Назад
Company hidden
7 дней назад

Pentester (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Portugal
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Pentester (Cybersecurity): Conducting penetration tests and technical security assessments across web applications, APIs, infrastructure, cloud, and identity environments with an accent on manual exploitation, vulnerability chaining, and attack-path analysis. Focus on validating realistic technical and business impact, developing offensive security tooling, and producing actionable remediation recommendations while independently validating AI-generated outputs.

Location: Porto, Portugal — hybrid

Company

hirify.global provides a multicultural technology environment supporting projects connected with the European stock market area.

What you will do

  • Perform penetration tests and technical security assessments across web applications, APIs, infrastructure, cloud, and identity environments.
  • Identify, validate, and exploit vulnerabilities through manual investigation, attack-path analysis, and vulnerability chaining.
  • Conduct reconnaissance, authentication and authorization testing, source code or configuration analysis, and offensive tooling development or adaptation.
  • Produce technically accurate security findings covering evidence, impact, exploitability, and remediation recommendations.
  • Support remediation validation and contribute to security methodologies, automation, vulnerability research, and knowledge sharing.
  • Leverage AI and modern offensive security techniques while independently validating AI-generated outputs.

Requirements

  • At least 2 years of professional experience as a Pentester or Offensive Security Specialist.
  • Practical experience in web application security, API security, vulnerability assessment, OWASP Top 10, and the OWASP Web Security Testing Guide.
  • Knowledge of authentication and authorization testing, HTTP, network and infrastructure security, and security assessment methodologies.
  • Experience with Linux and Windows environments, Active Directory, Entra ID, and cloud security concepts and technologies.
  • Proficiency in scripting or programming, vulnerability research, manual exploitation, attack-path analysis, and offensive security tooling.
  • Professional English communication skills are required.

Culture & Benefits

  • Hybrid work in Porto with a multicultural team distributed across several European cities.
  • Remote onboarding process.
  • Health insurance.
  • Personalized training plan with a budget for training and technical books.
  • Regular feedback and professional development support.
  • Team events every semester and a culture of proximity and transparency.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →