Pentesting Engineer - Tres Cantos

Gmv
Madrid, Spain
1 day ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Active Directory Artificial Intelligence Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Cloud Computing Cyber Security Python (Programming Language) Open Web Application Security Windows PowerShell Red Team (Cyber Security)
+8 more
Web Applications Wireless Networks Working Model 2D Scripting Google Cloud Cloud Platform System Mitre Att&ck Purple Team (Cyber Security)

Job description

Overview As a Pentesting Engineer at GMV, you will conduct pen-testing and security assessments across web, mobile, network, and cloud environments, including AI models.You will engage in Red Team exercises to simulate real attacks and Purple Team collaborations to strengthen detection and response.You report vulnerabilities and propose mitigations while aligning with IT and security teams to enforce best practices.The role offers hybrid work, international mobility, and a mission-driven environment focused on defense and threat remediation.Compensaciones / Beneficios Hybrid working model Teleworking up to 8 weeks/year Flexible start/finish times Relocation package Competitive compensation with reviews Wellbeing program (health, dental, mental health, training) Responsabilidades Perform penetration tests on web applications, mobile apps, networks, Wi?Fi, cloud environments, and AI models Participate in Red Team exercises to simulate attacks and Purple Team activities with defensive teams Identify vulnerabilities and provide actionable remediation recommendations Collaborate with IT and cybersecurity teams to implement security best practices Requisitos principales Cybersecurity or related degree with hands-on pentesting experience in networks, web/mobile apps, cloud (AWS, Azure, GCP), Active Directory, and wireless networks Experience in Red Team exercises including planning, executing simulated attacks, evasion, persistence, and exploitation Scripting skills (Python, Bash, PowerShell) for automation of offensive tasks Knowledge of PTES, MITRE ATT&CK, OWASP (asset) Team collaboration Strong communication Problem solving Penetration testing Cloud environments (AWS, Azure, GCP) Active Directory

Requirements

Compensaciones / Beneficios Hybrid working model Teleworking up to 8 weeks/year Flexible start/finish times Relocation package Competitive compensation with reviews Wellbeing program (health, dental, mental health, training) Responsabilidades Perform penetration tests on web applications, mobile apps, networks, Wi?Fi, cloud environments, and AI models Participate in Red Team exercises to simulate attacks and Purple Team activities with defensive teams Identify vulnerabilities and provide actionable remediation recommendations Collaborate with IT and cybersecurity teams to implement security best practices Requisitos principales Cybersecurity or related degree with hands-on pentesting experience in networks, web/mobile apps, cloud (AWS, Azure, GCP), Active Directory, and wireless networks Experience in Red Team exercises including planning, executing simulated attacks, evasion, persistence, and exploitation Scripting skills (Python, Bash, PowerShell) for automation of offensive tasks Knowledge of PTES, MITRE ATT&CK, OWASP (asset) Team collaboration Strong communication Problem solving Penetration testing Cloud environments (AWS, Azure, GCP) Active Directory

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney Dan Cranney +2 · LIVE

1:19 min

Enhancing product safety through continual red teaming operations

Rebekka Weiss Rebekka Weiss +1 · World Congress 2025

Videos

See all

Related articles

See all