Назад
Company hidden
7 дней назад

Pentester Senior (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Pentester Senior (Cybersecurity): Execute and lead advanced offensive security assessments across web and mobile applications, networks, cloud environments, Active Directory, Wi-Fi, and AI-based systems with an accent on realistic attack scenarios, Red Team exercises, and risk-focused reporting. Focus on evading EDR, XDR, WAF, and antivirus controls, automating offensive tooling, assessing LLM security, and coordinating complex technical audit projects.

Location: Hybrid role based in Tres Cantos, Madrid, Spain; includes up to 8 weeks per year of teleworking outside the usual geographical area.

Company

hirify.global's Technical Audits team conducts offensive security assessments and technical audit projects.

What you will do

  • Execute and lead penetration tests in complex corporate environments.
  • Design realistic attack scenarios based on MITRE ATT&CK TTPs and participate in Red Team and Purple Team exercises.
  • Assess web and mobile applications, network infrastructures, Wi-Fi networks, AWS, Azure, GCP, Active Directory, and AI-based systems.
  • Apply evasion techniques against EDR, XDR, WAF, and antivirus solutions, and develop offensive automations.
  • Identify vulnerabilities, analyze risk, recommend mitigations, and produce technical and executive reports.
  • Manage audit scope, timelines, deliverables, and presentations for technical and business audiences.

Requirements

  • 5+ years of penetration testing experience across web, mobile, network, cloud, Active Directory, and Wi-Fi environments.
  • Experience designing and executing Red Team operations and simulated attacks.
  • Advanced knowledge of Burp Suite, Nmap, Metasploit, or C2 frameworks.
  • Ability to automate offensive tasks with Python, Bash, or PowerShell.
  • Experience with technical and executive risk-focused reporting and cybersecurity project management.
  • Knowledge of PTES, MITRE ATT&CK, OWASP, and AI or LLM security assessment methods.

Nice to have

  • OSCP, OSEP, OSWE, eCPPT, CRTP, or equivalent offensive security certification.

Culture & Benefits

  • Hybrid working model with flexible start and finish times.
  • Intensive working hours on Fridays and during summer.
  • Personalized career development, training, and language learning support.
  • National and international mobility, including a relocation package for candidates from other countries.
  • Flexible compensation, brand discounts, health, dental, and accident insurance, plus physical, mental, and financial wellbeing programs.

Hiring process

  • Recruitment includes telephone and personal contact with the talent acquisition team, either face-to-face or online.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →