Information Security Engineer – Senior Penetration Tester

SmartRecruiters, Inc.

Madrid

On-site

EUR 70,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Travel discounts
Health insurance (optional discounts)
Hybrid work model

Job summary

Ryanair Labs is seeking an Information Security Engineer – Senior Penetration Tester to join Europe’s Largest Airline Group. You will perform hands-on testing across web, mobile and API apps, networks, and multi-cloud environments with a focus on practical exploit and remediation work.

You’ll drive threat modelling, build detection requirements, and partner with engineers to close gaps. A hybrid, office-and-remote setup in Madrid supports flexible work arrangements while delivering impactful

Qualifications

  • 4+ years hands-on penetration testing / offensive security.
  • Strong web/API and network/AD testing with manual exploitation, not just scanning.
  • Cloud pentesting in AWS, GCP or Azure, including IAM and identity paths.
  • Python scripting (Bash/PowerShell optional).
  • MITRE ATT&CK and OWASP methodologies; CVSS and risk-based reporting.
  • AI skillset: use of LLM assistants and agentic coding tools with validation; knowledge of LLM security.
  • Safe testing discipline in production and safety-critical environments; clear stakeholder communication.

Responsibilities

  • Test web, mobile and API applications (external and internal).
  • Test networks, identity attack paths and Active Directory/Entra ID.
  • Cloud penetration testing across AWS, GCP and Azure; IAM misconfigurations and secrets; CI/CD.
  • AI/LLM application testing with prompt injection and data handling safeguards.
  • Run adversary emulation and purple-team exercises with detection engineering.
  • Build and maintain tooling and automation; leverage LLM assistants for recon and PoC development.
  • Produce clear reports and executive summaries for engineers and leadership.

Skills

Penetration testing
Cloud security testing
Python scripting
MITRE ATT&CK
OWASP methodologies
LLM tooling
Adversary emulation

Tools

Claude Code
OpenCode

Job description

Information Security Engineer – Senior Penetration Tester
  • Full-time

Ryanair Labs are currently recruiting for an Information Security Engineer – Senior Penetration Tester to join Europe’s Largest Airline Group!

This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within the next 10 years.

Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT innovation hub creating Europe's Leading Travel Experience for our customers.

About the role
A hands-on, individual-contributor role in a lean airline security team. You find exploitable weaknesses before attackers do across web and mobile applications, APIs, internal networks, identity and multicloud (AWS, GCP, Azure) including the AI-enabled systems we build and buy. You don't stop at the report: you prove impact, drive fixes with owners, re-test, and turn what you learn into detection and hardening requirements.

  • Scope. Maintain an attack-surface inventory (external, internal, cloud, SaaS, AI systems); threat-model with owners; define rules of engagement and safety constraints, especially around operational systems.
  • Test. Manual-first testing following recognised methodologies (OWASP WSTG/ASVS/MASVS, PTES, MITRE ATT&CK), with automation for breadth.
  • Prove. Demonstrate real impact with safe proof-of-concept exploits and attack chains; rate with CVSS plus business context. Scanner output is not a finding.
  • Fix. Write remediation owners can act on; pair with engineers; convert findings into detection requirements and control improvements for the detection team.
  • Verify. Re-test, track closure, measure time-to-remediate and recurrence.

What you'll do

  • Test passenger-facing and internal web, mobile and API applications.
  • Test internal/external networks, Active Directory / Entra ID and identity attack paths.
  • Cloud penetration testing across AWS, GCP and Azure: IAM privilege escalation, misconfigurations, exposed services, CI/CD and secrets.
  • AI/LLM application testing: direct and indirect prompt injection, jailbreaks, insecure output handling, excessive agency and tool abuse, RAG data leakage and poisoning, agent/MCP integration weaknesses mapped to OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Run adversary emulation and purple-team exercises with detection engineering.
  • Build and maintain tooling and automation; use LLM assistants and agentic coding tools (Claude Code, OpenCode) for recon automation, PoC development, output parsing and report drafting, validating results and respecting data-handling boundaries.
  • Write clear reports and executive summaries; present findings to engineers and leadership.

