Pentesting cibersecurity engineer

GMV Spain

Tres Cantos

Híbrido

EUR 70.000 - 110.000

Jornada completa

Hace 4 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Transforma esta oferta en una entrevista — un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Hybrid work model
8 weeks teleworking per year
Relocation package
Flexible hours

Descripción de la vacante

GMV Spain is seeking a Senior Pentester to design realistic attack scenarios and lead audits across web, mobile, network, cloud and AI systems. You will drive Red Team and Purple Team exercises, coordinating with Blue Team to improve detection and response.

Ideal candidates bring 3+ years in pentesting, strong tool experience (Burp Suite, Nmap, Metasploit) and a track record of delivering risk-focused reports. Relocation support and a hybrid Spain-based role are offered.

Formación

  • 3+ years of experience in penetration testing (web, mobile, network, cloud, AD, Wi‑Fi).
  • Experience in Red Team operations designing and executing simulated attacks.
  • Advanced knowledge of Burp Suite, Nmap, Metasploit or C2 frameworks.
  • Automate offensive tasks with Python, Bash or PowerShell.
  • Experience producing technical and executive reports focused on risk.
  • Strong communication and ability to present results clearly.
  • Experience managing cybersecurity or technical audit projects.
  • Offensive certifications such as OSCP, OSEP, OSWE, eCPPT or equivalent.
  • Knowledge of PTES, MITRE ATT&CK or OWASP.
  • Experience assessing security in AI or LLM-based systems.

Responsabilidades

  • Lead penetration tests in complex corporate environments.
  • Participate in Red Team exercises, applying evasion techniques against EDR/XDR/WAF/AV.
  • Identify vulnerabilities, analyze impact and propose mitigations.
  • Develop offensive tools and automations using Python, Bash or PowerShell.
  • Produce technical and executive risk reports.
  • Present findings to technical and business audiences.
  • Manage cybersecurity audit projects with scope, timelines, and deliverables.

Conocimientos

Penetration testing
Red Team operations
Python scripting
Communication skills
Project leadership
Threat modeling

Herramientas

Burp Suite
Nmap
Metasploit
C2 frameworks
PowerShell

Descripción del empleo

If you wanted to be Anonymous, but the pandemic taught you that wearing a mask is not your cup of tea… Your place is with us!

Do you want to participate in advanced offensive security assessments? The GMV Technical Audits team is looking for you!

We´ll get to the point; we'll tell you what's not on the web.If you want to know more about de GMV

WHAT CHALLENGE WILL YOU BE TAKING ON?

As a Senior Pentester, you will not only execute technical assessments but also design realistic attack scenarios based on MITRE ATT&CK TTPs and lead audit projects, helping organizations understand how they could be compromised… before a real attacker does.

You will work on web and mobile applications, network infrastructures, Wi-Fi networks, cloud environments (AWS, Azure, GCP), Active Directory and AI-based systems.

You will also participate in Red Team and Purple Team exercises, simulating real attacks and collaborating with Blue Team professionals to improve threat detection and response capabilities.

In your day-to-day work you will:

  • Execute and lead penetration tests in complex corporate environments.
  • Participate in Red Team exercises, applying evasion techniques against EDR, XDR, WAF and antivirus solutions.
  • Identify vulnerabilities, analyze their impact and propose effective mitigation strategies.
  • Develop or adapt offensive tools and automations using Python, Bash or PowerShell.
  • Produce clear technical and executive reports focused on risk.
  • Present findings to both technical and business audiences.
  • Manage technical audit projects, coordinating scope, timelines and deliverables.
WHAT DO WE NEED IN OUR TEAM?

We are looking for someone with strong experience in offensive cybersecurity, comfortable working in complex environments and able to independently lead technical security assessments.

For this position, it is important to have:

  • 3+ years of experience in penetration testing (web, mobile, network, cloud, Active Directory, Wi-Fi).
  • Experience in Red Team operations designing and executing simulated attacks.
  • Advanced knowledge of tools such as Burp Suite, Nmap, Metasploit or C2 frameworks.
  • Ability to automate offensive tasks through scripting (Python, Bash or PowerShell).
  • Experience producing technical and executive reports focused on risk.
  • Strong communication skills and ability to present results clearly.
  • Experience managing cybersecurity or technical audit projects.
  • Offensive certifications such as OSCP, OSEP, OSWE, eCPPT, CRTP or equivalent.
  • Knowledge of frameworks and methodologies such as PTES, MITRE ATT&CK or OWASP.
  • Experience assessing security in AI or LLM-based systems (OWASP Top 10 for LLMs).
WHAT DO WE OFFER?

Hybridworking model and 8 weeks per year of teleworking outside your usual geographical area.

Flexible start and finish times, and intensive working hours Fridays and insummer.

Personalized career plan development, training and language learning support.

National and international mobility. Do you come from another country?We can offer you a relocation package.

Competitive compensation with ongoing reviews, flexible compensation and discount on brands.

Wellbeingprogram: Health, dental and accident insurance; free fruit and coffee, physical,mental and financial health training, and much more!

In our recruitment processes youwill always have telephone and personal contact, face-to-face or online, withour talent acquisition team. In addition, bank transfers and bank cards will neverbe requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.

We promote equal opportunities inrecruitment, and we are committed to inclusion and diversity.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Pentester Senior
Pentester Senior

GMV Spain • Tres Cantos

Híbrido
EUR 65.000 - 93.000
Hybrid working model
Teleworking up to 8 weeks/year
Relocation package
+2
Senior pentester
Senior pentester

GMV Spain • Madrid

Híbrido
EUR 70.000 - 100.000
Hybrid work model
Relocation package
Wellbeing program
+1
Pentesting engineer
Pentesting engineer

GMV Spain • Tres Cantos

Híbrido
EUR 45.000 - 65.000
Hybrid working
Relocation package
Wellbeing program
+2
Senior pentester
Senior pentester

GMV • Tres Cantos

Presencial
EUR 55.000 - 70.000
Hybrid work model
Flexible working hours
Personalized career development plan
+2
Pentesting engineer
Pentesting engineer

GMV • Tres Cantos

Híbrido
EUR 52.000 - 78.000
Hybrid working model
Relocation package
Mobility opportunities
Senior Pentester - Tres Cantos
Senior Pentester - Tres Cantos

Gmv • Madrid

Híbrido
EUR 70.000 - 95.000
Remote work up to 8 weeks/year
Relocation package
Training opportunities
Internships in the Financial Cybersecurity Field
Internships in the Financial Cybersecurity Field

GMV • Tres Cantos

Presencial
EUR 6696 - 10.044
Relocation package
Flexible hours
Career development
+3
Cybersecurity Engineer for vulnerability management projects
Cybersecurity Engineer for vulnerability management projects

GMV • Tres Cantos

Presencial
EUR 60.000 - 90.000
Hybrid working model
Relocation package
Wellbeing program
Hybrid Junior Cybersecurity & Regulatory Compliance Consultant
Hybrid Junior Cybersecurity & Regulatory Compliance Consultant

GMV Spain • Madrid

Híbrido
EUR 30.000 - 50.000
Hybrid work model
Flexible working hours
Competitive compensation
+3
Cybersecurity Infrastructure Engineer
Cybersecurity Infrastructure Engineer

GMV • Tres Cantos

Presencial
EUR 45.000 - 65.000
Career development
Relocation package
Competitive compensation
+1