Penetration Tester (Hybrid Set Up)

Swiss Re.
Madrid, Spain
6 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
2 years minimum
Compensation
€42,000.0
Working hours
Regular working hours
Languages
English

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Software System Penetration Testing Burp Suite Cyber Security Digital Assets Nmap Open Web Application Security Software Engineering Software Vulnerability Management Web Applications Application Enhancement Tool
+3 more
Large Language Models Information Technology Qualys

Job description

Join a team of cybersecurity professionals and help Swiss Re fulfil its mission to make the world more resilient.As the Penetration Tester, you will improve and develop the strategy of penetration testing within Swiss Re, ensuring security assessments of web applications and APIs are delivered and remediations are coordinated and fulfilled.What’s more, you’ll be working in a hybrid setup, perfectly balancing work from home and the office premises.About The TeamThe Penetration Testing team simulates real-world cyberattacks on Swiss Re’s computer systems, networks, applications, services and platforms.As part of the Group Security & Technology Platforms (GSTP) division, the team detects security weaknesses and fixes them before malicious hackers can exploit them.We’re looking for an experienced Penetration Tester who’s ready to help us protect our digital assets through comprehensive testing, research, fixing and reporting.About The RoleNobody is perfect and meets 100% of our requirements.If you, however, meet some of the criteria below and are curious about the world of penetration testing inside a large reinsurance company, we’ll be more than happy to meet you!Continuously improve existing processes and develop long-term strategy for the penetration testing serviceEfficiently own, perform and deliver security assessments of web applications, APIs and infrastructure penetration reports, and coordinate the remediation of all findings and recommendationsCompile "lessons-learnt" sessions and educational material for IT developers and other relevant partiesManage relations with internal partners and external security companies providing penetration testsCooperate closely with global teams from IT application owners, information security specialists and chief information security officersBe someone who believes in continuous innovation, is curious and relentless in finding a better way every dayUse your knowledge of Open Web Application Security Project (OWASP) Top 10 Vulnerabilities, testing procedures and remediation recommendationsYour QualificationsAt least 2 years of experience in information security and penetration testingGood understanding of software development and architectureSound understanding of security frameworks (ISO**, NIST, OWASP Top 10)Experience with vulnerability management and penetration testing tools (Burp Suite, nmap, Qualys, etc.)Exposure to AI/LLM security concepts or a strong interest in learning about securing AI-enabled applications and agentic systemsAnalytical thinking, structured approach to address complex mattersAbility to communicate complex technical concepts clearly and unambiguously to both business and technical audiencesGood communication and writing skills; proficiency in English is required, other languages are a plusYou are a phenomenal teammate, results-oriented, focused and fond of international professional relationshipsYou are curious, like to drive things forward, raise your voice for improvement and possess a great interest in learning new thingsNice-to-haveIndustry-relevant certifications (SANS, CEH, Offensive Security, eLearn Security, etc.)Familiarity with the OWASP Top 10 for LLM Applications, prompt injection risks, AI security testingRoleFor Spain the base salary range for this position is between EUR 42,000 and EUR 70,000 (for a full-time role).The specific salary offered considers:the requirements, scope, complexity and responsibilities of the role,the applicant’s own profile including education/qualifications, expertise, specialisation, skills and experience.In the situation where you do not meet all the requirements or you significantly exceed these, the offered salary may be below or above the advertised range.In addition to your base salary, you may be eligible for additional rewards and benefits including an attractive performance-based bonus.About Swiss ReSwiss Re is one of the world’s leading providers of reinsurance, insurance and other forms of insurance-based risk transfer, working to make the world more resilient.We anticipate and manage a wide variety of risks, from natural catastrophes and climate change to cybercrime.Combining experience with creative thinking and cutting-edge expertise, we create new opportunities and solutions for our clients.This is possible thanks to the collaboration of more than 15,000 employees across the world.Our success depends on our ability to build an inclusive culture encouraging fresh perspectives and innovative thinking.We embrace a workplace where everyone has equal opportunities to thrive and develop professionally regardless of their age, gender, race, ethnicity, gender identity and/or expression, sexual orientation, physical or mental ability, skillset, thought or other characteristics.In our inclusive and flexible environment everyone can bring their authentic selves to work and their passion for sustainability.If you are an experienced professional returning to the workforce after a career break, we encourage you to apply for open positions that match your skills and experience.We may use AI-powered tools to support the review and evaluation of applications for this position.These tools provide additional insights to our recruitment teams, but all hiring decisions are carefully reviewed and made by people.To learn more about how we use AI in recruitment and how we handle your personal data, please review our Data Privacy Statement before applying.KeywordsReference Code: **#J-**-Ljbffr

