Pentesting Engineer

Clara Sanchez Lobato
Guadalajara, Spain
19 days ago
Apply on www.jobleads.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Active Directory Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Intrusion Detection and Prevention Mobile Application Software Python (Programming Language) Network Architecture Open Web Application Security Windows PowerShell Red Team (Cyber Security)
+10 more
Web Applications Wireless Networks Working Model 2D Wi-Fi Technology Scripting Computer Networking Systems Google Cloud Cloud Platform System Mitre Att&ck Purple Team (Cyber Security)

Job description

In our team you will participate in penetration testing projects and technical assessments on web and mobile applications, network infrastructures, Wi-Fi networks, cloud environments (AWS, Azure, GCP), and emerging components such as artificial intelligence models. In addition, Red Team exercises will be conducted, oriented to simulate real attacks in a controlled manner, as well as Purple Team exercises, working in coordination with defensive teams to strengthen threat detection, response and will include:

  • Running penetration tests on web applications, mobile, network infrastructure, Wi-Fi networks, cloud environments, artificial intelligence models, etc.
  • Participate in Red Team exercises, simulating real attacks, and Purple Team exercises, collaborating with defensive teams to improve threat detection and response.
  • Identify and report vulnerabilities, proposing technical recommendations for effective with IT and cybersecurity teams in the implementation of security best practices.

Requirements

  • cybersecurity or similar graduates with experience in penetration testing in network infrastructure, web and mobile applications, cloud environments (AWS, Azure, GCP), Active Directory, wireless networks.
  • experience in Red Team exercises, including planning, execution of simulated attacks, evasion techniques, persistence and exploitation in controlled or real environments.
  • Scripting skills (Python, Bash, PowerShell) for automation of offensive tasks.
  • Understanding of methodologies such as PTES, MITRE ATT&CK, OWASP will also be an asset.

Benefits & conditions

  • Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area. Flexible start and finish times, and intensive working hours Fridays and in summer.
  • Personalized career plan development, training and language learning support.
  • National and international mobility.
  • Relocation package for those from another country.
  • Competitive compensation with ongoing reviews, flexible compensation and discount on brands.
  • Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!

In our recruitment processes you will always have telephone and personal contact, face-to-face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.

We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobleads.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all