Senior Penetration Tester | Madrid

UST España
Coslada, Spain
4 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Application Programming Interfaces (APIs) Software System Penetration Testing Authentication Protocols Burp Suite Cloud Computing Digital Technology Hypertext Transfer Protocols (HTTP) Nmap Open Web Application Security Web Application Security Web Applications Software Security
+2 more
GWAPT Metasploit

Job description

We are looking for the very Top Talent…and we would be delighted if you were to join our team!La siguiente información ofrece un resumen de las habilidades, cualidades y cualificaciones necesarias para este puesto.More in details, UST is a multinational company based in North America, certified as a Top Employer company with over ** employees all over the world and presence in more than 30 countries.We are leaders on digital technology services, and we provide large-scale technologic solutions to big companies.What are we looking for?We are looking for a Senior Penetration Tester to join a strategic cybersecurity project with a global client in the wealth management sector.As part of our Security Compliance Competence Centre (SCCC) in Madrid, you will play a key hands-on role in identifying, exploiting, and assessing security vulnerabilities across applications, APIs, infrastructure, and cloud environments.You will work closely with security teams, developers, architects, and business stakeholders to strengthen the organization’s security posture through proactive offensive security activities and expert security assessments.Location: Hybrid.Madrid city center (Sol area).3 days a week in the office.Language: English is a must.Spanish desirable.Key ResponsibilitiesPerform manual and automated penetration testing on web applications, APIs, and infrastructure.Identify, validate, and reproduce security vulnerabilities and attack scenarios.Assess the technical and business impact of security findings.Provide remediation recommendations and support security improvements.Apply OWASP-based methodologies and industry security best practices.Collaborate with security, development, and infrastructure teams to strengthen the organization’s security posture.Required Qualifications+5 years of hands-on experience in Penetration Testing, Ethical Hacking, or Application Security.Strong knowledge of OWASP Top 10, web application security, and exploitation techniques.Experience with tools such as Burp Suite, Nmap, OWASP ZAP, or Metasploit.Familiarity with APIs, authentication mechanisms, HTTP/S, and modern web architectures.Strong analytical, troubleshooting, and communication skills.Professional proficiency in English; certifications such as OSCP, eWPT, CEH, or GWAPT are a plus.What can we offer?23 days of Annual Leave plus the 24th and 31st of December as discretionary days!Numerous benefits (Health Care Plan, teleworking compensation, Life and Accident Insurances).`Retribución Flexible ? Program: (Meals, Kinder Garden, Transport, online English lessons, Health Care Plan…)Free access to several training platformsProfessional stability and career plansUST also, compensates referrals from which you could benefit when you refer professionals.The option to pick between 12 or 14 payments along the year.Real Work Life Balance measures (flexibility, WFH or remote work policy, compacted hours during summertime…)UST Club Platform discounts and gym Access discountsIf you would like to know more, don’t hesitate to apply and we’ll get in touch to fill you in detail.We are waiting for you!In UST we are committed to equal opportunities in our selection processes and do not discriminate based on race, gender, disability, age, religion, sexual orientation or nationality.xqysrnh We have a special commitment to Disability & Inclusion, so we are interested in hiring people with disability certificate.

Requirements

+5 years of hands-on experience in Penetration Testing, Ethical Hacking, or Application Security. Strong knowledge of OWASP Top 10, web application security, and exploitation techniques. Experience with tools such as Burp Suite, Nmap, OWASP ZAP, or Metasploit. Familiarity with APIs, authentication mechanisms, HTTP/S, and modern web architectures. Strong analytical, troubleshooting, and communication skills. Professional proficiency in English; certifications such as OSCP, eWPT, CEH, or GWAPT are a plus.

Benefits & conditions

23 days of Annual Leave plus the 24th and 31st of December as discretionary days! Numerous benefits (Health Care Plan, teleworking compensation, Life and Accident Insurances). `Retribución Flexible ? Program: (Meals, Kinder Garden, Transport, online English lessons, Health Care Plan…) Free access to several training platforms Professional stability and career plans UST also, compensates referrals from which you could benefit when you refer professionals. The option to pick between 12 or 14 payments along the year. Real Work Life Balance measures (flexibility, WFH or remote work policy, compacted hours during summertime…) UST Club Platform discounts and gym Access discounts If you would like to know more, don’t hesitate to apply and we’ll get in touch to fill you in detail. We are waiting for you! In UST we are committed to equal opportunities in our selection processes and do not discriminate based on race, gender, disability, age, religion, sexual orientation or nationality. xqysrnh We have a special commitment to Disability & Inclusion, so we are interested in hiring people with disability certificate.

About the company

Coslada, Madrid, España

We are looking for the very Top Talent…and we would be delighted if you were to join our team! La siguiente información ofrece un resumen de las habilidades, cualidades y cualificaciones necesarias para este puesto. More in details, UST is a multinational company based in North America, certified as a Top Employer company with over ** employees all over the world and presence in more than 30 countries. We are leaders on digital technology services, and we provide large-scale technologic solutions to big companies. What are we looking for? We are looking for a Senior Penetration Tester to join a strategic cybersecurity project with a global client in the wealth management sector. As part of our Security Compliance Competence Centre (SCCC) in Madrid, you will play a key hands-on role in identifying, exploiting, and assessing security vulnerabilities across applications, APIs, infrastructure, and cloud environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:31 min

Setting up a penetration testing environment for web apps

Anna Bacher · LIVE

4:36 min

Exploiting e-commerce basket identifiers with Burp Suite

Anna Bacher · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

2:22 min

Structuring critical internal and external penetration testing procedures

Jasmin Azemović Jasmin Azemović · World Congress 2023

1:17 min

Evaluating security vulnerabilities and user experience

Julian Richter Julian Richter · World Congress 2025

Videos

See all

Related articles

See all