7 дней назад
Pentester (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Pentester (Cybersecurity): Conducting penetration tests and technical security assessments across web applications, APIs, infrastructure, cloud, and identity environments with an accent on manual exploitation, vulnerability chaining, and attack-path analysis. Focus on validating realistic technical and business impact, developing offensive security tooling, and producing actionable remediation recommendations while independently validating AI-generated outputs.
Location: Porto, Portugal — hybrid
Company
provides a multicultural technology environment supporting projects connected with the European stock market area.
What you will do
- Perform penetration tests and technical security assessments across web applications, APIs, infrastructure, cloud, and identity environments.
- Identify, validate, and exploit vulnerabilities through manual investigation, attack-path analysis, and vulnerability chaining.
- Conduct reconnaissance, authentication and authorization testing, source code or configuration analysis, and offensive tooling development or adaptation.
- Produce technically accurate security findings covering evidence, impact, exploitability, and remediation recommendations.
- Support remediation validation and contribute to security methodologies, automation, vulnerability research, and knowledge sharing.
- Leverage AI and modern offensive security techniques while independently validating AI-generated outputs.
Requirements
- At least 2 years of professional experience as a Pentester or Offensive Security Specialist.
- Practical experience in web application security, API security, vulnerability assessment, OWASP Top 10, and the OWASP Web Security Testing Guide.
- Knowledge of authentication and authorization testing, HTTP, network and infrastructure security, and security assessment methodologies.
- Experience with Linux and Windows environments, Active Directory, Entra ID, and cloud security concepts and technologies.
- Proficiency in scripting or programming, vulnerability research, manual exploitation, attack-path analysis, and offensive security tooling.
- Professional English communication skills are required.
Culture & Benefits
- Hybrid work in Porto with a multicultural team distributed across several European cities.
- Remote onboarding process.
- Health insurance.
- Personalized training plan with a budget for training and technical books.
- Regular feedback and professional development support.
- Team events every semester and a culture of proximity and transparency.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 часов назад
Application Security Engineer
28 000 - 52 000€
7 часов назад
Application Security Engineer
50 000 - 75 000€
6 дней назад
Security Assurance Specialist - Associate (Information Security)
3 дня назад
Инженер по безопасности приложений и управлению уязвимостями
6 дней назад
Product Security Incident Response Team (PSIRT) Vulnerability Analyst (Cybersecurity)
8 часов назад