Careers

A small team with a high bar

Planck Defense & Aerospace is deliberately small and unapologetically senior. We hire slowly, we pay attention to craft, and we would rather leave a seat empty than fill it with the wrong person. If you want your name on serious technical work, we would like to hear from you.

Who We Hire

The role families we hire into

We do not keep a public board of open positions. These are the practices where we add people and the backgrounds that tend to fit. If your experience maps to one of them, or sits somewhere between two, write to us.

Application Security Consultant

Tests web applications and the platforms behind them against OWASP WSTG and ASVS: authentication, session handling, access control, injection classes, and business logic. Suits people who have spent years breaking real applications and can explain a finding to the engineer who has to fix it. Comfort reading source in at least one major language helps more than any certification.

Network and Infrastructure Tester

Runs external and internal network assessments: exposed services, Active Directory attack paths, segmentation testing, and lateral movement. A good fit for practitioners who are as comfortable inside a flat corporate LAN as they are enumerating a hardened perimeter, and who document what they did precisely enough that a network team can retrace every step.

Red Team Operator

Plans and executes objective-driven adversary emulation mapped to MITRE ATT&CK: initial access, persistence, evasion, and operating quietly against a live defensive team. Suits operators with real tradecraft judgment, who know when not to act, and who treat operational security and client safety as part of the craft rather than a constraint on it.

LLM and AI Security Researcher

Attacks systems built on large language models: direct and indirect prompt injection, jailbreaks, data exfiltration through model outputs, agentic tool abuse, and RAG poisoning. The right seat for people who track the OWASP LLM Top 10 the way others track CVE feeds, and who have already broken at least one production AI feature, in a lab or on an engagement.

Threat Intelligence Analyst

Monitors breach data, infostealer logs, phishing infrastructure, and dark web sources for specific client organizations, then turns raw signals into severity-ranked alerts with context and recommended actions. Suits analysts who write clearly, verify before escalating, and want to own a named relationship with the clients they cover.

Detection and Purple Team Engineer

Works alongside red team operations to measure what defenders actually see: mapping detections to ATT&CK techniques, tuning alert logic with client SOC teams, and closing the gap between an attack that happened and an alert that fired. Built for people who have lived on the defensive side and want to test their assumptions against a live adversary.

How We Work

The environment you would be joining

Consultancies fail their staff in predictable ways: overbooked calendars, junior teams sold as senior ones, reports ground out overnight before a deadline nobody sanity checked. We built this firm to avoid exactly those failures, because the quality of our work depends on the conditions it is done in.

You will spend most of your time on technical work. Scoping, testing, analysis, and reporting sit with the same person, so the report you write describes work you actually did, and the client you debrief is one you already know. Administrative overhead stays thin.

  • Senior practitioners across the team. Everyone here tests, hunts, or builds. There is no delivery layer between you and the work, and no separate class of people who only manage.
  • Direct client contact. You scope your own engagements, talk to the client's engineers without an intermediary, and present your own findings. Your name goes on your work.
  • No bench of juniors billed as seniors. Clients get the people they were promised. You will never be sold as someone you are not, and you will never inherit a scope someone else oversold.
  • Protected research time. Time for research, tooling, and publication is part of the job, not something you defend against a utilization target.
  • Scoping that lets you do good work. Engagements are sized for real depth, with room for the unexpected paths that produce the findings that matter. You will not be asked to cover a sprawling estate in three days.
Hiring Process

Four stages, calibrated to the role

The process is designed to respect your time. Each stage is adjusted to the role you are applying for, we tell you where you stand after every step, and we do not run day-long whiteboard gauntlets.

Application and CV review

Send your CV and anything that shows your work to [email protected]. A practitioner reads every application, and every applicant receives an answer, including the ones we decline.

Technical conversation

A discussion with the people you would work with, about work you have actually done: targets, techniques, findings, and the judgment calls behind them. No trivia quizzes, no brainteasers.

Practical exercise or portfolio review

Depending on the role, either a scoped exercise in our own lab environment or a walkthrough of work you have already published: reports, writeups, tooling, research. Existing work counts. We do not ask candidates for free labor.

Offer and onboarding

A clear written offer, then structured onboarding: our methodology, reporting standards, data handling rules, and a first engagement staffed alongside a colleague who knows the environment.

How To Apply

Write to us, even without an opening

We accept speculative applications year round. Send an email to [email protected] with your CV attached and a few paragraphs about the work you want to do. Plain text is fine. A short letter written for us beats a polished template written for everyone.

Tell us what you have tested and in what context: applications, networks, cloud environments, AI systems, or the intelligence work you have delivered, at whatever level of detail confidentiality allows. Tell us which tools you reach for first and which ones you have built or extended yourself. If there is a writeup, a CVE, a CTF result, or a piece of research you are proud of, link it. One good artifact tells us more than a page of keywords.

We also welcome people who do not fit a neat box. Some of the strongest practitioners we know arrived from software engineering, systems administration, network operations, or intelligence work rather than a straight security track. If you can show depth, curiosity, and evidence of finishing hard things, the title on your last job matters far less.

What to include

  • Your CV. PDF preferred. Focus on what you did, not on the logos you did it near.
  • What you have tested. The kinds of targets, environments, and engagements you have worked on.
  • The tools you reach for. Plus anything you have written yourself, from one-off scripts to published tooling.
  • One thing you are proud of. A writeup, a CVE, a CTF finish, a conference talk, a detection rule. A link is enough.

[email protected]

Join Us

Do work you can put your name on

One email starts the conversation. A practitioner reads it, and you will hear back either way.