Penetration Tester

Hace 3 días

Basauri Vizcaya, Gran Bilbao (comarca); Vizcaya; País Vasco, España SQUAD Group Jornada completa

Junior Penetration Tester | 100% REMOTE - Spain

Since 2011, SQUAD Group has been a key player in the cybersecurity landscape. We partner with leading organizations to protect their information systems through a comprehensive 360° offering of consulting, integration, expertise, and managed services

Our mission: Securing Together

We believe in a collaborative approach to cybersecurity, where experts and clients work hand-in-hand to anticipate threats and protect critical infrastructure.

As part of our growing team, we're seekin g a Senior Security Engineer specialising in Vulnerability Manage ment. Based in Barcelona, this role will put you at the heart of a high-impact security engineering function, building and operating the systems that keep complex, large-scale environments continuously protected.

Your Role

You are a hands-on, curious security tester joining a pentest practice focused on web, mobile, and API applications. Working alongside senior pentesters on long-running client missions, you'll conduct hands-on assessments, document findings clearly, and grow into more autonomous engagements over time.

Your Responsibilities

  • Conduct penetration tests on web applications, APIs, and mobile apps, following OWASP methodologies (OWASP Top 10, ASVS, MASVS).
  • Perform manual and tool-assisted vulnerability discovery (Burp Suite, OWASP ZAP, Nmap, and similar tooling).
  • Reproduce, validate, and document vulnerabilities with clear technical evidence and business-risk framing.
  • Write clear, well-structured pentest reports and executive summaries in English for international clients.
  • Support remediation discussions with development teams, explaining findings and validating fixes.
  • Contribute to internal methodology, checklists, and knowledge-sharing within the pentest team.
  • Work on long-duration client missions, maintaining consistent quality and communication throughout the engagement.

What You Bring

  • 3 years of experience in Cybersecurity, including at least 1 year dedicated to application penetration testing.
  • Solid understanding of web application vulnerabilities (injection, authN/authZ flaws, SSRF, IDOR, etc.) and common exploitation techniques.
  • Working knowledge of Burp Suite, ZAP, and standard recon/exploitation tooling.
  • Basic scripting ability (Python or Bash) to support testing and automation.
  • Fluent professional English, spoken and written — required for client-facing missions and report writing.
  • Comfortable working independently on long missions while staying aligned with senior pentesters and client stakeholders.

Preferred Certifications: eJPT, eWPT, OSCP (in progress or recently obtained), or equivalent hands-on offensive security credentials.

Why Join Squad?

Personalized Growth: We help you build a training and certification plan aligned with your professional goals through our SquadExeperience

  • Expertise Development: Participate in internal events like our MixYourTalent webinars and monthly C TF sessions .
  • Visibility: Attend major industry conferences and contribute to our #TheExpert tec hnical b log
  • Culture: Enjoy a dynamic and close-knit environment with after-work events and team gatherings that foster great camaraderie.