Penetration Tester (Mid+/ Senior)

UnderDefense
France
22 days ago
Apply on fr.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Working hours
Regular working hours
Languages
English
Job source

Tech stack

.NET Framework Microsoft Windows Active Directory Artificial Intelligence Apple IOS Apple Mac Systems Software System Penetration Testing C++ (Programming Language) Cloud Computing Linux Python (Programming Language) Red Team (Cyber Security)
+1 more
Vulnerability Analysis

Job description

  • Independently own and deliver Red Team engagements end-to-end (planning, execution, reporting, client delivery).
  • Take on complex projects across Mobile, Desktop and IoT
  • Develop custom implants, beacons and exploits for Windows/Mac when engagements require it.
  • Create detailed reports explaining technical and logical findings, business risk and prioritized recommendations.
  • Share expertise: run lessons-learned, internal lectures and knowledge sharing
  • Act as a role model by example - take the initiative, dig in, take ownership.
  • Collaborate closely with the team and contribute to continuous improvement of teampentest capabilities.
  • Think outside the box and simulate real adversarial approaches.

What we offer:

  • Growth, really fast growth
  • Good salary + really challengeable projects
  • Brilliant Team
  • Flexible working hours
  • Paid vacation and sick-leaves
  • Internal training and workshop (conferences, workshops, training, etc.)
  • English courses
  • Work-rest balance support ( foosball, workout station)

Requirements

We are looking for bright and self-motivated individuals to join our technical team. Someone who is passionate about Security as we are., * Red Team (core): hands-on experience with C2 frameworks; base in exploit development and writing implants/beacons for C2.

  • Deep Internal / Active Directory penetration testing.
  • OPSEC techniques and understanding of how SOC and defensive mechanisms work - and how to evade them.
  • Mobile, Desktop, IoT (willing to cover): general testing techniques; understanding of Windows/Linux/MacOS/iOS/Android internals and system-level vulnerabilities; for IoT - protocols plus basic hardware skills (disassemble a board, solder).
  • Cloud: understanding of cloud infrastructure, privileges and related attack vectors.
  • Business-logic vulnerabilities: proven experience and breadth in finding non-standard logic flaws.
  • Deep adoption of AI tooling (own setups, MCP; AI integrated into the workflow - not surface-level use).
  • English sufficient to independently present a report to the client and answer questions.
  • Web is not the core focus but assumed by default at this level.

Preferred Experience: OSCP / CRTO / OSEP or other related offensive-security certifications; ability to code in Python, C/C++, .NET or similar.

About the company

UnderDefense is a fast-growing company that safeguards businesses around the globe from cybersecurity threats. We are a globally top-ranked firm by Gartner and Clutch, provide cyber resiliency consulting and technology-enabled services to anticipate, manage and defend against cyber threats. We empower clients to predict, prevent, detect, and respond to threats. We work with 122 clients in more than 20 countries. We have already detected 38K vulnerabilities before hackers tried to exploit them. We are passionate about making the Internet a Safer to people and businesses.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on fr.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:25 min

Testing the AI generated Apple iOS Flashcards application

MIlan Todorović MIlan Todorović · World Congress 2026 Europe

2:50 min

Electronic diagnostic software tools and factory production flashing

Denis Grahovac · World Congress 2021

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

Videos

See all

Related articles

See all