## Senior Offensive Security AuditorApply: Hybrid: Leca do Balio: Full time: Posted Today: R0329207Location: Leca do Balio, Portugal## About the role We are looking for an experienced **Senior Offensive Security Auditor** to join our Offensive Security team in Portugal. This is a **hands-on senior role** for an offensive security professional with strong experience in penetration testing, red teaming and security assessments, who will act as a **technical reference for our Offensive Security activities in Portugal**. You will lead complex security assessments from planning through delivery, working closely with our **SOC, DFIR, Threat Hunting, Threat Intelligence and Security Engineering** teams to identify vulnerabilities, validate security controls and strengthen our customers' cyber resilience. This role offers the opportunity to combine **deep technical expertise, client interaction and technical leadership**. ## What you'll do* Lead and deliver complex **penetration testing, red team, adversary simulation and security assessment** engagements.* Define scope, testing approaches and methodologies for offensive security engagements.* Perform hands-on security testing across **web applications, APIs, infrastructure and cloud environments**.* Conduct **vulnerability assessments, exploitation and security validation** activities.* Develop and execute **adversary emulation and red team scenarios** based on real-world attack techniques.* Work closely with **SOC, DFIR, Threat Hunting and Threat Intelligence** teams to provide offensive security expertise and support security investigations when required.* Identify, assess and communicate security risks, translating technical findings into **clear and actionable remediation recommendations**.* Prepare high-quality technical reports and present findings to both **technical and non-technical stakeholders**.* Act as a **technical reference for Offensive Security activities in Portugal**, supporting the quality and continuous improvement of local engagements.* Contribute to the development and improvement of **methodologies, playbooks, testing procedures and reporting standards**.* Support and share knowledge with other members of the offensive security team. **What you bring****Required*** **5+ years of professional experience** in offensive security, penetration testing, red teaming or security auditing.* Strong hands-on experience in:Web application and API security testing.Infrastructure and network penetration testing.Cloud security assessments.Vulnerability assessment and exploitation.Red Team / adversary simulation activities.* Strong understanding of **attack techniques, vulnerabilities and security controls**.* Ability to independently plan and deliver complex security assessments.* Excellent analytical, reporting and communication skills.* Ability to communicate technical risks and recommendations clearly to both technical and business stakeholders.* Ability to work effectively with **SOC, DFIR, Threat Intelligence and Security Engineering** teams.* **English level C1**.* Professional working proficiency in **Portuguese**. **Nice to have*** Experience with **Purple Team exercises** and security control validation.* Experience with **cloud offensive security**, mobile security, OT/ICS, IoT or social engineering.* Experience supporting **incident response or post-incident investigations** from an offensive security perspective.* Knowledge of frameworks such as **MITRE ATT&CK** and experience applying them to adversary simulation.* Experience working directly with customers and presenting technical findings.## **Certification**sRelevant certifications will be highly valued, including:* **Offensive Security:** OSEP, OSCP, OSCE3* **SANS:** GXPN, GPEN, GWAPT, etc.* **CREST:** CCT, CCSAM, CCTIM or equivalent* **Altered Security:** CRTE, CARTP* **Other recognised offensive security certifications**## What we offer* A senior technical role within a leading **cybersecurity organisation**.* The opportunity to become a **technical reference for Offensive Security in Portugal**.* Exposure to complex and diverse cybersecurity projects and customers.* Continuous learning and professional development through **training and certifications**.* Collaboration with highly experienced cybersecurity professionals across different areas and countries.* Flexible working model according to local policy.* **Medium travel** depending on project requirements.* Competitive compensation package and benefits. ## **Your career at Thales**At Thales, your career can evolve in different directions. You will have the opportunity to develop your expertise, explore new technologies and work with international teams and customers.You can continue developing as a **technical cybersecurity expert**, move towards technical leadership, or explore new areas and opportunities across the Thales Group.**Join Thales and help us build a safer digital world.**