Назад
Company hidden
обновлено 3 дня назад

Penetration Tester / Red Team Specialist (f/m/x) (Cybersecurity)

3 375 - 40
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Austria
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Penetration Tester / Red Team Specialist (Cybersecurity): Simulating realistic attack paths across enterprise, endpoint, identity, network, cloud, and web environments with an accent on offensive operations and defender enablement. Focus on exploiting privilege escalation, lateral movement, persistence, identity abuse, and web vulnerabilities while translating attack chains into detection and response improvements.

Location: Austria, with work-from-home options from Austria

Salary: Minimum EUR 3,375.40 gross per month under the Austrian Banking Collective Agreement; actual salary is determined based on qualifications and experience.

Company

hirify.global serves more than 17 million customers across Austria and Central and Eastern Europe through a large banking group.

What you will do

  • Plan and execute red team and purple team engagements across enterprise, endpoint, identity, network, cloud, and web environments.
  • Conduct realistic attack-path exercises against business units, network banks, and subsidiaries.
  • Perform privilege escalation, lateral movement, persistence, defense evasion, and identity abuse.
  • Assess Active Directory, cloud identity, internal infrastructure, and web application attack surfaces.
  • Document attack chains, expected telemetry, detection gaps, and prioritized remediation recommendations.
  • Work with blue teams, detection engineers, and incident responders to validate controls and improve detection coverage.

Requirements

  • Hands-on experience delivering red team, purple team, or advanced penetration testing engagements in large enterprise environments.
  • Experience with offensive operations, including privilege escalation, lateral movement, persistence, defense evasion, and identity abuse.
  • Practical knowledge of web application exploitation, including authentication bypass, session abuse, SSRF, deserialization, injection flaws, and OAuth/SAML abuse.
  • Deep understanding of Windows or Linux internals, authentication mechanisms, service and process relationships, and system telemetry.
  • Knowledge of Active Directory abuse paths and enterprise identity attack techniques.
  • Proficiency in at least one scripting language, preferably PowerShell or Python, with clear communication skills for technical and non-technical stakeholders.

Nice to have

  • Blue Team, detection engineering, incident response, SIEM, or EDR experience.
  • Familiarity with Atomic Red Team, Caldera, Azure AD/Entra ID, SWIFT security controls, TIBER-style testing, or DORA.
  • Experience in financial services, regulated industries, OT/SCADA, or banking ATM/POS security assessments.
  • Offensive security certifications or contributions such as CVEs, public tooling, conference talks, blog posts, or CTF participation.
  • German at business level.

Culture & Benefits

  • Work-from-home options are available from Austria, alongside flexible working hours.
  • English is the company language, with a global community representing more than 75 nationalities.
  • Work permit support, continuous learning, training, and career development opportunities.
  • Well-being programs, health check-ups, sport allowances, and a subsidized canteen.
  • Banking discounts, exclusive banking terms, and a free public transport pass.
  • Child allowances, gender-neutral parental leave, bilingual company kindergarten, and holiday childcare.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →