> Markdown version of [/jobs/ext/2929000-senior-pentester-tres-cantos](https://www.wearedevelopers.com/jobs/ext/2929000-senior-pentester-tres-cantos). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Pentester - Tres Cantos - **Company:** Gmv - **Location:** Madrid, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Bash Shell, Burp Suite, Cloud Computing, Python (Programming Language), Nmap, Open Web Application Security, Windows PowerShell, Red Team (Cyber Security), Wi-Fi Technology, Scripting, Large Language Models, Mitre Att&ck, Metasploit, Purple Team (Cyber Security) - **Published:** September 16, 2026 - **Apply:** https://www.buscojobs.com.es/senior-pentester-tres-cantos-en-madrid-ID-372127778 ## About the Role Experience in Red Team operations Advanced knowledge of Burp Suite, Nmap, Metasploit or C2 frameworks Automation of offensive tasks via scripting (Python, Bash, PowerShell) Experience producing technical and executive risk reports Strong communication and clear presentation of results Experience managing cybersecurity or technical audit projects Offensive certifications (OSCP, OSEP, OSWE, eCPPT, CRTP or equivalent) Knowledge of PTES, MITRE ATT&CK, OWASP Experience assessing security in AI/LLM-based systems (OWASP Top 10 for LLMs) Strong communication Independent leadership Cross-functional collaboration Burp Suite Nmap Metasploit ## Description OverviewAs a Senior Pentester, you will lead offensive security assessments and design realistic attack scenarios using MITRE ATT&CK, guiding audit projects for organizations aiming to understand vulnerabilities before real attackers exploit them.You will work across web, mobile, network, cloud, AD, and AI-based systems, and participate in Red Team and Purple Team exercises to boost detection and response.You will translate findings into practical mitigation and contribute to risk-focused reports for technical and business audiences.This role offers collaboration with cross-functional teams and a chance to shape security practices at scale.Compensaciones / Beneficioshybrid work modelremote work up to 8 weeks/yearflexible working hoursrelocation packagetraining opportunitieswellbeing programResponsabilidadesLead penetration tests in complex corporate environmentsParticipate in Red Team exercises and apply evasion against EDR, XDR, WAF, and AVsIdentify vulnerabilities, assess impact and propose mitigationsDevelop or adapt offensive tools and automations (Python, Bash, PowerShell)Produce technical and executive risk-focused reportsPresent findings to technical and business audiencesManage audit projects, including scope, timelines and deliverablesRequisitos principales5+ years in penetration testing (web, mobile, network, cloud, AD, Wi-Fi)Experience in Red Team operationsAdvanced knowledge of Burp Suite, Nmap, Metasploit or C2 frameworksAutomation of offensive tasks via scripting (Python, Bash, PowerShell)Experience producing technical and executive risk reportsStrong communication and clear presentation of resultsExperience managing cybersecurity or technical audit projectsOffensive certifications (OSCP, OSEP, OSWE, eCPPT, CRTP or equivalent)Knowledge of PTES, MITRE ATT&CK, OWASPExperience assessing security in AI/LLM-based systems (OWASP Top 10 for LLMs)Strong communicationIndependent leadershipCross-functional collaborationBurp SuiteNmapMetasploit ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss)