Penetration Tester
WTW
This position is at WTW
The selection process will be fully managed by WTW.
--
# Penetration Tester **Requisition identifier**: 202603993 **Location**: Madrid, Community of Madrid, Spain **Employment type**: Full time ## Description A penetration tester is responsible for assessing the security of web applications and its underlying infrastructure to identify vulnerabilities and weaknesses that could be exploited by attackers. Their role involves conducting thorough assessments and penetration tests to uncover potential security risks and provide recommendations for mitigation. The role will work closely alongside the rest of the Penetration Testing team, Business units and other Cyber team. We are looking for a collaborative team player, with a good technical knowledge in web application and infrastructure penetration testing. The successful candidate will contribute to and work as part of a global multi-disciplined security community with clear vision and direction, and top-down support across the business. **The Role** * Vulnerability Assessment: Conducting comprehensive assessments of web applications and Infrastructure to identify security vulnerabilities, such as cross-site scripting (XSS), SQL injection, authentication flaws, insecure configurations, poor host device and service configurations, and use these to penetrate deeper into the application/server. * Penetration Testing: Performing controlled attacks on web applications. APIs, infrastructure, and simulate real-world hacking attempts and identify potential entry points for attackers. This involves utilizing various techniques, tools, and methodologies to exploit vulnerabilities and gain access. * Security Analysis: Analyzing the results of penetration tests to assess the severity of identified vulnerabilities, their potential impact on the system and the business, and the likelihood of exploitation. * Reporting and Documentation: Preparing detailed reports that document the findings, including identified vulnerabilities, attack vectors, and recommendations for remediation. These reports typically outline the risks associated with each vulnerability and provide guidance on how to mitigate them. * Remediation Support: Collaborating with developers and system administrators to assist in the remediation of identified vulnerabilities. This may involve providing guidance on secure coding practices, recommending security controls, or validating the effectiveness of implemented fixes. * Stay Up to Date: Keeping abreast of the latest web application and infrastructure vulnerabilities, attack techniques, security tools, and industry best practices. This includes staying informed about emerging threats and trends in web applications and infrastructure. * Ethical Approach: Conducting all testing and assessment activities within a legal and ethical framework, ensuring that the organization's systems and data are not compromised or harmed during the process. * Continuous Improvement: Engaging in professional development activities, such as attending conferences, participating in training programs, and obtaining relevant certifications, to enhance knowledge and skills in cyber security. ## Qualifications **The Requirements** * Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements. * Technical Knowledge: A strong understanding of web technologies, programming languages (e.g., HTML, CSS, JavaScript, PHP, Python), and web application architecture is essential. Knowledge of networking fundamentals, operating systems, and databases is also beneficial. **Skills:** * Web Application Security: In-depth knowledge of web application vulnerabilities, common attack techniques, and mitigation strategies. Strong understanding of OWASP Top 10 vulnerabilities is crucial. * Infrastructure security: Working knowledge of different on-prem and cloud builds (IaaS, PaaS, SaaS), in-depth understanding of operating system and its common flaws * Penetration Testing Techniques: Proficiency in various penetration testing methodologies, tools, and frameworks. Experience with manual testing techniques, automated vulnerability scanners, and exploit frameworks is necessary. * Programming and Scripting: Proficiency in at least one programming language (e.g., Python, Ruby, or JavaScript, etc) to write custom scripts and tools. Understanding SQL queries for database testing is also important. * Analytical and Problem-Solving Skills: Ability to analyze complex web application environments, identify vulnerabilities, and exploit them. Strong problem-solving skills to understand attack vectors and recommend appropriate countermeasures. * Very good English skills (C1/C2 level), both spoken and written **Holds relevant industry certification/s or equivalent like the following:** * CEH – Certified Ethical Hacker * OSCP – Offensive Security Certified Professional * GPEN – GIAC Penetration Tester * PNPT – Practical Network Penentration Tester * Burp Suite Certified Practitioner * eWAPT/eWAPTx – elearning Web Application Penetration Tester _We’re committed to equal employment opportunity and provide application, interview and workplace adjustments and accommodations to all applicants. If you foresee any barriers, from the application process through to joining WTW, please email Ver el correo electrónico en es.fitly.work
--
de 42000 a 70000 €/año
