Pentesting cibersecurity engineer

Hace 3 días

Tres Cantos, Madrid, España GMV Jornada completa
Overview

In this Senior Pentester role, you design and execute advanced offensive security assessments across web, mobile, network, cloud, and AI-enabled environments. You lead audit projects, simulate realistic attacks, and collaborate with Blue Team to boost detection and response. You’ll build custom tools and automation, producing clear risk-focused reports for technical and business audiences. Join a hands-on team that operates in Red and Purple Team contexts to help organizations understand and mitigate their weaknesses.

Compensaciones / Beneficios
  • Hybrid working model
  • 8 weeks teleworking per year
  • flexible start/end times
  • career plan development and training
  • relocation package
  • health, dental and accident insurance
Responsabilidades
  • Lead penetration tests in complex corporate environments
  • Participate in Red Team exercises and evasion testing against EDR, XDR, WAF, and antivirus tools
  • Identify vulnerabilities, quantify risk, and propose mitigations
  • Develop or adapt offensive tooling and automation (Python, Bash, PowerShell)
  • Produce clear technical and executive risk reports
  • Present findings to technical and business audiences
  • Manage audit projects including scope, timelines, and deliverables
Requisitos principales
  • 3+ years of penetration testing experience (web, mobile, network, cloud, Active Directory, Wi-Fi)
  • Experience in Red Team operations and simulated attacks
  • Advanced knowledge of Burp Suite, Nmap, Metasploit or C2 frameworks
  • Scripting ability (Python, Bash or PowerShell) to automate offensive tasks
  • Experience producing risk-focused technical and executive reports
  • Strong communication and presentation skills
  • Experience managing cybersecurity or technical audit projects
  • Offensive certifications (OSCP, OSEP, OSWE, eCPPT, CRTP or equivalent)
  • Knowledge of PTES, MITRE ATT&CK or OWASP
  • Experience assessing security in AI/LLM-based systems (OWASP Top 10 for LLMs)
  • Strong communication
  • Independent, self-driven leadership
  • Cross-functional collaboration
  • Burp Suite
  • Nmap
  • Metasploit