Pentesting cibersecurity engineer - GMV
5 days ago
Tres Cantos
Overview In this Senior Pentester role, you design and execute advanced offensive security assessments across web, mobile, network, cloud, and AI-enabled environments. You lead audit projects, simulate realistic attacks, and collaborate with Blue Team to boost detection and response. You’ll build custom tools and automation, producing clear risk-focused reports for technical and business audiences. Join a hands-on team that operates in Red and Purple Team contexts to help organizations understand and mitigate their weaknesses. Compensaciones / Beneficios • Hybrid working model, • 8 weeks teleworking per year, • flexible start/end times, • career plan development and training, • relocation package, • health, dental and accident insurance Responsabilidades, • Lead penetration tests in complex corporate environments, • Participate in Red Team exercises and evasion testing against EDR, XDR, WAF, and antivirus tools, • Identify vulnerabilities, quantify risk, and propose mitigations, • Develop or adapt offensive tooling and automation (Python, Bash, PowerShell), • Produce clear technical and executive risk reports, • Present findings to technical and business audiences, • Manage audit projects including scope, timelines, and deliverables Requisitos principales, • 3+ years of penetration testing experience (web, mobile, network, cloud, Active Directory, Wi-Fi), • Experience in Red Team operations and simulated attacks, • Advanced knowledge of Burp Suite, Nmap, Metasploit or C2 frameworks, • Scripting ability (Python, Bash or PowerShell) to automate offensive tasks, • Experience producing risk-focused technical and executive reports, • Strong communication and presentation skills, • Experience managing cybersecurity or technical audit projects, • Offensive certifications (OSCP, OSEP, OSWE, eCPPT, CRTP or equivalent), • Knowledge of PTES, MITRE ATT&CK or OWASP, • Experience assessing security in AI/LLM-based systems (OWASP Top 10 for LLMs), • Strong communication, • Independent, self-driven leadership, • Cross-functional collaboration, • Burp Suite, • Nmap, • Metasploit