Назад
Company hidden
обновлено 1 месяц назад

Red Team PenTester

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Romania
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Red Team PenTester (Offensive Security): Assessing web applications, APIs, networks, cloud platforms, and internal infrastructures through realistic attack simulations with an accent on manual exploitation, Active Directory abuse, privilege escalation, and cloud security. Focus on chaining adversary-style techniques, validating remediation, and translating vulnerabilities into clear technical and business-impact guidance.

Location: Bucharest, Romania. Candidates must have a valid visa and work permit to work in Romania at the application stage.

Company

hirify.global develops secure connectivity and edge processing solutions for embedded applications.

What you will do

  • Perform penetration tests of web applications, APIs, networks, internal infrastructures, and cloud environments.
  • Identify, exploit, document, and report vulnerabilities through realistic attack simulations.
  • Conduct manual testing, source code reviews, and adversary-style attack chains including lateral movement, privilege escalation, and Active Directory abuse.
  • Assess AWS, Azure, and GCP environments for configuration and architectural weaknesses.
  • Produce reports explaining technical findings and business impact, and present remediation guidance to engineering and management.
  • Support remediation, mitigation validation, retesting, and ongoing offensive security research.

Requirements

  • 3+ years of hands-on penetration testing or offensive security experience.
  • Strong knowledge of OWASP Top 10, API security, internal network attacks, Active Directory exploitation, and Windows and Linux privilege escalation.
  • Experience with Burp Suite, Nmap, Metasploit, BloodHound, CrackMapExec, and Impacket.
  • Understanding of TCP/IP, DNS, HTTP(S), Kerberos, NTLM, OAuth2, and SSO.
  • Comfort working with Linux and Windows, Bash, PowerShell, and basic Python scripting.
  • Strong reporting, communication, risk-explanation, time-management, and client-facing skills.

Nice to have

  • OSCP, PNPT, CRTO, or OSWE certification.
  • Red team, adversary simulation, cloud penetration testing, source code review, threat modeling, or attack path analysis experience.
  • Experience with EDR/AV evasion techniques in ethical or laboratory settings.

Culture & Benefits

  • Permanent full-time contract with a bonus plan.
  • Flexible working hours and a work-from-home policy.
  • Lunch vouchers, 25 vacation days, and the option to buy company shares at a 15% discount.
  • Online and offline learning opportunities for professional development.
  • On-site cafeteria, restaurant, relaxation areas, social activities, and employee community initiatives.

Hiring process

  • Submit an online application with a CV and motivation letter in English.
  • After CV screening, complete an initial phone or video conversation with Talent Acquisition.
  • Continue with several business interviews.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →