7 дней назад
Pentester Senior (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Pentester Senior (Cybersecurity): Execute and lead advanced offensive security assessments across web and mobile applications, networks, cloud environments, Active Directory, Wi-Fi, and AI-based systems with an accent on realistic attack scenarios, Red Team exercises, and risk-focused reporting. Focus on evading EDR, XDR, WAF, and antivirus controls, automating offensive tooling, assessing LLM security, and coordinating complex technical audit projects.
Location: Hybrid role based in Tres Cantos, Madrid, Spain; includes up to 8 weeks per year of teleworking outside the usual geographical area.
Company
's Technical Audits team conducts offensive security assessments and technical audit projects.
What you will do
- Execute and lead penetration tests in complex corporate environments.
- Design realistic attack scenarios based on MITRE ATT&CK TTPs and participate in Red Team and Purple Team exercises.
- Assess web and mobile applications, network infrastructures, Wi-Fi networks, AWS, Azure, GCP, Active Directory, and AI-based systems.
- Apply evasion techniques against EDR, XDR, WAF, and antivirus solutions, and develop offensive automations.
- Identify vulnerabilities, analyze risk, recommend mitigations, and produce technical and executive reports.
- Manage audit scope, timelines, deliverables, and presentations for technical and business audiences.
Requirements
- 5+ years of penetration testing experience across web, mobile, network, cloud, Active Directory, and Wi-Fi environments.
- Experience designing and executing Red Team operations and simulated attacks.
- Advanced knowledge of Burp Suite, Nmap, Metasploit, or C2 frameworks.
- Ability to automate offensive tasks with Python, Bash, or PowerShell.
- Experience with technical and executive risk-focused reporting and cybersecurity project management.
- Knowledge of PTES, MITRE ATT&CK, OWASP, and AI or LLM security assessment methods.
Nice to have
- OSCP, OSEP, OSWE, eCPPT, CRTP, or equivalent offensive security certification.
Culture & Benefits
- Hybrid working model with flexible start and finish times.
- Intensive working hours on Fridays and during summer.
- Personalized career development, training, and language learning support.
- National and international mobility, including a relocation package for candidates from other countries.
- Flexible compensation, brand discounts, health, dental, and accident insurance, plus physical, mental, and financial wellbeing programs.
Hiring process
- Recruitment includes telephone and personal contact with the talent acquisition team, either face-to-face or online.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →