About this role
About the Role In the Cybersecurity Prevention & Response organization, you will work in a team of highly qualified professionals in an international, dynamic and expanding environment. Your main task will be to conduct Penetration Testing, emulating attacks to identify logical and application vulnerabilities, both known and unknown. Vulnerabilities will be identified in corporate assets, software, processes and procedures to ensure complete risk mitigation and the definition of corrective action plans. What You'll Do
- Conduct Penetration Tests in an international context
- Perform post-patching application re-testing
- Keep track of actions and procedures during Penetration Testing to produce clear and comprehensive reports
- Define remedial actions and provide recommendations to mitigate/vulnerabilities
- Maintain confidentiality following ethical standards and laws
- Use advanced tools and methodologies to perform activities in compliance with industry standards and best practices
- Collaborate with development and security teams to implement mitigation solutions and ensure vulnerability resolution
- Contribute to continuous security process improvement by identifying and proposing new methodologies What We're Looking For
- 3-5 years of experience in Penetration Testing
- STEM degree (Engineering, Computer Science) or technical diploma with significant industry experience
- Good written and spoken English
- Deep knowledge of current cyber threat landscape, particularly in Web-based attacks
- Knowledge of programming, scripting and markup languages including JavaScript, SQL, PHP, ASP, Python, Java, Bash
- Knowledge of evasion techniques for security controls like WAF and PROXY
- Knowledge of bypass methods by vulnerability class categories
- Experience in Penetration Testing on web, mobile, API applications
- Knowledge of major frameworks and methodologies in security testing (e.g., CVSS, PTES, MITRE ATT&CK)
- Basic knowledge of cyber regulations (e.g., GDPR) and national security perimeters
- Understanding of cybersecurity fundamentals (CIA) and cyber risk management Nice to Have
- OSCP, OSWE, eWPT, GWAPT, CPENT certifications
- Proven CVE publications Compensation & Benefits
- Annual gross salary starting from €45,000