N’envoyez pas un CV générique — générez un CV et une lettre de motivation adaptés à ce poste précis.
Stormshield, the leading French publisher and European reference in cybersecurity, seeks a Senior Pentester to join the Product Security Evaluation team in France. You will conduct penetration tests across all Stormshield products and services, promote security best practices, and integrate security testing into development.
The role emphasizes collaboration with R&D and ongoing vulnerability research. You will work in a hybrid setup with offices in Issy-les-Moulineaux and remote options,
TEAM:
Product Security Evaluation (PSE)
CONTRACT:
CDI
LOCATION:
Paris, Lyon, Lille
REMOTE WORK:
3 days per week
Stormshield, the leading French publisher and European reference player in cybersecurity, is a subsidiary of Airbus Defence and Space Cyber Programmes and offers innovative, certified, European‑level‑qualified security products for protecting networks and data. To keep growing, we are looking for a
Senior Pentester with solid technical knowledge in penetration testing and networking, autonomous, able to work in a team and passionate.
The Product Security Evaluation (PSE) team’s main mission is to perform penetration tests and vulnerability research on our products. They are often carried out with a black‑box approach and then a white‑box approach depending on the need and scope of the audit.
Penetration tests cover all solutions and products offered to our customers as well as the company’s business and IT services.
Through our internal audits we help evangelize security best practices and promote the secure by design approach.
Conduct penetration tests on all solutions and products offered to customers as well as on the company’s business and IT services;
Contribute to evangelizing security best practices and promote the secure by design approach;
Automate and integrate security testing into the product development process;
Support, advise, and raise awareness among R&D teams;
Lead internal ethical‑hacking training sessions;
Perform source‑code and architecture audits;
Manage, support, and monitor bug bounty campaigns;
Conduct fuzzing and advanced vulnerability research;
Assist the IT department and run phishing awareness campaigns;
Conduct internal pentests and “assumed breach” scenarios.
Penetration tests involve all our products such as:
Our SNS firewalls (Stormshield Network Security);
Our cloud offerings and services;
Our data‑encryption solutions (desktop client, SDK, REST API, mobile app);
Our companion products (VPN client, TS/SSO agent, etc.);
Our mobile and multi‑OS applications (Android, iOS, macOS, Windows, Linux);
Our centralized management console SMC (Stormshield Management Console).
Penetration testing missions can also target:
Business services exposed on the Internet (APIs, SaaS infrastructure, etc.);
Customer‑facing websites (MyStormshield, support site, knowledge base, etc.);
Ad‑hoc discovery audits;
FreeBSD, Linux, Windows, macOS, cloud infrastructures, etc.;
Web front‑ends, thick clients, cloud services, network protocols, mobile applications, etc.;
Specific features, new functionalities or updates, the product as a whole, etc.
You will join the PSE team, attached to Stormshield’s cybersecurity department. The team is currently split between our Issy‑les‑Moulineaux office and full‑remote work.
Innovation Time Off
Holiday bonuses, profit‑sharing and participation
Airbus ESOP
Sick child leave
Positive Company certified with two stars
Discover our social policy
A first conversation with Alaix , our recruiter at Stormshield.
An interview with Clément who will present the role, the missions and the internal organisation.
A practical CTF‑style exercise.
An interview with Franck, our VP of Engineering.
A final HR interview with William.
Stormshield is committed to creating an inclusive working environment. We welcome all applications, regardless of social or cultural background, age, gender, disability, sexual orientation or religious beliefs.