Senior Pentester | Madrid

Ust
Madrid, Spain
26 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

JavaScript (Programming Language) Application Programming Interfaces (APIs) Software System Penetration Testing Automation of Tests Burp Suite Code Review Cyber Security Continuous Integration Digital Technology Python (Programming Language) Open Web Application Security Secure Coding
+8 more
Web Application Security Web Applications Scripting GWAPT Information Technology Devsecops Vulnerability Analysis Microservices

Job description

Role DescriptionWe are looking for the very Top Talent…and we would be delighted if you were to join our team!More in details, UST is a multinational company based in North America, certified as a Top Employer company with over ** employees all over the world and presence in more than 30 countries.We are leaders on digital technology services, and we provide large-scale technologic solutions to big companies.What are we looking for?We’re looking for an Senior Penetration Tester.You will join a strategic project with a global client in the wealth management sector.As an Exposure Management Technical Expert within our Security Compliance Competence Centre (SCCC) in Madrid, you will play a key hands?on role in strengthening our proactive security testing program.Acting As An Internal Penetration Testing Specialist, You WillValidate external security findingsEnsure technical quality and reproducibility of deliverablesSupport the scoping and execution of penetration testing engagementsYou will collaborate closely with Exposure Managers, application and technology teams, and external vendors to ensure consistent and high-quality testing practices across the organization.Key ResponsibilitiesPenetration Testing & ValidationReproduce and validate vulnerabilities and their remediation using tools such as Burp Suite and NmapApply manual and automated techniques across web applications, APIs, and infrastructureTechnical Quality AssuranceReview penetration testing reports to ensure:AccuracyCompletenessClarityReproducibility of findingsScoping & AdvisorySupport risk-based scoping of penetration testing engagementsAct as a technical advisor on:Security testing methodologiesFindings interpretationRemediation strategiesSecurity Standards & Best PracticesEnsure alignment with:OWASP Testing GuideOWASP Top 10Internal security standardsFalse Positive & Risk ManagementAnalyze reported vulnerabilities and identify false positivesEnsure correct classification and prioritizationRemediation & HardeningProvide technical guidance to development and infrastructure teamsCollaborate with architects on secure and resilient baseline configurationsCollaboration & Knowledge SharingWork closely with Exposure Managers and global technical teamsShare insights, patterns, and lessons learned to improve internal practicesSupport consistent execution across all penetration testing activitiesYour ProfileRequired QualificationsBachelor’s degree in Computer Science, Information Security, or equivalent experience3-5 years of hands?on experience in:Penetration testingApplication securityVulnerability assessmentStrong experience with web application security testing tools (e.G., Burp Suite)Solid understanding of:OWASP Top 10 vulnerabilitiesExploitation techniquesAbility to:Read, understand, and reproduce penetration testing findingsCommunicate technical topics to non-technical stakeholdersKnowledge of:HTTP/S protocolsAuthentication mechanismsModern web architectures (APIs, microservices)Strong analytical and problem-solving skillsProfessional proficiency in English and SpanishEligibility to work in SpainNice to HaveCertifications such as:OSCP, eWPT, CEH, GWAPT, Burp Suite Certified PractitionerExperience:Reviewing third-party security reportsWorking with external testing vendorsInfrastructure/network penetration testingSecure code review or secure development practicesProgramming/scripting skills (e.G., Python, JavaScript)Experience in financial services or regulated environmentsFamiliarity with DevSecOps or CI/CD security integrationGerman language skillsLocation: Hybrid.Madrid city centre (Sol area).3 days a week in the office.What can we offer?23 days of Annual Leave plus the 24th and 31st of December as discretionary days!Numerous benefits (Health Care Plan, teleworking compensation, Life and Accident Insurances).R?S Program: (Meals, Kinder Garden, Transport, online English lessons, Health Care Plan…)Free access to several training platformsProfessional stability and career plansUST also, compensates referrals from which you could benefit when you refer professionals.The option to pick between 12 or 14 payments along the year.Real Work Life Balance measures (flexibility, WFH or remote work policy, compacted hours during summertime…)UST Club Platform discounts and gym Access discountsIn UST we are committed to equal opportunities in our selection processes and do not discriminate based on race, gender, disability, age, religion, sexual orientation or nationality.We have a special commitment to Disability & Inclusion, so we are interested in hiring people with disability certificate.SkillsApplication Security, Vulnerability Assessment and Penetration Testing, Burp Suite, Vulnerability Assessment#J-*****-Ljbffr

