Security Expert (Red Team)

Hotelbeds Group

Valencia

Presencial

EUR 90.000 - 130.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Hotelbeds Group is seeking a Security Expert (Red Team) to proactively assess and validate security posture across corporate, cloud, applications, and AI-enabled environments. You will conduct penetration tests, adversary emulation, and purple team activities to strengthen cyber resilience.

Responsibilities include offensive security assessments of web apps, APIs, cloud platforms, and infrastructure; AI security governance; cloud and container security; and collaboration with Blue Team, DevOps,

Formación

  • Previous experience in a Red Team, Penetration Testing or Offensive Security role.
  • Strong understanding of adversary emulation and offensive security methodologies.
  • Experience with cloud, container security and secure development practices.

Responsabilidades

  • Plan and execute offensive security assessments across web apps, APIs, cloud and on-prem environments.
  • Collaborate with Blue Team and DevOps to remediate findings and improve detections and controls.

Conocimientos

Red Team
Penetration Testing
Adversary Emulation
AI Security
Cloud Security
Kubernetes & Docker

Descripción del empleo

## Security Expert (Red Team)Applylocations: Spain - Valenciatime type: Full timeposted on: Posted Todayjob requisition id: R-00023599HBX Group is the world’s leading technology partner, connecting and empowering the world of travel. We’re game-changers, disruptors, the people who bring together local and global brands in accommodation, transport, activities and payments through our network of 300,000 hotels worldwide, 60,000 hard to reach high value clients such as tour operators, travel agents and loyalty schemes across 140 source markets. We are tech-driven, with a customer-first philosophy, and commercial teams whose knowledge and relationships on the ground are second to none. And of course we have an amazing team! Our people, Team HBX Group, are the beating heart of the company who we encourage to ‘move fast, dream big and make the difference’ every day. In fact, we believe that it is tech + data + people that truly sets us apart in the market, alongside our ‘global approach, local touch’ mentality. We’re headquartered in Palma, Mallorca and employ around 3,500 people worldwide.## **JOB DESCRIPTION:**The Red Team Security Expert is responsible for proactively assessing and validating HBX Group's security posture across corporate, cloud, application, and AI-enabled environments.The role combines penetration testing, adversary emulation, offensive security assessments, Purple Team activities, security research, and AI security testing. The successful candidate will work closely with Blue Team, Security Architecture, DevOps, Engineering, Data, and AI teams to identify weaknesses, validate security controls, and strengthen cyber resilience.Offensive Security Assessments* Conduct penetration testing activities across web applications, APIs, cloud platforms, infrastructure services and corporate environments.* Identify, validate and assess security vulnerabilities, attack paths and exposure risks affecting business services and technology platforms.* Perform security assessments throughout the technology lifecycle to support secure development and deployment practices.* Collaborate with engineering and infrastructure teams to ensure vulnerabilities are effectively remediated and validated.AI Security & Emerging Threats* Assess risks related to Generative AI, Large Language Models (LLMs), AI agents, and machine learning systems.* Identify and mitigate threats such as:* Prompt injection attacks* Data poisoning* Model manipulation* AI supply chain attacks* Sensitive data leakage through AI platforms* Shadow AI usage* Partner with AI and Data teams to implement secure-by-design AI solutions.* Contribute to AI governance, monitoring, and security controls.* Stay up to date on emerging AI security frameworks and industry best practices.Adversary Emulation & Red Team Operations* Plan and execute realistic Red Team engagements that emulate real-world threat actors and attack scenarios.* Leverage MITRE ATT&CK methodologies to assess detection, prevention and response capabilities.* Evaluate security controls across on-premises, cloud and hybrid environments.* Support cyber resilience initiatives through controlled attack simulations and adversary emulation exercises.Application Security & Code Review* Perform web application, API and source code security assessments.* Identify weaknesses associated with authentication, authorisation, session management and secure coding practices.* Support agile delivery teams by providing security findings and remediation guidance during development cycles.* Help improve the organisation's ability to identify and mitigate vulnerabilities early in the software development lifecycle.Cloud & Platform Security* Perform offensive security assessments across AWS, Azure and GCP environments.* Assess Kubernetes clusters, Docker environments and cloud-native architectures.* Review Infrastructure-as-Code deployments and cloud configurations for security weaknesses.* Identify privilege escalation opportunities, misconfigurations and potential attack paths.* Support cloud security validation and architecture review activities.Security Research & Automation* Research emerging attack techniques, exploitation methods and offensive security tools.* Develop and maintain automation, scripts and testing utilities to improve offensive security capabilities.* Support continuous improvement of Red Team methodologies and testing approaches.* Contribute to knowledge sharing, research initiatives and internal security innovation.Purple Team Collaboration* Collaborate with Blue Team teams to validate detections and strengthen defensive capabilities.* Support the development and testing of monitoring rules, alerting mechanisms and incident response processes.* Simulate realistic attack techniques to improve visibility and detection coverage.* Promote continuous improvement through joint Red Team and Blue Team exercises.What You Will Bring* Previous experience in a Red Team, Penetration Testing, Offensive Security, Application Security or equivalent security-focused role.* Strong understanding of offensive security methodologies, attack techniques and adversary emulation practices.* Up-to-date knowledge of cyber security threats, exploitation techniques and offensive tooling.* Experience performing vulnerability assessments, penetration testing and security validation activities.* Knowledge of application security, secure development practices and source code reviews.* Good understanding of DevOps and Agile principles, with the ability to support security activities in fast-moving delivery environments.* Knowledge of cloud and container technologies, including Kubernetes, Docker and cloud environments such as AWS, GCP or Azure.* Experience using scripting languages and automation tools to improve offensive security capabilities and testing efficiency.Desired skills* Ability to translate technical security findings into clear risk-based recommendations.* Strong analytical mindset, with the ability to investigate complex attack scenarios and identify realistic exploitation paths.* Good collaboration skills, with the ability to work effectively with Security, Engineering, DevOps and infrastructure teams.* Proactive approach to learning and staying current with emerging threats, attack techniques and security technologies.* Ability to balance security requirements with business priorities in agile and cloud-based environments.You will have the opportunity to work for a company that is going through significant change in becoming the world ́s leading travel services provider. We are looking for people that are ready to ride the wave in this exciting journey.As well as an attractive benefits package you will be able to work: * Within an innovative, engaging and multicultural environment.* Have the opportunity to build strong and lasting business relationships and friendships from around the world.* Have the opportunity in developing your career locally or within one of our beautiful working locations across the globe.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cyber Security Specialist - Red Team
Cyber Security Specialist - Red Team

