7 дней назад
Pentesting Cybersecurity Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Pentesting Cybersecurity Engineer (AI): Executing and leading advanced penetration tests across web and mobile applications, networks, cloud environments, Active Directory, Wi-Fi, and AI-based systems with an accent on realistic attack scenarios, Red Team operations, and risk-focused reporting. Focus on designing MITRE ATT&CK-based attacks, evading EDR/XDR/WAF and antivirus controls, automating offensive tasks, and managing complex technical security audits.
Location: Hybrid role based in Tres Cantos, Madrid, Spain; includes 8 weeks per year of teleworking outside the usual geographical area.
Company
delivers technical audits and advanced offensive security assessments for organizations.
What you will do
- Execute and lead penetration tests in complex corporate environments.
- Design realistic attack scenarios based on MITRE ATT&CK TTPs and participate in Red Team and Purple Team exercises.
- Assess web and mobile applications, network infrastructures, Wi-Fi networks, cloud environments, Active Directory, and AI-based systems.
- Apply evasion techniques against EDR, XDR, WAF, and antivirus solutions.
- Identify vulnerabilities, evaluate risk, and propose mitigation strategies.
- Develop or adapt offensive tools and automations, produce technical and executive reports, present findings, and manage audit projects.
Requirements
- At least 3 years of penetration testing experience across web, mobile, network, cloud, Active Directory, or Wi-Fi environments.
- Experience designing and executing Red Team operations and independently leading technical security assessments.
- Advanced knowledge of Burp Suite, Nmap, Metasploit, or C2 frameworks.
- Ability to automate offensive tasks using Python, Bash, or PowerShell.
- Experience with technical and executive risk-focused reporting, stakeholder presentations, and cybersecurity or technical audit project management.
- Knowledge of PTES, MITRE ATT&CK, or OWASP; experience assessing AI or LLM-based systems is required.
Nice to have
- Offensive security certifications such as OSCP, OSEP, OSWE, eCPPT, CRTP, or equivalent.
Culture & Benefits
- Hybrid working model with 8 weeks per year of teleworking outside the usual geographical area.
- Flexible start and finish times, with intensive working hours on Fridays and during summer.
- Personalized career development plan, training, and language-learning support.
- National and international mobility, including a relocation package for candidates from other countries.
- Health, dental, and accident insurance, flexible compensation, brand discounts, and wellbeing programs.
Hiring process
- Recruitment includes telephone and personal contact with the talent acquisition team, either face-to-face or online.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →