Information Security Engineer – Senior Penetration Tester

Ryanair Group Holdings

Wrocław

Presencial

PLN 200.000 - 320.000

Jornada completa

Hace 3 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura completa en un minuto — currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Staff travel benefits
Multisport card

Descripción de la vacante

Ryanair Labs is seeking an Information Security Engineer – Senior Penetration Tester to join Europe’s largest airline group. This hands-on role focuses on finding exploitable weaknesses across web, mobile, APIs, networks, and multi-cloud environments (AWS, GCP, Azure) with a bias toward practical impact.

You’ll own testing from discovery to remediation, drive fixes with owners, re-test, and contribute to detection and hardening requirements.

Formación

  • 4+ years hands-on penetration testing / offensive security.
  • Strong web/API and network/AD testing with manual exploitation, not just scanning.
  • Cloud pentesting in at least two of AWS, GCP, Azure, including IAM and identity attack paths.
  • Scripting in Python (plus Bash/PowerShell); comfortable reading, modifying and writing exploits and tooling.
  • Practical use of MITRE ATT&CK and OWASP methodologies; CVSS and risk-based reporting.
  • AI skillset: effective daily use of LLM assistants and agentic coding tools with critical validation of output; knowledge of LLM apps and RAG pipelines.

Responsabilidades

  • Test passenger-facing and internal web, mobile and API applications.
  • Test internal/external networks, Active Directory / Entra ID and identity attack paths.
  • Cloud penetration testing across AWS, GCP and Azure: IAM privilege escalation, misconfigurations, exposed services, CI/CD and secrets.
  • AI/LLM application testing: prompt injection, jailbreaks, insecure output handling, data leakage and poisoning.
  • Run adversary emulation and purple-team exercises with detection engineering.
  • Build tooling and automation; use LLM assistants for recon, PoC development and report drafting.
  • Write clear reports and executive summaries; present findings to engineers and leadership.

Conocimientos

Penetration testing
Web/API testing
Network/AD testing
Python scripting
MITRE ATT&CK
OWASP methodologies
AI security testing
Effective communication

Herramientas

Claude Code
OpenCode

Descripción del empleo

Information Security Engineer – Senior Penetration Tester
  • Full-time

Ryanair Labs are currently recruiting for an Information Security Engineer – Senior Penetration Tester to join Europe’s Largest Airline Group!

This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within the next 10 years.

Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT innovation hub creating Europe's Leading Travel Experience for our customers.

About the role
A hands-on, individual-contributor role in a lean airline security team. You find exploitable weaknesses before attackers do across web and mobile applications, APIs, internal networks, identity and multicloud (AWS, GCP, Azure) including the AI-enabled systems we build and buy. You don't stop at the report: you prove impact, drive fixes with owners, re-test, and turn what you learn into detection and hardening requirements.

  • Scope. Maintain an attack-surface inventory (external, internal, cloud, SaaS, AI systems); threat-model with owners; define rules of engagement and safety constraints, especially around operational systems.
  • Test. Manual-first testing following recognised methodologies (OWASP WSTG/ASVS/MASVS, PTES, MITRE ATT&CK), with automation for breadth.
  • Prove. Demonstrate real impact with safe proof-of-concept exploits and attack chains; rate with CVSS plus business context. Scanner output is not a finding.
  • Fix. Write remediation owners can act on; pair with engineers; convert findings into detection requirements and control improvements for the detection team.
  • Verify. Re-test, track closure, measure time-to-remediate and recurrence.

What you'll do

  • Test passenger-facing and internal web, mobile and API applications.
  • Test internal/external networks, Active Directory / Entra ID and identity attack paths.
  • Cloud penetration testing across AWS, GCP and Azure: IAM privilege escalation, misconfigurations, exposed services, CI/CD and secrets.
  • AI/LLM application testing: direct and indirect prompt injection, jailbreaks, insecure output handling, excessive agency and tool abuse, RAG data leakage and poisoning, agent/MCP integration weaknesses mapped to OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Run adversary emulation and purple-team exercises with detection engineering.
  • Build and maintain tooling and automation; use LLM assistants and agentic coding tools (Claude Code, OpenCode) for recon automation, PoC development, output parsing and report drafting, validating results and respecting data-handling boundaries.
  • Write clear reports and executive summaries; present findings to engineers and leadership.

