Pentesting Engineer - Gmv

Gmv
Madrid, Spain
5 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work

Tech stack

Active Directory Artificial Intelligence Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Cloud Computing Python (Programming Language) Open Web Application Security Windows PowerShell Red Team (Cyber Security) Web Applications
+7 more
Wireless Networks Working Model 2D Scripting Google Cloud Cloud Platform System Mitre Att&ck Purple Team (Cyber Security)

Job description

OverviewAs a Pentesting Engineer at GMV, you will conduct pen-testing and security assessments across web, mobile, network, and cloud environments, including AI models.You will engage in Red Team exercises to simulate real attacks and Purple Team collaborations to strengthen detection and response.You report vulnerabilities and propose mitigations while aligning with IT and security teams to enforce best practices.The role offers hybrid work, international mobility, and a mission-driven environment focused on defense and threat remediation.Compensaciones / BeneficiosHybrid working modelTeleworking up to 8 weeks/yearFlexible start/finish timesRelocation packageCompetitive compensation with reviewsWellbeing program (health, dental, mental health, training)ResponsabilidadesPerform penetration tests on web applications, mobile apps, networks, Wi?Fi, cloud environments, and AI modelsParticipate in Red Team exercises to simulate attacks and Purple Team activities with defensive teamsIdentify vulnerabilities and provide actionable remediation recommendationsCollaborate with IT and cybersecurity teams to implement security best practicesRequisitos principalesCybersecurity or related degree with hands-on pentesting experience in networks, web/mobile apps, cloud (AWS, Azure, GCP), Active Directory, and wireless networksExperience in Red Team exercises including planning, executing simulated attacks, evasion, persistence, and exploitationScripting skills (Python, Bash, PowerShell) for automation of offensive tasksKnowledge of PTES, MITRE ATT&CK, OWASP (asset)Team collaborationStrong communicationProblem solvingPenetration testingCloud environments (AWS, Azure, GCP)Active Directory

Requirements

Requisitos principalesCybersecurity or related degree with hands-on pentesting experience in networks, web/mobile apps, cloud (AWS, Azure, GCP), Active Directory, and wireless networks Experience in Red Team exercises including planning, executing simulated attacks, evasion, persistence, and exploitation Scripting skills (Python, Bash, PowerShell) for automation of offensive tasks Knowledge of PTES, MITRE ATT&CK, OWASP (asset) Team collaboration Strong communication Problem solving Penetration testing Cloud environments (AWS, Azure, GCP) Active Directory

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:19 min

Enhancing product safety through continual red teaming operations

Rebekka Weiss Rebekka Weiss +1 · World Congress 2025

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all