HBX Group • Valencia

Presencial
EUR 90.000 - 130.000
Software Developer (.NET, dotnet)
Software Developer (.NET, dotnet)

Hotelbeds Group • Palma

Híbrido
EUR 42.000 - 64.000
Cyber Security Specialist - Blue Team
Cyber Security Specialist - Blue Team

HBX Group • Valencia

Presencial
EUR 70.000 - 120.000
Data & Automation Data Specialist
Data & Automation Data Specialist

Hotelbeds Group • Palma

Presencial
EUR 42.000 - 60.000
Head of Global Employment Law
Head of Global Employment Law

Hotelbeds Group • Palma

Presencial
EUR 120.000 - 190.000
ESG Specialist
ESG Specialist

Hotelbeds Group • Palma

Presencial
EUR 42.000 - 68.000
Finance Analyst
Finance Analyst

Hotelbeds Group • Palma

Presencial
EUR 36.000 - 48.000
Senior Finance Operations Analyst
Senior Finance Operations Analyst

Hotelbeds Group • Palma

Presencial
EUR 52.000 - 76.000
Account Management Specialist
Account Management Specialist

Hotelbeds Group • Palma

Presencial
EUR 42.000 - 65.000
Senior Commercial Legal Advisor Americas
Senior Commercial Legal Advisor Americas

Hotelbeds Group • Palma

Híbrido
PHP 3.525.000 - 5.288.000
Attractive benefits package
Innovative and multicultural environment