OPEN TO WORK ⁄⁄ PENETRATION TESTER ⁄⁄ REMOTE EU ⁄⁄ 20+ VERIFIED FINDINGS ⁄⁄ SECURITY+ CERTIFIED ⁄⁄ OT/ICS BACKGROUND ⁄⁄ OPEN TO WORK ⁄⁄ PENETRATION TESTER ⁄⁄ REMOTE EU ⁄⁄ 20+ VERIFIED FINDINGS ⁄⁄ SECURITY+ CERTIFIED ⁄⁄ OT/ICS BACKGROUND ⁄⁄ 
PDF ↓PDF ↓
Open to Work · Junior / Trainee · Remote EUOpen to Work · Junior / Trainee · Remote EU

JOSEF BASNER

Penetration Tester · Security ResearcherPenetration Tester · Security Researcher

01

ProfilProfile

~/whoami.sh

josef@sec:~$ cat profile.txt

Offensive-Security-Spezialist mit 5+ Jahren Praxis in Bug Bounty, Web-/API-Pentesting und Active-Directory-Angriffen. Seit 2020 in privaten / invite-only Programmen auf HackerOne und Bugcrowd — 20+ verifizierte Schwachstellen (RCE, SQLi, XSS, IDOR, Auth-Bypass), Schwerpunkt Business-Logic und Exploit-Chains. CompTIA Security+ (SY0-701) zertifiziert. Eigenes Security-Lab, dokumentierte Methodik, laufender Zertifizierungspfad (PenTest+, CEH v13, OSCP für Q4 2026). Zusätzlich ausgebildeter Mechatroniker (Siemens S7, SCADA) — direkter Zugang zu OT/ICS-Security.

Offensive-security specialist with 5+ years of hands-on experience in bug bounty, web/API penetration testing and Active Directory attacks. Active since 2020 in private / invite-only programs on HackerOne and Bugcrowd — 20+ verified vulnerabilities (RCE, SQLi, XSS, IDOR, auth bypass), focused on business-logic flaws and exploit chains. CompTIA Security+ (SY0-701) certified. Own security lab, documented methodology, certification path in progress (PenTest+, CEH v13, OSCP planned Q4 2026). Also a trained mechatronics engineer (Siemens S7, SCADA) — a direct route into OT/ICS security.

josef@sec:~$ _

02

HighlightsHighlights

0+
Verifizierte Findings · privat/NDAVerified findings · private/NDA
0+
Jahre offensive PraxisYears offensive practice
Sec+
CompTIA · SY0-701CompTIA · SY0-701
OT/ICS
Siemens S7 · SCADASiemens S7 · SCADA
03

Technische SchwerpunkteTechnical Skills

Offensive SecurityOffensive Security

Penetration TestingWeb & API TestingBug BountyRecon & EnumerationPrivilege EscalationAD AttacksLateral MovementPost-Exploitation

Tools

Burp Suite ProMetasploitNmapBloodHoundCrackMapExecImpacketffufsqlmapWiresharkHydraNessus

Scripting

PythonBashPowerShellJavaScript

OT / ICS

Siemens S7 (PLC)SCADAIndustriesteuerungenIndustrial control systemsFeldbusseFieldbusesIT/OT

NetzwerkeNetworking

TCP/IPDNSDHCPSubnettingRoutingFirewalls

SystemeSystems

Kali LinuxParrot OSWindows ServerActive DirectoryDocker
04

Security-ErfahrungSecurity Experience

seit 2020since 2020

Bug Bounty ResearcherBug Bounty Researcher

HackerOne · Bugcrowd · privat / invite-onlyprivate / invite-only
  • 20+ bestätigte Schwachstellen: RCE, SQL-Injection, Stored/Reflected XSS, IDOR, Auth-Bypass, Business-Logic-Flaws
  • 20+ verified vulnerabilities: RCE, SQL injection, stored/reflected XSS, IDOR, auth bypass, business-logic flaws
  • Schwerpunkt Web- & API-Schwachstellen, Recon-Automatisierung, Token-Analyse, Exploit-Chains
  • Focus on web & API vulnerabilities, recon automation, token analysis, exploit chains
  • Ziele: ████████ CLASSIFIED ████ — vollständige NDA- & Responsible-Disclosure-Einhaltung, reproduzierbare PoC-Reports
  • Targets: ████████ CLASSIFIED ████ — full NDA & responsible-disclosure compliance, reproducible PoC reports
laufendongoing

