wealth with easy, safe, and free access to financial systems. You will have the opportunity to grow your career by collaborating with a team of outstanding talents and state-of-the-art technology to build a lasting, positive future for millions.

WHAT YOU'LL BE DOING As a Senior Security Engineer in Purple Teaming, you'll plan and execute purple team exercises aligned to real‑world threat actors to protect Trade Republic's critical systems and customer data. Your responsibilities include:

  • Design attack scenarios covering initial access, persistence, lateral movement, privilege escalation, command‑and‑control, and exfiltration.
  • Coordinate with business and engineering teams to gather requirements, understand operational constraints, and ensure testing activities align with business risk.
  • Assess existing security controls to ensure they aren't just "active," but actually effective.
  • Conduct deep-dive assessments of internal networks, applications, and cloud infrastructure.
  • Develop and tune SIEM detections, analytics rules, and alerts based on attack simulations and real incidents together with the Security Operations team.
  • Validate alert quality, reduce false positives, and improve signal‑to‑noise ratio.
  • Validate coverage of detections against known TTPs and identify detection gaps.
  • Support and enhance incident response playbooks, escalation paths, and response automation.
  • Conduct hypothesis‑driven threat hunts based on attacker tradecraft and threat intelligence.

WHAT WE'RE LOOKING FOR Core Experience

  • 5+ years as a Security Engineer with 3+ years specializing in Purple/Red/Blue Teaming.
  • Experience running or leading purple team exercises in enterprise environments
  • Strong understanding of real‑world attacker behavior, not just theoretical frameworks
  • Experience operating in regulated or compliance‑driven environments (MaRisk, BAIT, GDPR)

Technical Experience

  • Strong understanding of cloud security (AWS) and Kubernetes security
  • Good understanding of macOS security
  • Experience with SIEM solutions, preferably Google SecOps
  • Experience with Endpoint Detection & Response (EDR) tools such as SentinelOne or CrowdStrike
  • Proficiency in Python, Go or other scripting language
  • Multi-cloud experience (GCP, Azure) is advantageous

WHY YOU SHOULD APPLY NOW

Our culture rewards ownership, excellence, and high energy. We care deeply about outcomes and hold each other accountable - we’re here to win and fix one of the largest challenges Europeans face - closing the pension gap and democratizing wealth. If this gets you fired up, reach out!

We believe it’s our team’s varied identities and backgrounds that make us sharper and stronger. We’re committed to creating an environment where everyone feels respected and has equal opportunity to thrive in their careers. For any questions on DEI during the interview process, reach out to your recruitment partner.

We believe it’s our team’s varied identities and backgrounds that make us sharper and stronger. We’re committed to creating an environment where everyone feels respected and has equal opportunity to thrive in their careers. For any questions on DEI during the interview process, reach out to your recruitment partner.

You've read the whole posting — now see how you match it.