{"schemaVersion":"jobsearcher.job.v1","id":"c14a666d28fdef1df5bbf2ca","url":"https://jobsearcher.com/jobs/c14a666d28fdef1df5bbf2ca","canonicalUrl":"https://jobsearcher.com/jobs/c14a666d28fdef1df5bbf2ca","title":"Auditor - Vulnerability Identification, Penetration Testing, Software & IT (d/m/f/x)","description":"The Mercedes-Benz Group AG is one of the world's most successful automotive companies. With Mercedes-Benz AG, the vehicle manufacturer is among the largest providers of premium and luxury passenger cars and vans.\r\nBecoming part of Mercedes Benz means finding the area of responsibility in which you can develop your talents individually. It means giving your best in a global automotive company with the goal of building the world's most desirable cars. In doing so, you will be supported by visionary colleagues who share your pioneering spirit. Together for excellence.\r\nAbout Us\r\nCorporate Audit of Mercedes Benz AG is an independent and objective assurance function. We support the company in identifying, assessing, and managing technological, digital, and cyber risks in a transparent and sustainable manner, in accordance with the International Standards for the Professional Practice of Internal Auditing (IIA / IPPF) and DIIR requirements. To strengthen our team, we are looking for an Auditor (m/f/d) with strong Cyber Security and Offensive Security expertise who not only assesses risks conceptually, but technically validates them.\r\nYour Role\r\nIn this position, you combine internal audit responsibilities with hands on offensive cyber security expertise. You audit where risks are most critical: software, IT systems, digital platforms, and connected architectures.\r\nKey Responsibilities\r\nCyber Security & Offensive Testing - Perform authorized vulnerability assessments and penetration tests as part of audit and special engagements (e.g. \"friendly attack\", assumed breach scenarios). Conduct technical testing of Applications, APIs, and platforms, IT infrastructure, networks, and identity environments, Cloud, hybrid, and connected systems. Validate vulnerability scanner results and third party penetration test findings\r\nAudit & Security Assurance - Independently plan, execute, and follow up audits in line with IIA Standards (IPPF) and DIIR, assess the effectiveness of technical and organizational security controls (confidentiality, integrity, availability, traceability), evaluate governance, risk, and control systems in IT and software environments, support audit readiness, remediation tracking, re testing, and closure verification\r\nReporting & Management Communication - Prepare concise, management ready audit reports including clear risk assessments, verifiable evidence, actionable and prioritized recommendations. Communicate complex technical findings clearly to IT and software owners, auditees and (top) management\r\nMethods & Continuous Improvement - Apply and further develop audit and security methodologies (e.g. OWASP, MITRE ATT&CK, NIST, ISO standards), use modern tools and AI supported analysis and testing techniques, actively contribute to the advancement of cyber security audit approaches and technology enabled audit practices\r\nQualifikationen\r\nProfessional Qualifications\r\nUniversity degree in Computer Science, IT Security, Software Engineering, Business Informatics, or comparable\r\nSeveral years of professional experience in Cyber Security / Offensive Security / Penetration Testing, Vulnerability Management or Software / IT Security, ideally complemented by experience in Internal Audit or audit relevant environments\r\nStrong knowledge of Application and API security, IT, cloud, and hybrid architectures, authentication, authorization, and privilege concepts, confident use of professional penetration testing tools and manual testing techniques\r\nBasic understanding of audit compliant work according to IIA / IPPF\r\nPersonal Competencies\r\nStrong analytical and conceptual thinking skills\r\nAbility to explain complex technical risks in a clear, structured, and management relevant manner\r\nStrong cyber security mindset combined with high integrity and sense of responsibility\r\nConfident communication skills, including in critical discussions on cyber and IT risks\r\nTeam oriented, proactive, and professional attitude as part of an independent audit function\r\nWillingness to travel for business purposes (several times per year, including longer assignments)\r\nCertifications (Beneficial, Not Mandatory): offensive security certifications (e.g. OSCP, OSCE, CRTO, GPEN or comparable), CIA, CISA, or comparable audit / security certifications, cloud or platform security certifications\r\nWhat We Offer\r\nHighly relevant audit work at the intersection of Internal Audit and Cyber Security\r\nDirect impact on cyber resilience, product security, and system integrity\r\nHigh visibility and close interaction with management, IT, and security units\r\nDeep insights into complex, future oriented IT and software landscapes\r\nStructured professional development in audit, security, and emerging technologies (including AI)\r\nModern, flexible working models based on trust and personal responsibility\r\nAdditional Information\r\nThis is a permanent position.\r\nSeverely disabled applicants and applicants with equivalent status are welcome!\r\nJ-18808-Ljbffr","company":"Daimler Ag","rawCompany":"daimler ag","city":"Stuttgart","state":"AR","isRemote":false,"isActive":false,"createdAt":"2026-06-29T01:02:44.196Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.04","title":"Penetration Testers","slug":"penetration-testers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Auditor - Vulnerability Identification, Penetration Testing, Software & IT (d/m/f/x)","description":"The Mercedes-Benz Group AG is one of the world's most successful automotive companies. With Mercedes-Benz AG, the vehicle manufacturer is among the largest providers of premium and luxury passenger cars and vans.\r\nBecoming part of Mercedes Benz means finding the area of responsibility in which you can develop your talents individually. It means giving your best in a global automotive company with the goal of building the world's most desirable cars. In doing so, you will be supported by visionary colleagues who share your pioneering spirit. Together for excellence.\r\nAbout Us\r\nCorporate Audit of Mercedes Benz AG is an independent and objective assurance function. We support the company in identifying, assessing, and managing technological, digital, and cyber risks in a transparent and sustainable manner, in accordance with the International Standards for the Professional Practice of Internal Auditing (IIA / IPPF) and DIIR requirements. To strengthen our team, we are looking for an Auditor (m/f/d) with strong Cyber Security and Offensive Security expertise who not only assesses risks conceptually, but technically validates them.\r\nYour Role\r\nIn this position, you combine internal audit responsibilities with hands on offensive cyber security expertise. You audit where risks are most critical: software, IT systems, digital platforms, and connected architectures.\r\nKey Responsibilities\r\nCyber Security & Offensive Testing - Perform authorized vulnerability assessments and penetration tests as part of audit and special engagements (e.g. \"friendly attack\", assumed breach scenarios). Conduct technical testing of Applications, APIs, and platforms, IT infrastructure, networks, and identity environments, Cloud, hybrid, and connected systems. Validate vulnerability scanner results and third party penetration test findings\r\nAudit & Security Assurance - Independently plan, execute, and follow up audits in line with IIA Standards (IPPF) and DIIR, assess the effectiveness of technical and organizational security controls (confidentiality, integrity, availability, traceability), evaluate governance, risk, and control systems in IT and software environments, support audit readiness, remediation tracking, re testing, and closure verification\r\nReporting & Management Communication - Prepare concise, management ready audit reports including clear risk assessments, verifiable evidence, actionable and prioritized recommendations. Communicate complex technical findings clearly to IT and software owners, auditees and (top) management\r\nMethods & Continuous Improvement - Apply and further develop audit and security methodologies (e.g. OWASP, MITRE ATT&CK, NIST, ISO standards), use modern tools and AI supported analysis and testing techniques, actively contribute to the advancement of cyber security audit approaches and technology enabled audit practices\r\nQualifikationen\r\nProfessional Qualifications\r\nUniversity degree in Computer Science, IT Security, Software Engineering, Business Informatics, or comparable\r\nSeveral years of professional experience in Cyber Security / Offensive Security / Penetration Testing, Vulnerability Management or Software / IT Security, ideally complemented by experience in Internal Audit or audit relevant environments\r\nStrong knowledge of Application and API security, IT, cloud, and hybrid architectures, authentication, authorization, and privilege concepts, confident use of professional penetration testing tools and manual testing techniques\r\nBasic understanding of audit compliant work according to IIA / IPPF\r\nPersonal Competencies\r\nStrong analytical and conceptual thinking skills\r\nAbility to explain complex technical risks in a clear, structured, and management relevant manner\r\nStrong cyber security mindset combined with high integrity and sense of responsibility\r\nConfident communication skills, including in critical discussions on cyber and IT risks\r\nTeam oriented, proactive, and professional attitude as part of an independent audit function\r\nWillingness to travel for business purposes (several times per year, including longer assignments)\r\nCertifications (Beneficial, Not Mandatory): offensive security certifications (e.g. OSCP, OSCE, CRTO, GPEN or comparable), CIA, CISA, or comparable audit / security certifications, cloud or platform security certifications\r\nWhat We Offer\r\nHighly relevant audit work at the intersection of Internal Audit and Cyber Security\r\nDirect impact on cyber resilience, product security, and system integrity\r\nHigh visibility and close interaction with management, IT, and security units\r\nDeep insights into complex, future oriented IT and software landscapes\r\nStructured professional development in audit, security, and emerging technologies (including AI)\r\nModern, flexible working models based on trust and personal responsibility\r\nAdditional Information\r\nThis is a permanent position.\r\nSeverely disabled applicants and applicants with equivalent status are welcome!\r\nJ-18808-Ljbffr","datePosted":"2026-06-29T01:02:44.196Z","dateModified":"2026-06-29T01:02:44.196Z","hiringOrganization":{"@type":"Organization","name":"Daimler Ag","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Stuttgart","addressRegion":"AR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"c14a666d28fdef1df5bbf2ca"},"url":"https://jobsearcher.com/jobs/c14a666d28fdef1df5bbf2ca"}}