Senior Pentester | Madrid

UST

Madrid

Híbrido

EUR 60.000 - 90.000

Jornada completa

Hace 6 días
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Health care plan
Teleworking compensation
Life and accident insurances
Annual leave (23 days)

Descripción de la vacante

UST is seeking a Senior Penetration Tester to join our Madrid-based Security Compliance team on a hybrid model. You will lead hands-on penetration testing engagements, validate findings, and advise on remediation strategies for a global wealth-management client.

You will work with Burp Suite, Nmap, and other tools to assess web applications, APIs, and infrastructure. English and Spanish fluency, plus eligibility to work in Spain, are required.

Formación

  • Bachelor’s degree in Computer Science or Information Security or equivalent experience.
  • 3–5 years hands-on experience in penetration testing, application security, and vulnerability assessment.
  • Strong experience with web application security testing tools (Burp Suite).
  • Solid understanding of OWASP Top 10 and exploitation techniques.
  • Ability to read, understand, and reproduce penetration testing findings and communicate to non-technical stakeholders.
  • Knowledge of HTTP/S, authentication mechanisms, and modern web architectures (APIs, microservices).
  • Professional proficiency in English and Spanish; eligible to work in Spain.

Responsabilidades

  • Validate external security findings and ensure quality and reproducibility of deliverables.
  • Support scoping and execution of penetration testing engagements.
  • Reproduce and validate vulnerabilities and their remediation using Burp Suite and other tools.
  • Provide technical guidance on security testing methodologies and remediation strategies.
  • Collaborate with Exposure Managers, development and infrastructure teams, and external vendors.

Conocimientos

Penetration testing
Application security
Vulnerability assessment
Web application security
Communication to stakeholders

Educación

Bachelor's degree in Computer Science or Information Security

Herramientas

Burp Suite

Descripción del empleo

Role Description

We are looking for the very Top Talent…and we would be delighted if you were to join our team! More in details, UST is a multinational company based in North America, certified as a Top Employer company with over 35.000 employees all over the world and presence in more than 30 countries. We are leaders on digital technology services, and we provide large-scale technologic solutions to big companies.

What are we looking for?

We’re looking for an Senior Penetration Tester. You will join a strategic project with a global client in the wealth management sector.

As an Exposure Management Technical Expert within our Security Compliance Competence Centre (SCCC) in Madrid, you will play a key hands‑on role in strengthening our proactive security testing program.

Acting As An Internal Penetration Testing Specialist, You Will
  • Validate external security findings
  • Ensure technical quality and reproducibility of deliverables
  • Support the scoping and execution of penetration testing engagements

You will collaborate closely with Exposure Managers, application and technology teams, and external vendors to ensure consistent and high-quality testing practices across the organization.

Key Responsibilities
Penetration Testing & Validation
  • Reproduce and validate vulnerabilities and their remediation using tools such as Burp Suite and Nmap
  • Apply manual and automated techniques across web applications, APIs, and infrastructure
Technical Quality Assurance
  • Review penetration testing reports to ensure:
    • Accuracy
    • Completeness
    • Clarity
    • Reproducibility of findings
Scoping & Advisory
  • Support risk-based scoping of penetration testing engagements
  • Act as a technical advisor on:
    • Security testing methodologies
    • Findings interpretation
    • Remediation strategies
Security Standards & Best Practices
  • Ensure alignment with:
    • OWASP Testing Guide
    • OWASP Top 10
    • Internal security standards
False Positive & Risk Management
  • Analyze reported vulnerabilities and identify false positives
  • Ensure correct classification and prioritization
Remediation & Hardening
  • Provide technical guidance to development and infrastructure teams
  • Collaborate with architects on secure and resilient baseline configurations
Collaboration & Knowledge Sharing
  • Work closely with Exposure Managers and global technical teams
  • Share insights, patterns, and lessons learned to improve internal practices
  • Support consistent execution across all penetration testing activities
Your Profile
Required Qualifications
  • Bachelor’s degree in Computer Science, Information Security, or equivalent experience
  • 3–5 years of hands‑on experience in:
    • Penetration testing
    • Application security
    • Vulnerability assessment
  • Strong experience with web application security testing tools (e.g., Burp Suite)
  • Solid understanding of:
    • OWASP Top 10 vulnerabilities
    • Exploitation techniques
  • Ability to:
    • Read, understand, and reproduce penetration testing findings
    • Communicate technical topics to non-technical stakeholders
  • Knowledge of:
    • HTTP/S protocols
    • Authentication mechanisms
    • Modern web architectures (APIs, microservices)
  • Strong analytical and problem-solving skills
  • Professional proficiency in English and Spanish
  • Eligibility to work in Spain
Nice to Have
  • Certifications such as:
    • OSCP, eWPT, CEH, GWAPT, Burp Suite Certified Practitioner
  • Experience:
    • Reviewing third-party security reports
    • Working with external testing vendors
    • Infrastructure/network penetration testing
    • Secure code review or secure development practices
  • Programming/scripting skills (e.g., Python, JavaScript)
  • Experience in financial services or regulated environments
  • Familiarity with DevSecOps or CI/CD security integration
  • German language skills