Must have

  • 4+ years hands-on penetration testing / offensive security.
  • Strong web/API and network/AD testing with manual exploitation, not just scanning.
  • Cloud pentesting in at least two of AWS, GCP, Azure, including IAM and identity attack paths.
  • Scripting in Python (plus Bash/PowerShell); comfortable reading, modifying and writing exploits and tooling.
  • Practical use of MITRE ATT&CK and OWASP methodologies; CVSS and risk-based reporting.
  • AI skillset: effective daily use of LLM assistants and agentic coding tools (e.g., Claude Code, OpenCode) with critical validation of output; working knowledge of how LLM applications, RAG pipelines and agents are built and where they break (OWASP LLM Top 10, MITRE ATLAS); ability to design and run structured tests against AI systems.
  • Safe testing discipline in production and safety-critical environments; strict rules of engagement.
  • Clear written and verbal communication to technical and non-technical stakeholders.

Nice to have

  • Strongly valued: contributions to, or research on, AI red-teaming agents building or extending LLM-driven offensive tooling (autonomous recon, exploitation or prompt-injection agents), automated jailbreak and injection evaluation harnesses, or benchmarks for AI security testing. Open-source commits, publications, conference talks or CTF/AI red-team competition results all count.
  • Adversarial ML (evasion, extraction, poisoning) and AI supply-chain risk (models, datasets, dependencies).
  • Certifications: OSCP, OSEP, OSWE, GPEN, GWAPT, GCPN, CRTO; cloud security (AZ-500, AWS Security Specialty, Google Professional Cloud Security Engineer).
  • Mobile (iOS/Android) and thick-client testing; OT/ICS awareness for airport and ground systems.
  • Secure code review and DevSecOps integration (SAST/DAST in CI/CD).
  • Public research, CVEs, bug-bounty or open-source tooling contributions beyond AI.

Benefits & form of employment

Contract of employment (permanent contract after trial period)

  • Staff travel benefits from day one
  • Multisport card

Other benefits

  • Possibility of taking part in trainings and certifications
  • Great chance to meet your colleagues in other offices
  • Annual events (i.e. St. Patrick’s Day)
  • Regular social meetings
  • Paid referral system
  • New office building surrounded by great dinettes right in the city centre
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Information Security Engineer – Senior Penetration Tester
Information Security Engineer – Senior Penetration Tester

Ryanair - Europe's Favourite Airline • Wrocław

Híbrido
PLN 180.000 - 300.000
Staff travel benefits from day one
Multisport card
Private health care
+1
Information Security Engineer – Senior Penetration Tester
Information Security Engineer – Senior Penetration Tester

Ryanair Ltd. • Wrocław

Híbrido
PLN 120.000 - 180.000
Staff travel benefits
Multisport card
Training & certifications
+1
Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair Group Holdings • Wrocław

Presencial
PLN 180.000 - 300.000
Staff travel benefits
Multisport card
Training & certifications
+2
Information Security - Senior Threat Detection & Response Engineer
Information Security - Senior Threat Detection & Response Engineer

Ryanair Group Holdings • Wrocław

Presencial
PLN 260.000 - 420.000
Staff travel benefits
Multisport card
Training and certifications
+1
Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair - Europe's Favourite Airline • Wrocław

Híbrido
PLN 180.000 - 240.000
Staff travel benefits from day one
Multisport card
Private health care
+1
Information Security Architect – AI & Strategic Initiatives
Information Security Architect – AI & Strategic Initiatives

Ryanair Ltd. • Wrocław

Híbrido
PLN 260.000 - 420.000
Staff travel benefits from day one
Multisport card
Training and certifications
Information Security Architect – AI & Strategic Initiatives
Information Security Architect – AI & Strategic Initiatives

Ryanair - Europe's Favourite Airline • Wrocław

Presencial
PLN 260.000 - 420.000
Staff travel benefits from day one
Multisport card
Private health care
+1
Information Security – Senior Threat Detection & Response Engineer
Information Security – Senior Threat Detection & Response Engineer

Ryanair Ltd. • Wrocław

Híbrido
PLN 180.000 - 280.000
Hybrid model
Staff travel benefits
Multisport card
+2
Information Security Architect - AI & Strategic Initiatives
Information Security Architect - AI & Strategic Initiatives

Ryanair Group Holdings • Wrocław

Presencial
PLN 394.000 - 657.000
Staff travel benefits from day one
Multisport card
Training and certifications
Information Security Analyst SOC Tier 1
Information Security Analyst SOC Tier 1

Ryanair - Europe's Favourite Airline • Wrocław

Presencial
PLN 100.000 - 150.000
Staff travel benefits from day one
Multisport card
Private health care
+1