> Markdown version of [/jobs/ext/2886728-junior-penetration-tester-ethical-hacker-security-tester](https://www.wearedevelopers.com/jobs/ext/2886728-junior-penetration-tester-ethical-hacker-security-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior Penetration Tester / Ethical Hacker / Security Tester - **Company:** Squad Conseil Et Expertises - **Location:** Oña, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Software System Penetration Testing, Automation of Tests, Bash Shell, Cyber Security, Mobile Application Software, Python (Programming Language), Open Web Application Security, Software Vulnerability Management, Web Applications, Scripting - **Published:** September 13, 2026 - **Apply:** https://www.buscojobs.com.es/junior-penetration-tester-ethical-hacker-security-tester-m-w-d-en-ona-ID-371210023 ## About the Role 3 years of experience in Cybersecurity, including at least 1 year dedicated to application penetration testing. ~ Solid understanding of web application vulnerabilities (injection, authN/authZ flaws, SSRF, IDOR, etc.) Basic scripting ability (Python or Bash) to support testing and automation. ~ Fluent professional English, spoken and written - required for client-facing missions and report writing. ~ Comfortable working independently on long missions while staying aligned with senior pentesters and client stakeholders. Personalized Growth: We help you build a training and certification plan aligned with your professional goals through our SquadExeperience Visibility: Attend major industry conferences and contribute to our #TheExpert technical blog ## Description Junior Penetration Tester | 100% REMOTE - Spain Since ****, SQUAD Group has been a key player in the cybersecurity landscape.We believe in a collaborative approach to cybersecurity, where experts and clients work hand-in-hand to anticipate threats and protect critical infrastructure.As part of our growing team, we're seeking a Senior Security Engineer specialising in Vulnerability Management.Based in Barcelona, this role will put you at the heart of a high-impact security engineering function, building and operating the systems that keep complex, large-scale environments continuously protected.You are a hands-on, curious security tester joining a pentest practice focused on web, mobile, and API applications.Working alongside senior pentesters on long-running client missions, you'll conduct hands-on assessments, document findings clearly, and grow into more autonomous engagements over time.Conduct penetration tests on web applications, APIs, and mobile apps, following OWASP methodologies (OWASP Top 10, ASVS, MASVS).Write clear, well-structured pentest reports and executive summaries in English for international clients.Work on long-duration client missions, maintaining consistent quality and communication throughout the engagement.3 years of experience in Cybersecurity, including at least 1 year dedicated to application penetration testing.~ Solid understanding of web application vulnerabilities (injection, authN/authZ flaws, SSRF, IDOR, etc.) Basic scripting ability (Python or Bash) to support testing and automation.~ Fluent professional English, spoken and written - required for client-facing missions and report writing.~ Comfortable working independently on long missions while staying aligned with senior pentesters and client stakeholders.Personalized Growth: We help you build a training and certification plan aligned with your professional goals through our SquadExeperience Visibility: Attend major industry conferences and contribute to our #TheExpert technical blog ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)