Requirements

to ensure:AccuracyCompletenessClarityReproducibility of findingsScoping & AdvisorySupport risk-based scoping of penetration testing engagementsAct as a technical advisor on:Security testing methodologiesFindings interpretationRemediation strategiesSecurity Standards & Best PracticesEnsure alignment with:OWASP Testing GuideOWASP Top 10Internal security standardsFalse Positive & Risk ManagementAnalyze reported vulnerabilities and identify false positivesEnsure correct classification and prioritizationRemediation & HardeningProvide technical guidance to development and infrastructure teamsCollaborate with architects on secure and resilient baseline configurationsCollaboration & Knowledge SharingWork closely with Exposure Managers and global technical teamsShare insights, patterns, and lessons learned to improve internal practicesSupport consistent execution across all penetration testing activitiesYour ProfileRequired QualificationsBachelor’s degree in Computer Science, Information Security, or equivalent experience3-5 years of hands?on experience in:Penetration testingApplication securityVulnerability assessmentStrong experience with web application security testing tools (e.G., Burp Suite)Solid understanding of:OWASP Top 10 vulnerabilitiesExploitation techniquesAbility to:Read, understand, and reproduce penetration testing findingsCommunicate technical topics to non-technical stakeholdersKnowledge of:HTTP/S protocolsAuthentication mechanismsModern web architectures (APIs, microservices)Strong analytical and problem-solving skillsProfessional proficiency in English and SpanishEligibility to work in SpainNice to HaveCertifications such as:OSCP, eWPT, CEH, GWAPT, Burp Suite Certified PractitionerExperience:Reviewing third-party security reportsWorking with external testing vendorsInfrastructure/network penetration testingSecure code review or secure development practicesProgramming/scripting skills (e.G., Python, JavaScript)Experience in financial services or regulated environmentsFamiliarity with DevSecOps or CI/CD security integrationGerman language skillsLocation: Hybrid.

Benefits & conditions

3 days a week in the office.What can we offer? 23 days of Annual Leave plus the 24th and 31st of December as discretionary days! Numerous benefits (Health Care Plan, teleworking compensation, Life and Accident Insurances). R?S Program: (Meals, Kinder Garden, Transport, online English lessons, Health Care Plan…)Free access to several training platformsProfessional stability and career plansUST also, compensates referrals from which you could benefit when you refer professionals.The option to pick between 12 or 14 payments along the year.Real Work Life Balance measures (flexibility, WFH or remote work policy, compacted hours during summertime…)UST Club Platform discounts and gym Access discountsIn UST we are committed to equal opportunities in our selection processes and do not discriminate based on race, gender, disability, age, religion, sexual orientation or nationality. We have a special commitment to Disability & Inclusion, so we are interested in hiring people with disability certificate.SkillsApplication Security, Vulnerability Assessment and Penetration Testing, Burp Suite, Vulnerability Assessment#J-*****-Ljbffr

About the company

Madrid, España

Role DescriptionWe are looking for the very Top Talent…and we would be delighted if you were to join our team! More in details, UST is a multinational company based in North America, certified as a Top Employer company with over ** employees all over the world and presence in more than 30 countries. We are leaders on digital technology services, and we provide large-scale technologic solutions to big companies.What are we looking for? We’re looking for an Senior Penetration Tester.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:17 min

Evaluating security vulnerabilities and user experience

Julian Richter Julian Richter · World Congress 2025

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all