Location: Hybrid. Madrid city centre (Sol area). 3 days a week in the office.

What can we offer?
  • 23 days of Annual Leave plus the 24th and 31st of December as discretionary days!
  • Numerous benefits (Health Care Plan, teleworking compensation, Life and Accident Insurances).
  • R‑S Program: (Meals, Kinder Garden, Transport, online English lessons, Health Care Plan…)
  • Free access to several training platforms
  • Professional stability and career plans
  • UST also, compensates referrals from which you could benefit when you refer professionals.
  • The option to pick between 12 or 14 payments along the year.
  • Real Work Life Balance measures (flexibility, WFH or remote work policy, compacted hours during summertime…)
  • UST Club Platform discounts and gym Access discounts

In UST we are committed to equal opportunities in our selection processes and do not discriminate based on race, gender, disability, age, religion, sexual orientation or nationality. We have a special commitment to Disability & Inclusion, so we are interested in hiring people with disability certificate.

Skills
  • Application Security, Vulnerability Assessment and Penetration Testing, Burp Suite, Vulnerability Assessment
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior Penetration Tester | Madrid
Senior Penetration Tester | Madrid

UST España & Latam • Madrid

Híbrido
EUR 90.000 - 110.000
Health insurance
Teleworking compensation
Training platforms access
+2
Senior Performance Test Engineer - Hybrid Madrid
Senior Performance Test Engineer - Hybrid Madrid

UST España & Latam • Madrid

Híbrido
EUR 70.000 - 90.000
23 days of Annual Leave plus the 24th/
Teleworking compensation
Life and Accident Insurances
+4
Senior Performance Test Engineer - Hybrid Madrid
Senior Performance Test Engineer - Hybrid Madrid

UST • Madrid

Híbrido
EUR 50.000 - 85.000
23 days annual leave
Health care plan
Teleworking compensation
+2
Senior Application Security & Penetration Tester (Hybrid Madrid)
Senior Application Security & Penetration Tester (Hybrid Madrid)

UST • Madrid

Híbrido
EUR 60.000 - 90.000
Health care plan
Teleworking compensation
Life and accident insurances
+1
Cybersecurity Consultant (Cloud Security) - Hybrid Madrid
Cybersecurity Consultant (Cloud Security) - Hybrid Madrid

UST • Madrid

Híbrido
EUR 55.000 - 75.000
Healthcare plan
Life and accident insurances
Training platform access
+2
OT Security Engineer- Hybrid (Madrid or Barcelona)
OT Security Engineer- Hybrid (Madrid or Barcelona)

UST • Barcelona

Híbrido
EUR 45.000 - 65.000
Annual Leave
Health Care Plan
Flexible working hours
+2
Cybersecurity consultant - Hybrid Madrid
Cybersecurity consultant - Hybrid Madrid

UST • Madrid

Híbrido
EUR 65.000 - 95.000
23 days annual leave
Healthcare plan
Internet connectivity
+7
Governance risk and Compliance Technical Specialist - Hybrid Madrid
Governance risk and Compliance Technical Specialist - Hybrid Madrid

UST • Madrid

Híbrido
EUR 45.000 - 60.000
Annual Leave
Health Care Plan
Free training access
+1
Cybersecurity Consultant (Cloud Security) - Hybrid Madrid
Cybersecurity Consultant (Cloud Security) - Hybrid Madrid

UST • Madrid

Híbrido
EUR 70.000 - 95.000
Annual leave 23 days
Health care plan
Flexible benefits program
+4
QA Engineer
QA Engineer

UST • Madrid

Híbrido
EUR 40.000 - 55.000
Annual Leave (23 days)
Health Care Plan
Flexible Compensation Program
+5