N’envoyez pas un CV générique — générez un CV et une lettre de motivation adaptés à ce poste précis.
Stormshield is seeking a Senior Pentester to join the Product Security Evaluation team. You will conduct penetration tests on our solutions and services, promote secure by design, and help integrate testing into product development.
The role requires autonomous work within a security-focused team and collaboration with R&D. The team operates from Issy-les-Moulineaux with full-remote options.
TEAM:
Product Security Evaluation (PSE)
CONTRACT:
CDI
LOCATION:
Paris, Lyon, Lille
REMOTE WORK:
3 days per week
Stormshield, the leading French publisher and European reference player in cybersecurity, is a subsidiary of Airbus Defence and Space Cyber Programmes and offers innovative, certified, European‑level‑qualified security products for protecting networks and data. To keep growing, we are looking for a Senior Pentester with solid technical knowledge in penetration testing and networking, autonomous, able to work in a team and passionate.
The Product Security Evaluation (PSE) team’s main mission is to perform penetration tests and vulnerability research on our products. They are often carried out with a black‑box approach and then a white‑box approach depending on the need and scope of the audit.
Penetration tests cover all solutions and products offered to our customers as well as the company’s business and IT services.
Through our internal audits we help evangelize security best practices and promote the secure by design approach.
Conduct penetration tests on all solutions and products offered to customers as well as on the company’s business and IT services;
Contribute to evangelizing security best practices and promote the secure by design approach;
Automate and integrate security testing into the product development process;
Support, advise, and raise awareness among R&D teams;
Lead internal ethical‑hacking training sessions;
Perform source‑code and architecture audits;
Manage, support, and monitor bug bounty campaigns;
Conduct fuzzing and advanced vulnerability research;
Assist the IT department and run phishing awareness campaigns;
Conduct internal pentests and “assumed breach” scenarios.
Penetration tests involve all our products such as:
Our SNS firewalls (Stormshield Network Security)
Our cloud offerings and services
Our data‑encryption solutions (desktop client, SDK, REST API, mobile app)
Our companion products (VPN client, TS/SSO agent, etc.)
Our mobile and multi‑OS applications (Android, iOS, macOS, Windows, Linux)
Our centralized management console SMC (Stormshield Management Console)
Penetration testing missions can also target:
Business services exposed on the Internet (APIs, SaaS infrastructure, etc.)
Customer‑facing websites (MyStormshield, support site, knowledge base, etc.)
Ad‑hoc discovery audits
FreeBSD, Linux, Windows, macOS, cloud infrastructures, etc.
Web front‑ends, thick clients, cloud services, network protocols, mobile applications, etc.
Specific features, new functionalities or updates, the product as a whole, etc.
You will join the PSE team, attached to Stormshield’s cybersecurity department. The team is currently split between our Issy‑les‑Moulineaux office and full‑remote work.
Discover our social policy
A first conversation with Alaix, our recruiter at Stormshield.
An interview with Clément who will present the role, the missions and the internal organisation.
A practical CTF‑style exercise.
An interview with Franck, our VP of Engineering.
A final HR interview with William.
Stormshield is committed to creating an inclusive working environment. We welcome all applications, regardless of social or cultural background, age, gender, disability, sexual orientation or religious beliefs.