Must have

  • 4+ years hands-on penetration testing / offensive security.
  • Strong web/API and network/AD testing with manual exploitation, not just scanning.
  • Cloud pentesting in at least two of AWS, GCP, Azure, including IAM and identity attack paths.
  • Scripting in Python (plus Bash/PowerShell); comfortable reading, modifying and writing exploits and tooling.
  • Practical use of MITRE ATT&CK and OWASP methodologies; CVSS and risk-based reporting.
  • AI skillset: effective daily use of LLM assistants and agentic coding tools (e.g., Claude Code, OpenCode) with critical validation of output; working knowledge of how LLM applications, RAG pipelines and agents are built and where they break (OWASP LLM Top 10, MITRE ATLAS); ability to design and run structured tests against AI systems.
  • Safe testing discipline in production and safety-critical environments; strict rules of engagement.
  • Clear written and verbal communication to technical and non-technical stakeholders.

Nice to have

  • Strongly valued: contributions to, or research on, AI red-teaming agents building or extending LLM-driven offensive tooling (autonomous recon, exploitation or prompt-injection agents), automated jailbreak and injection evaluation harnesses, or benchmarks for AI security testing. Open-source commits, publications, conference talks or CTF/AI red-team competition results all count.
  • Adversarial ML (evasion, extraction, poisoning) and AI supply-chain risk (models, datasets, dependencies).
  • Certifications: OSCP, OSEP, OSWE, GPEN, GWAPT, GCPN, CRTO; cloud security (AZ-500, AWS Security Specialty, Google Professional Cloud Security Engineer).
  • Mobile (iOS/Android) and thick-client testing; OT/ICS awareness for airport and ground systems.
  • Secure code review and DevSecOps integration (SAST/DAST in CI/CD).
  • Public research, CVEs, bug-bounty or open-source tooling contributions beyond AI.
  • A competitive but flexible technical career plan.
  • Possibility for career growth in a continuously growing team.
  • We believe in a hybrid working model, you can work up to three days per week remote, but you are also going to enjoy the excellent work environment at our modern offices in the heart of Madrid
  • Optional discounts on health insurances (various companies).
  • Travel discounts,of course!
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Architect - AI & Strategic Initiatives
Information Security Architect - AI & Strategic Initiatives

Ryanair Group Holdings • Madrid

Hybrid
EUR 120,000 - 150,000
Hybrid working model
Travel discounts
Health insurance discounts
Senior Penetration Tester – AI/Cloud & App Security (Hybrid)
Senior Penetration Tester – AI/Cloud & App Security (Hybrid)

SmartRecruiters, Inc. • Madrid

Hybrid
EUR 70,000 - 110,000
Travel discounts
Health insurance (optional discounts)
Hybrid work model
Senior Data Scientist
Senior Data Scientist

Ryanair - Europe's Favourite Airline • Madrid

On-site
EUR 60,000 - 90,000
Hybrid work model
Health insurance discounts
Travel discounts
Penetration Tester (All Gender)
Penetration Tester (All Gender)

Prestwick Aerosystems • Getafe

On-site
EUR 45,000 - 70,000
Penetration Tester (All Gender)
Penetration Tester (All Gender)

Airbus • Madrid

On-site
EUR 55,000 - 90,000
Senior Tech Lead
Senior Tech Lead

Capitole • Barcelona

Hybrid
EUR 100,000 - 140,000
Private health insurance
Hybrid work model
Wellness programs
+1
.NET Payments Engineer - Hybrid (Travel Discounts Included)
.NET Payments Engineer - Hybrid (Travel Discounts Included)

SmartRecruiters, Inc. • Madrid

Hybrid
EUR 70,000 - 95,000
Hybrid working model
Travel discounts
Health insurance options
Security Engineer
Security Engineer

airapps • Barcelona

On-site
EUR 60,000 - 80,000
Annual Bonus
Top-tier Health and Life Insurance
Transportation Budget
+4
Software Engineer - Barcelona, Spain
Software Engineer - Barcelona, Spain

Flight Centre Travel Group • Barcelona

Hybrid
EUR 55,000 - 75,000
Travel discounts
25 days off + 5 compensation days
Language learning platform
+2
Senior Security Engineer
Senior Security Engineer

The Mill Adventure Limited • Barcelona

Hybrid
EUR 70,000 - 90,000
Private health insurance
Learning budget
Work equipment of your choice
+2