Requirements

Continuously improve existing processes and develop long-term strategy for the penetration testing serviceEfficiently own, perform and deliver security assessments of web applications, APIs and infrastructure penetration reports, and coordinate the remediation of all findings and recommendationsCompile "lessons-learnt" sessions and educational material for IT developers and other relevant partiesManage relations with internal partners and external security companies providing penetration testsCooperate closely with global teams from IT application owners, information security specialists and chief information security officersBe someone who believes in continuous innovation, is curious and relentless in finding a better way every dayUse your knowledge of Open Web Application Security Project (OWASP) Top 10 Vulnerabilities, testing procedures and remediation recommendationsYour QualificationsAt least 2 years of experience in information security and penetration testingGood understanding of software development and architectureSound understanding of security frameworks (ISO***, NIST, OWASP Top 10)Experience with vulnerability management and penetration testing tools (Burp Suite, nmap, Qualys, etc.)Exposure to AI/LLM security concepts or a strong interest in learning about securing AI-enabled applications and agentic systemsAnalytical thinking, structured approach to address complex mattersAbility to communicate complex technical concepts clearly and unambiguously to both business and technical audiencesGood communication and writing skills; proficiency in English is required, other languages are a plusYou are a phenomenal teammate, results-oriented, focused and fond of international professional relationshipsYou are curious, like to drive things forward, raise your voice for improvement and possess a great interest in learning new thingsNice-to-haveIndustry-relevant certifications (SANS, CEH, Offensive Security, eLearn Security, etc.)Familiarity with the OWASP Top

About the company

The specific salary offered considers:the requirements, scope, complexity and responsibilities of the role,the applicant’s own profile including education/qualifications, expertise, specialisation, skills and experience.In the situation where you do not meet all the requirements or you significantly exceed these, the offered salary may be below or above the advertised range.In addition to your base salary, you may be eligible for additional rewards and benefits including an attractive performance-based bonus.About Swiss ReSwiss Re is one of the world’s leading providers of reinsurance, insurance and other forms of insurance-based risk transfer, working to make the world more resilient. We anticipate and manage a wide variety of risks, from natural catastrophes and climate change to cybercrime. Combining experience with creative thinking and cutting-edge expertise, we create new opportunities and solutions for our clients. This is possible thanks to the collaboration of more than 15,000 employees across the world.Our success depends on our ability to build an inclusive culture encouraging fresh perspectives and innovative thinking. We embrace a workplace where everyone has equal opportunities to thrive and develop professionally regardless of their age, gender, race, ethnicity, gender identity and/or expression, sexual orientation, physical or mental ability, skillset, thought or other characteristics. In our inclusive and flexible environment everyone can bring their authentic selves to work and their passion for sustainability.If you are an experienced professional returning to the workforce after a career break, we encourage you to apply for open positions that match your skills and experience.We may use AI-powered tools to support the review and evaluation of applications for this position. These tools provide additional insights to our recruitment teams, but all hiring decisions are carefully reviewed and made by people. To learn more about how we use AI in recruitment and how we handle your personal data, please review our Data Privacy Statement before applying.KeywordsReference Code: ** #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

1:51 min

Leveraging continuous penetration testing via red teams

Reto Kaeser · LIVE

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

Videos

See all

Related articles

See all