Josef Roland Basner
Penetration Tester · Security ResearcherPenetration Tester · Security Researcher
josefbasner@proton.me · +49 151 4495 7240 · github.com/JBMTP07 · linkedin.com/in/josef-basner · Deutschland · Remote (EU)Germany · Remote (EU)
Open to Work · Junior / Trainee · Remote EU · CompTIA Security+ zertifiziertOpen to Work · Junior / Trainee · Remote EU · CompTIA Security+ certified
ProfilProfile
Offensive-Security-Spezialist mit 5+ Jahren Praxis in Bug Bounty, Web-/API-Pentesting und Active-Directory-Angriffen. Seit 2020 in privaten / invite-only Programmen auf HackerOne und Bugcrowd mit 20+ verifizierten Schwachstellen (RCE, SQLi, XSS, IDOR, Auth-Bypass), Schwerpunkt Business-Logic und Exploit-Chains. CompTIA Security+ (SY0-701) zertifiziert (05/2026). Eigenes Security-Lab, dokumentierte Methodik, laufender Zertifizierungspfad (PenTest+, CEH v13, OSCP geplant Q4 2026). Zusätzlich ausgebildeter Mechatroniker (Siemens S7, SCADA) — direkter Zugang zu OT/ICS-Security.
Offensive-security specialist with 5+ years of hands-on experience in bug bounty, web/API penetration testing and Active Directory attacks. Active since 2020 in private / invite-only programs on HackerOne and Bugcrowd with 20+ verified vulnerabilities (RCE, SQLi, XSS, IDOR, auth bypass), focused on business-logic flaws and exploit chains. CompTIA Security+ (SY0-701) certified (05/2026). Own security lab, documented methodology, certification path in progress (PenTest+, CEH v13, OSCP planned Q4 2026). Also a trained mechatronics engineer (Siemens S7, SCADA) — a direct route into OT/ICS security.
Technische SchwerpunkteTechnical Skills
Offensive Security Penetration Testing · Web- & API-Testing · Bug Bounty · Recon & Enumeration · Privilege Escalation · Active Directory Attacks (Kerberoasting, AS-REP Roasting, Lateral Movement) · Post-ExploitationPenetration testing · web & API testing · bug bounty · recon & enumeration · privilege escalation · Active Directory attacks (Kerberoasting, AS-REP roasting, lateral movement) · post-exploitation
Tools Burp Suite Pro · Metasploit · Nmap · Wireshark · Hydra · Nessus · BloodHound · CrackMapExec · Impacket · ffuf · sqlmap · gobuster
Scripting Python · Bash · PowerShell · JavaScript
Networking TCP/IP · DNS · DHCP · Subnetting · ARP · Routing · Firewalls
Systems Kali Linux · Parrot OS · Ubuntu · Windows Server · Active Directory · Docker
OT / ICS Siemens S7 (SPS) · SCADA · Industriesteuerungen · Feldbusse · IT/OT-SchnittstellenSiemens S7 (PLC) · SCADA · industrial control systems · fieldbuses · IT/OT interfaces
Security-ErfahrungSecurity Experience
Bug Bounty ResearcherBug Bounty Researcher
seit 2020since 2020
HackerOne · Bugcrowd · privat / invite-onlyprivate / invite-only
- 20+ bestätigte Schwachstellen: RCE, SQL-Injection, Stored/Reflected XSS, IDOR, Auth-Bypass, Business-Logic-Flaws
- 20+ verified vulnerabilities: RCE, SQL injection, stored/reflected XSS, IDOR, auth bypass, business-logic flaws
- Schwerpunkt Web- & API-Schwachstellen, Recon-Automatisierung, Token-Analyse, Exploit-Chains
- Focus on web & API vulnerabilities, recon automation, token analysis, exploit chains
- Vollständige NDA- & Responsible-Disclosure-Einhaltung; saubere, reproduzierbare PoC-Reports nach Industriestandard
- Full NDA & responsible-disclosure compliance; clean, reproducible PoC reports to industry standard
HackTheBox · Eigenes Security-LabHackTheBox · Own Security Lab
laufendongoing
- Öffentliche Writeups vollständiger Angriffsketten für retired Machines (github.com/JBMTP07/HTB-Writeups)
- Public write-ups of full attack chains for retired machines (github.com/JBMTP07/HTB-Writeups)
- Isoliertes Testlabor: Raspberry Pi, Metasploitable, Vulnerable VMs, eigene AD-Domäne; Workflow: Recon → Enumerate → Exploit → Escalate → Report
- Isolated test lab: Raspberry Pi, Metasploitable, vulnerable VMs, own AD domain; workflow: Recon → Enumerate → Exploit → Escalate → Report
- Veröffentlichte Methodik-Sammlung: Linux PrivEsc, AD-Angriffe, Nmap-Enumeration, Burp-Workflow (github.com/JBMTP07/Study-Notes)
- Published methodology notes: Linux PrivEsc, AD attacks, Nmap enumeration, Burp workflow (github.com/JBMTP07/Study-Notes)
Gastredner — KI & CybersecurityGuest Speaker — AI & Cybersecurity
seit 2024since 2024
Ehrenamtlich · 8 SchulenVolunteer · 8 schools
- Vorträge zu LLMs, KI-Sicherheitsrisiken, Phishing & Cybersecurity-Grundlagen für Schüler:innen und Lehrkräfte
- Talks on LLMs, AI security risks, phishing & cybersecurity fundamentals for students and teachers
ZertifizierungenCertifications
CompTIA Security+ (SY0-701) — bestanden 05/2026passed 05/2026
CompTIA PenTest+ — in Vorbereitungin progress
EC-Council CEH v13 — in Vorbereitungin progress
CompTIA Network+ / Linux+ — in Vorbereitungin progress
OffSec OSCP — geplant Q4 2026planned Q4 2026
Kurse abgeschlossen über New Horizons (zertifizierter Bildungsträger).
Courses completed via New Horizons (accredited training provider).
WerdegangWork Experience
Selbstständig (freiberuflich)Self-employed (freelance)
seit 01/2025since 01/2025Parallel zur Cybersecurity-Weiterbildung & aktivem Bug BountyAlongside continuous cybersecurity training & active bug bounty
Mechatroniker · Rotan GmbH
2023- Wartung, Instandhaltung & Fehlerdiagnose industrieller Anlagen — praktische OT-Berührungspunkte
- Maintenance, servicing & fault diagnosis of industrial plants — hands-on OT exposure
Stellv. Teamleiter · Avedo RostockDeputy Team Lead · Avedo Rostock
2023- Operative Führung, Teamkoordination, Qualitätssicherung, Eskalationsmanagement
- Operational leadership, team coordination, quality assurance, escalation management
Ausbildung Mechatroniker · Consun Beet CompanyApprenticeship, Mechatronics Engineer · Consun Beet Company
2018–2022- SPS-Programmierung (Siemens S7), SCADA-Systeme, Industrieautomation, Messtechnik — direkter Bezug zu OT/ICS-Security
- PLC programming (Siemens S7), SCADA systems, industrial automation, instrumentation — direct link to OT/ICS security
SprachenLanguages
Deutsch (Muttersprache) · Englisch (fließend, technisch) · Russisch (Grundkenntnisse)German (native) · English (fluent, technical) · Russian (basic)