Penetration Tester

WTW

Madrid

Presencial

EUR 50.000 - 75.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

WTW is seeking a security-focused professional to conduct vulnerability assessments, perform penetration testing, and provide remediation guidance. The role emphasizes ethical testing practices and staying updated with evolving threats. Strong English communication is required, with a background in web and infrastructure security.

The candidate will collaborate with developers and IT teams to strengthen security controls and document findings for leadership and stakeholders.

Formación

  • Bachelor's degree in a related field is commonly preferred, but not mandatory.
  • Experience in securing web applications and infrastructure is valued.
  • Knowledge of testing methodologies, tools, and frameworks is essential.

Responsabilidades

  • Conduct vulnerability assessments of web apps and infrastructure to identify security flaws.
  • Perform controlled penetration testing on web apps, APIs, and infrastructure.
  • Analyze results to assess severity and business impact.
  • Prepare detailed remediation reports with actionable guidance.

Conocimientos

Web App Security
Infrastructure Security
Penetration Testing
Analytical Thinking
English Proficiency

Educación

Bachelor's degree in CS/Info Security

Herramientas

Vulnerability Scanners
Exploit Frameworks

Descripción del empleo

The Role
  • Vulnerability Assessment: Conducting comprehensive assessments of web applications and Infrastructure to identify security vulnerabilities, such as cross-site scripting (XSS), SQL injection, authentication flaws, insecure configurations, poor host device and service configurations, and use these to penetrate deeper into the application/server.
  • Penetration Testing: Performing controlled attacks on web applications. APIs, infrastructure, and simulate real-world hacking attempts and identify potential entry points for attackers. This involves utilizing various techniques, tools, and methodologies to exploit vulnerabilities and gain access.
  • Security Analysis: Analyzing the results of penetration tests to assess the severity of identified vulnerabilities, their potential impact on the system and the business, and the likelihood of exploitation.
  • Reporting and Documentation: Preparing detailed reports that document the findings, including identified vulnerabilities, attack vectors, and recommendations for remediation. These reports typically outline the risks associated with each vulnerability and provide guidance on how to mitigate them.
  • Remediation Support: Collaborating with developers and system administrators to assist in the remediation of identified vulnerabilities. This may involve providing guidance on secure coding practices, recommending security controls, or validating the effectiveness of implemented fixes.
  • Stay Up to Date: Keeping abreast of the latest web application and infrastructure vulnerabilities, attack techniques, security tools, and industry best practices. This includes staying informed about emerging threats and trends in web applications and infrastructure.
  • Ethical Approach: Conducting all testing and assessment activities within a legal and ethical framework, ensuring that the organization's systems and data are not compromised or harmed during the process.
  • Continuous Improvement: Engaging in professional development activities, such as attending conferences, participating in training programs, and obtaining relevant certifications, to enhance knowledge and skills in cyber security.
The Requirements
  • Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.
Skills:
  • Web Application Security: In-depth knowledge of web application vulnerabilities, common attack techniques, and mitigation strategies. Strong understanding of OWASP Top 10 vulnerabilities is crucial.
  • Infrastructure security: Working knowledge of different on-prem and cloud builds (IaaS, PaaS, SaaS), in-depth understanding of operating system and its common flaws
  • Penetration Testing Techniques: Proficiency in various penetration testing methodologies, tools, and frameworks. Experience with manual testing techniques, automated vulnerability scanners, and exploit frameworks is necessary.
  • Analytical and Problem-Solving Skills: Ability to analyze complex web application environments, identify vulnerabilities, and exploit them. Strong problem-solving skills to understand attack vectors and recommend appropriate countermeasures.
  • Very good English skills (C1/C2 level), both spoken and written
Holds relevant industry certification/s or equivalent like the following:
  • CEH - Certified Ethical Hacker
  • OSCP - Offensive Security Certified Professional
  • PNPT - Practical Network Penentration Tester

We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any , from the application process through to joining WTW, please email candidate.helpdesk@willistowerswatson.com.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Penetration Tester: Web & Infra Security
Penetration Tester: Web & Infra Security

WTW • Madrid

Presencial
EUR 50.000 - 75.000
Senior pentester
Senior pentester

GMV • Tres Cantos

Híbrido
EUR 55.000 - 70.000
Hybrid work model
Flexible working hours
Personalized career development plan
+2
IT Cybersecurity Engineer
IT Cybersecurity Engineer

Werfen • Barcelona

Presencial
EUR 70.000 - 100.000
Cybersecurity Specialist
Cybersecurity Specialist

Randstad España • Madrid

Presencial
EUR 60.000 - 95.000
Pentest Coordinator
Pentest Coordinator

Neotalent Conclusion • Madrid

Presencial
EUR 50.000 - 70.000
Access to continuous learning and certifications
Senior Pentester | Madrid
Senior Pentester | Madrid

UST • Madrid

Híbrido
EUR 60.000 - 90.000
Health care plan
Teleworking compensation
Life and accident insurances
+1
Security Engineer
Security Engineer

Wizeline • Barcelona

Presencial
EUR 90.000 - 130.000
High-Impact Environment
Professional Development
Flexible Culture
+3
Security Engineer (Infrastructure)
Security Engineer (Infrastructure)

Hiring • Málaga

Presencial
EUR 45.000 - 65.000
Security Engineer (Infrastructure) - ESK Agency
Security Engineer (Infrastructure) - ESK Agency

hiring • Málaga

Presencial
EUR 50.000 - 80.000
Senior Penetration Tester | Madrid
Senior Penetration Tester | Madrid

UST España & Latam • Madrid

Híbrido
EUR 90.000 - 110.000
Health insurance
Teleworking compensation
Training platforms access
+2