DE · EN  ·  ⎙ PDF

Josef Roland Basner

Penetration Tester · Security ResearcherPenetration Tester · Security Researcher
josefbasner@proton.me  ·  +49 151 4495 7240  ·  github.com/JBMTP07  ·  linkedin.com/in/josef-basner  ·  Deutschland · Remote (EU)Germany · Remote (EU)
Open to Work · Junior / Trainee · Remote EU · CompTIA Security+ zertifiziertOpen to Work · Junior / Trainee · Remote EU · CompTIA Security+ certified

ProfilProfile

Offensive-Security-Spezialist mit 5+ Jahren Praxis in Bug Bounty, Web-/API-Pentesting und Active-Directory-Angriffen. Seit 2020 in privaten / invite-only Programmen auf HackerOne und Bugcrowd mit 20+ verifizierten Schwachstellen (RCE, SQLi, XSS, IDOR, Auth-Bypass), Schwerpunkt Business-Logic und Exploit-Chains. CompTIA Security+ (SY0-701) zertifiziert (05/2026). Eigenes Security-Lab, dokumentierte Methodik, laufender Zertifizierungspfad (PenTest+, CEH v13, OSCP geplant Q4 2026). Zusätzlich ausgebildeter Mechatroniker (Siemens S7, SCADA) — direkter Zugang zu OT/ICS-Security.

Offensive-security specialist with 5+ years of hands-on experience in bug bounty, web/API penetration testing and Active Directory attacks. Active since 2020 in private / invite-only programs on HackerOne and Bugcrowd with 20+ verified vulnerabilities (RCE, SQLi, XSS, IDOR, auth bypass), focused on business-logic flaws and exploit chains. CompTIA Security+ (SY0-701) certified (05/2026). Own security lab, documented methodology, certification path in progress (PenTest+, CEH v13, OSCP planned Q4 2026). Also a trained mechatronics engineer (Siemens S7, SCADA) — a direct route into OT/ICS security.

Technische SchwerpunkteTechnical Skills

Offensive Security Penetration Testing · Web- & API-Testing · Bug Bounty · Recon & Enumeration · Privilege Escalation · Active Directory Attacks (Kerberoasting, AS-REP Roasting, Lateral Movement) · Post-ExploitationPenetration testing · web & API testing · bug bounty · recon & enumeration · privilege escalation · Active Directory attacks (Kerberoasting, AS-REP roasting, lateral movement) · post-exploitation

Tools Burp Suite Pro · Metasploit · Nmap · Wireshark · Hydra · Nessus · BloodHound · CrackMapExec · Impacket · ffuf · sqlmap · gobuster

Scripting Python · Bash · PowerShell · JavaScript

Networking TCP/IP · DNS · DHCP · Subnetting · ARP · Routing · Firewalls

Systems Kali Linux · Parrot OS · Ubuntu · Windows Server · Active Directory · Docker

OT / ICS Siemens S7 (SPS) · SCADA · Industriesteuerungen · Feldbusse · IT/OT-SchnittstellenSiemens S7 (PLC) · SCADA · industrial control systems · fieldbuses · IT/OT interfaces

Security-ErfahrungSecurity Experience

Bug Bounty ResearcherBug Bounty Researcher

seit 2020since 2020
HackerOne · Bugcrowd · privat / invite-onlyprivate / invite-only

HackTheBox · Eigenes Security-LabHackTheBox · Own Security Lab

laufendongoing

Gastredner — KI & CybersecurityGuest Speaker — AI & Cybersecurity

seit 2024since 2024
Ehrenamtlich · 8 SchulenVolunteer · 8 schools

ZertifizierungenCertifications

CompTIA Security+ (SY0-701) — bestanden 05/2026passed 05/2026 CompTIA PenTest+ — in Vorbereitungin progress EC-Council CEH v13 — in Vorbereitungin progress CompTIA Network+ / Linux+ — in Vorbereitungin progress OffSec OSCP — geplant Q4 2026planned Q4 2026

Kurse abgeschlossen über New Horizons (zertifizierter Bildungsträger).

Courses completed via New Horizons (accredited training provider).

WerdegangWork Experience

Selbstständig (freiberuflich)Self-employed (freelance)

seit 01/2025since 01/2025
Parallel zur Cybersecurity-Weiterbildung & aktivem Bug BountyAlongside continuous cybersecurity training & active bug bounty

Mechatroniker · Rotan GmbH

2023

Stellv. Teamleiter · Avedo RostockDeputy Team Lead · Avedo Rostock

2023

Ausbildung Mechatroniker · Consun Beet CompanyApprenticeship, Mechatronics Engineer · Consun Beet Company

2018–2022

SprachenLanguages

Deutsch (Muttersprache) · Englisch (fließend, technisch) · Russisch (Grundkenntnisse)German (native) · English (fluent, technical) · Russian (basic)