Penetration Tester / Security Tester

Squad Conseil Et Expertises
Ciudad Real, Spain
13 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Working hours
Regular working hours
Languages
English

Tech stack

Application Programming Interfaces (APIs) Software System Penetration Testing Automation of Tests Bash Shell Cyber Security Mobile Application Software Python (Programming Language) Open Web Application Security Software Vulnerability Management Web Applications Scripting

Job description

Junior Penetration Tester 100% REMOTE - Spain Since **, SQUAD Group has been a key player in the cybersecurity landscape.We believe in a collaborative approach to cybersecurity, where experts and clients work hand-in-hand to anticipate threats and protect critical infrastructure.As part of our growing team, we’re seeking a Senior Security Engineer specialising in Vulnerability Management.Based in Barcelona, this role will put you at the heart of a high-impact security engineering function, building and operating the systems that keep complex, large-scale environments continuously protected.You are a hands-on, curious security tester joining a pentest practice focused on web, mobile, and API applications.Working alongside senior pentesters on long-running client missions, you’ll conduct hands-on assessments, document findings clearly, and grow into more autonomous engagements over time.Conduct penetration tests on web applications, APIs, and mobile apps, following OWASP methodologies (OWASP Top 10, ASVS, MASVS).Write clear, well-structured pentest reports and executive summaries in English for international clients.Work on long-duration client missions, maintaining consistent quality and communication throughout the engagement.3 years of experience in Cybersecurity, including at least 1 year dedicated to application penetration testing.~ Solid understanding of web application vulnerabilities (injection, authN/authZ flaws, SSRF, IDOR, etc.) Basic scripting ability (Python or Bash) to support testing and automation.~ Fluent professional English, spoken and written - required for client-facing missions and report writing.~ Comfortable working independently on long missions while staying aligned with senior pentesters and client stakeholders.Personalized Growth: We help you build a training and certification plan aligned with your professional goals through our SquadExeperience Visibility: Attend major industry conferences and contribute to our #TheExpert technical blog

Requirements

3 years of experience in Cybersecurity, including at least 1 year dedicated to application penetration testing. ~ Solid understanding of web application vulnerabilities (injection, authN/authZ flaws, SSRF, IDOR, etc.) Basic scripting ability (Python or Bash) to support testing and automation. ~ Fluent professional English, spoken and written - required for client-facing missions and report writing. ~ Comfortable working independently on long missions while staying aligned with senior pentesters and client stakeholders. Personalized Growth: We help you build a training and certification plan aligned with your professional goals through our SquadExeperience Visibility: Attend major industry conferences and contribute to our #TheExpert technical blog

About the company

Junior Penetration Tester | 100% REMOTE - Spain Since **, SQUAD Group has been a key player in the cybersecurity landscape. We believe in a collaborative approach to cybersecurity, where experts and clients work hand-in-hand to anticipate threats and protect critical infrastructure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:17 min

Evaluating security vulnerabilities and user experience

Julian Richter Julian Richter · World Congress 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all