HackTheBox · Eigenes Security-LabOwn Security Lab

Recon → Enumerate → Exploit → Escalate → Report
  • Öffentliche deutschsprachige Writeups für retired Machines · github.com/JBMTP07/HTB-Writeups
  • Public write-ups of full attack chains for retired machines · github.com/JBMTP07/HTB-Writeups
  • Isoliertes Testlabor: Raspberry Pi, Metasploitable, Vulnerable VMs, eigene AD-Domäne
  • Isolated test lab: Raspberry Pi, Metasploitable, vulnerable VMs, own AD domain
  • Veröffentlichte Methodik-Sammlung (Linux PrivEsc, AD-Angriffe, Burp-Workflow) · github.com/JBMTP07/Study-Notes
  • Published methodology notes (Linux PrivEsc, AD attacks, Burp workflow) · github.com/JBMTP07/Study-Notes
seit 2024since 2024

Gastredner — KI & CybersecurityGuest Speaker — AI & Cybersecurity

Ehrenamtlich · 8 SchulenVolunteer · 8 schools
  • Vorträge zu LLMs, KI-Sicherheitsrisiken, Phishing und Cybersecurity-Grundlagen für Schüler:innen & Lehrkräfte
  • Talks on LLMs, AI security risks, phishing and cybersecurity fundamentals for students & teachers
05

ZertifizierungenCertifications

Kurse abgeschlossen über New Horizons (zertifizierter Bildungsträger). Security+ bestanden — weitere Prüfungen folgen 2026.Courses completed via New Horizons (accredited training provider). Security+ passed — further exams follow in 2026.

  1. BESTANDENPASSED

    CompTIA Security+ SY0-701

    05/2026
  2. IN PRÜFUNGIN PROGRESS

    CompTIA PenTest+

    2026
  3. IN PRÜFUNGIN PROGRESS

    EC-Council CEH v13

    2026
  4. IN PRÜFUNGIN PROGRESS

    CompTIA Network+ / Linux+

    2026
  5. GEPLANTPLANNED

    OffSec OSCP

    Q4 2026
06

WerdegangWork Experience

seit 01/2025since 01/2025

SelbstständigSelf-employed

Freiberuflich — parallel zur Cybersecurity-Weiterbildung & aktivem Bug BountyFreelance — alongside continuous cybersecurity training & active bug bounty
2023

MechatronikerMechatronics Engineer

Rotan GmbH
  • Wartung, Instandhaltung & Fehlerdiagnose industrieller Anlagen — praktische OT-Berührungspunkte
  • Maintenance, servicing & fault diagnosis of industrial plants — hands-on OT exposure
2023

Stellv. TeamleiterDeputy Team Lead

Avedo Rostock
  • Operative Führung, Teamkoordination, Qualitätssicherung, Eskalationsmanagement
  • Operational leadership, team coordination, QA, escalation management
2018–2022

Ausbildung MechatronikerApprenticeship — Mechatronics

Consun Beet Company
  • SPS-Programmierung (Siemens S7), SCADA-Systeme, Industrieautomation, Messtechnik — direkter Bezug zu OT/ICS-Security
  • PLC programming (Siemens S7), SCADA systems, industrial automation, instrumentation — direct link to OT/ICS security
07

Sprachen & BildungLanguages & Education

SprachenLanguages

Deutsch
MutterspracheNative
English
Fließend (technisch)Fluent (technical)
Русский
GrundkenntnisseBasic

AusbildungEducation

Berufsausbildung MechatronikerVocational training — Mechatronics Engineer
Consun Beet Company · 2018–2022