> Markdown version of [/jobs/ext/2127522-senior-pentester](https://www.wearedevelopers.com/jobs/ext/2127522-senior-pentester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Pentester - **Company:** UST - **Location:** Madrid, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Application Programming Interfaces (APIs), Software System Penetration Testing, Authentication Protocols, Automation of Tests, Burp Suite, Cyber Security, Computer Programming, Continuous Integration, Python (Programming Language), Nmap, Open Web Application Security, Secure Coding, Web Application Security, Web Applications, Scripting, Software Security, GWAPT, Information Technology, Devsecops, Vulnerability Analysis, Microservices - **Published:** August 19, 2026 - **Apply:** https://www.tecnoempleo.com/senior-pentester-ust/burp-suite-nmap/rf-34c712b56229633afd40 ## About the Role Bachelor's degree in Computer Science, Information Security, or equivalent experience - 3-5 years of hands-on experience in: - Penetration testing - Application security - Vulnerability assessment - Strong experience with web application security testing tools (e.g., Burp Suite) - Solid understanding of: - OWASP Top 10 vulnerabilities - Exploitation techniques - Ability to: - Read, understand, and reproduce penetration testing findings - Communicate technical topics to non-technical stakeholders - Knowledge of: - HTTP/S protocols - Authentication mechanisms - Modern web architectures (APIs, microservices) - Strong analytical and problem-solving skills - Professional proficiency in English and Spanish - Eligibility to work in Spain Nice to Have - Certifications such as: - OSCP, eWPT, CEH, GWAPT, Burp Suite Certified Practitioner - Experience: - Reviewing third-party security reports - Working with external testing vendors - Infrastructure/network penetration testing - Secure code review or secure development practices - Programming/scripting skills (e.g., Python, JavaScript) - Experience in financial services or regulated environments - Familiarity with DevSecOps or CI/CD security integration - German language skills ## Description We're looking for a Senior Penetration Tester. You will join a strategic project with a global client in the wealth management sector. As an Exposure Management Technical Expert within our Security Compliance Competence Centre (SCCC) in Madrid, you will play a key hands-on role in strengthening our proactive security testing program. Acting as an internal penetration testing specialist, you will: - Validate external security findings - Ensure technical quality and reproducibility of deliverables - Support the scoping and execution of penetration testing engagements You will collaborate closely with Exposure Managers, application and technology teams, and external vendors to ensure consistent and high-quality testing practices across the organization. Key Responsibilities Penetration Testing & Validation - Reproduce and validate vulnerabilities and their remediation using tools such as Burp Suite and Nmap - Apply manual and automated techniques across web applications, APIs, and infrastructure Technical Quality Assurance - Review penetration testing reports to ensure: - Accuracy - Completeness - Clarity - Reproducibility of findings Scoping & Advisory - Support risk-based scoping of penetration testing engagements - Act as a technical advisor on: - Security testing methodologies - Findings interpretation - Remediation strategies Security Standards & Best Practices - Ensure alignment with: - OWASP Testing Guide - OWASP Top 10 - Internal security standards False Positive & Risk Management - Analyze reported vulnerabilities and identify false positives - Ensure correct classification and prioritization Remediation & Hardening - Provide technical guidance to development and infrastructure teams - Collaborate with architects on secure and resilient baseline configurations Collaboration & Knowledge Sharing - Work closely with Exposure Managers and global technical teams - Share insights, patterns, and lessons learned to improve internal practices - Support consistent execution across all penetration testing activities ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)