Senior Web App Security Consultant - Remote

Google

España

Presencial

EUR 88.000 - 90.000

Jornada completa

hace 15 horas
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Ventajas ofrecidas por este puesto de trabajo

Bonus target 15%
Equity
Benefits

Descripción de la vacante

Google is seeking a true web application hacking specialist to scope, plan, and execute highly sophisticated offensive security assessments for Google Cloud and Mandiant customers.

The role focuses on advanced web application and API exploitation, red team initial access vectors, and bespoke security assessments; occasional infrastructure assessments and bespoke projects are included. Strong reporting and leadership are required.

Formación

  • Bachelor's degree or equivalent practical experience in Computer Science, Cybersecurity, or a related field.
  • 5 years of experience in offensive security, specifically focused on manual web application pen testing and API testing.
  • Experience with operating system security across Linux, Windows, and macOS.
  • Experience delivering reports to both technical and executive audiences (e.g., explaining exploit chains or technical risks).
  • Preferred certifications: OSWE, GWAPT, OSCP, eWPTX, or CCT APP.
  • Cloud security experience including GCP.
  • Proficiency in Python, JavaScript, or Go for custom tool creation.
  • Understanding of OWASP Top 10 and modern JS/SPA frameworks, GraphQL, REST APIs, and microservices.
  • Understanding of network protocols, system administration, and incident response.
  • Proven track record of manually discovering and exploiting critical vulnerabilities.

Responsabilidades

  • Participate in external phases of Red Team engagements, leveraging web app compromise to establish footholds.
  • Conduct in-depth, manual pen testing of web applications, APIs, microservices, and mobile backends; include network/infrastructure pen testing in broader assessments.
  • Dedicate time to security research, finding new exploitation techniques and developing custom tools.
  • Author highly technical reports detailing exploitation steps, PoCs, and remediation for developers and executives.
  • Act as a technical lead, scoping projects, guiding delivery, and mentoring junior consultants.

Conocimientos

Offensive security
Manual web app pen testing
API testing
Executive reporting
Cross-platform (Linux/Windows/macOS)
Security research
Python
JavaScript
Go

Educación

Bachelor's degree or equivalent in CS/Cybersecurity

Herramientas

Python
JavaScript
Go

Descripción del empleo

Google is seeking a true web application hacking specialist to scope, plan, and execute highly sophisticated offensive security assessments for Google Cloud and Mandiant customers.

The role focuses on advanced web application and API exploitation, red team initial access vectors, and bespoke security assessments; occasional infrastructure assessments and bespoke projects are included. Strong reporting and leadership are required.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

On-Site Senior Offensive Web & API Security Consultant
On-Site Senior Offensive Web & API Security Consultant

Google • España

A distancia
EUR 88.000 - 90.000
Equity
Bonus target
Benefits
Cloud Security Engineer - Product & Threat Modeling
Cloud Security Engineer - Product & Threat Modeling

Google Inc. • España

Presencial
EUR 70.000 - 71.500
AI-Driven Red Team Specialist - Web Apps & Cloud Security
AI-Driven Red Team Specialist - Web Apps & Cloud Security

DKB Code Factory GmbH • España

Presencial
EUR 70.000 - 110.000
Remote Associate Security Consultant - App & Infra Testing
Remote Associate Security Consultant - App & Infra Testing

IOActive, Inc. • Madrid

Presencial
EUR 40.000 - 50.000
Remote work flexibility
Travel opportunities
Competitive compensation
Senior AppSec Engineer: AI-Driven Security & CI/CD (Remote)
Senior AppSec Engineer: AI-Driven Security & CI/CD (Remote)

AgileEngine, LLC. • Barcelona

Presencial
EUR 70.000 - 110.000
Remote work
Flexible hours
Learning budget
+2
Senior pentester
Senior pentester

GMV • Tres Cantos

Híbrido
EUR 55.000 - 70.000
Hybrid work model
Flexible working hours
Personalized career development plan
+2
Security Architect / Senior AppSec Engineer - Remote-Ready
Security Architect / Senior AppSec Engineer - Remote-Ready

Wizeline • España

Híbrido
EUR 70.000 - 110.000
Health benefits
Retirement plans
Global mobility
+4
Senior AppSec Engineer - Remote, AI-Driven Security
Senior AppSec Engineer - Remote, AI-Driven Security

AgileEngine, LLC. • Madrid

A distancia
EUR 70.000 - 90.000
Growth without limits
Competitive compensation
Flexibility: remote work
+3
Remote Senior AppSec Engineer – Secure by Design
Remote Senior AppSec Engineer – Secure by Design

Job&Talent • Madrid

Presencial
EUR 60.000 - 90.000
Cloud Security Engineer - Product Security & Threat Modeling
Cloud Security Engineer - Product Security & Threat Modeling

Google • Málaga

Presencial
EUR 70.000 - 72.000