...Join a team of cybersecurity professionals and help Swiss Re fulfil its mission to make the world more resilient. As the Penetration Tester, you will improve and develop the strategy of penetration testing within Swiss Re, ensuring security assessments of web applications...Ofertas de empleo recomendadasTiempo completoDesde casaTrabajo híbrido- ## Penetration TesterApplylocations: Madrid Areatime type: Full timeposted on: Posted Todayjob requisition id: JR10426813****Job Description:****Missions & Responsabilités ● Conduct penetration testing on networks, applications, infrastructure and industrial systems. ●...Ofertas de empleo recomendadasEmpleo permanenteContratoHorario flexible
- ...Swiss Re is seeking a Penetration Tester to advance our testing strategy and deliver robust assessments of web applications, APIs, and infrastructures. You will coordinate remediations and share lessons learned with IT developers and security teams. Join a team within...Ofertas de empleo recomendadasDesde casaTrabajo híbrido
- ...Airbus is seeking a Penetration Tester to work in Madrid. The role involves conducting penetration testing on various systems, reporting results, and providing recommendations for security improvements. Candidates should possess at least 3 years of experience in penetration...Ofertas de empleo recomendadas
- Una empresa de consultoría tecnológica en Madrid busca un Administrador de Jboss con experiencia en despliegue y operación de aplicaciones web en entornos Windows y Linux. Se requiere un mínimo de 5 años de experiencia y conocimientos en gestión de certificados y troubleshooting...Ofertas de empleo recomendadas
- ...evaluar y mitigar vulnerabilidades en infraestructuras críticas. Esto incluye la realización de auditorías técnicas y pruebas de penetración para identificar riesgos y proponer soluciones correctivas. Responsabilidades principales: * Realizar auditorías de vulnerabilidades...IndefinidoTiempo completoRemotoTurno de tarde
- Babel Group. busca un Consultor GRC de Ciberseguridad para unirse a su equipo en expansión. El candidato ideal debe contar con al menos 10 años de experiencia y titulaciones relacionadas, además de certificaciones en auditoría de sistemas de seguridad. Ofrecemos un ...Remoto
- S2 Grupo busca un Administrador de Sistemas Linux con perfil mixto para diseñar y gestionar infraestructuras y aplicaciones basadas en máquinas virtuales, contenedores Docker y Kubernetes. Trabajarás junto a equipos de desarrollo, DevOps y soporte de infraestructuras para...
- ## Consultor Ciberseguridad Senior (Mallorca)Applyremote type: Hybridlocations: MADRIDtime type: Full timeposted on: Posted Todayjob requisition id: JR108299We are **One Team.** We **make it happen.** We are **Unstoppable.**BABEL es una consultora tecnológica multinacional...Remoto
- S2 Grupo busca un/a Consultor/a de Concienciación en Ciberseguridad para desarrollarse en un entorno profesional orientado al trabajo en equipo y la colaboración interdisciplinar. Se valorará la capacidad de crear contenidos y explicar conceptos de seguridad a distintos...
- About Atos Group Atos Group is a global leader in digital transformation with c. 67,000 employees and annual revenue of c. €10 billion, operating in 61 countries under two brands — Atos for services and Eviden for products. European number one in cybersecurity, cloud and...Trabajo híbrido
- Desde el Área de Formación y Concienciación de S2 Grupo queremos incorporar a nuestro equipo un/a Consultor/a de Concienciación en CIberseguridad que esté interesado/a en desarrollar su carrera en un muy buen ambiente profesional donde prima el trabajo en equipo y la colaboración...
- This position is at Telefónica The selection process will be fully managed by Telefónica. --  para incorporarse a un proyecto estable dando soporte a importantes...Tiempo completoEmpleo permanenteContratoInicio inmediato1 día a la semana20500 €/año
This position is at Adecco Spain The selection process will be fully managed by Adecco Spain. -- ¿Hablas italiano? ¿Tienes experiencia en atención al cliente?¡Si tu respuesta es SÍ, ésta es tu oportunidad! **La misión del puesto:** Formarás parte de una empresa líder...Tiempo completoEmpleo permanenteContratoInicio inmediato1 día a la semana- Renovalia Energy Group, S.L. busca un/a Técnico/a de Sistemas y Redes para incorporarse en su sede de Madrid. La función implica la implantación y el mantenimiento de equipos, redes y aplicaciones corporativas, así como soporte a usuarios y gestión de bases de datos. ...Empleo permanenteTrabajar en la oficina
- Evolutio en Madrid busca un técnico especialista en redes y seguridad perimetral L2 para operar y mantener infraestructuras de clientes, garantizando disponibilidad, rendimiento y cumplimiento de SLA. Se valorará experiencia en SASE/ZTNA, firewalls (Fortinet, Palo Alto...
- En Métrica España, buscamos constantemente profesionales apasionados por la tecnología y comprometidos con la excelencia para unirse a nuestro equipo y contribuir a nuestro continuo crecimiento. Descripción del Puesto Estamos en la búsqueda de un Especialista en...Práctica
- Nunsys Group busca un/a Técnico/a de Seguridad de Redes SDN para incorporarse en su delegación de Madrid. Será responsable de proteger la infraestructura de red virtualizada y centralizada y de mantener la seguridad de las soluciones basadas en VMware NSX. El candidato...
- Vantage Towers in Madrid, Spain seeks a Site Design, Plan & Deployment Expert (m/f/d) to drive network deployment projects with customers and vendors. You will manage dashboards, SLA compliance, and lead deployment meetings, while directing incident management and budget...Trabajo híbrido
- The Opportunity We are seeking a Manufacturing Specialist – Cyber Security to join our PTE organization. In this role, you will serve as the key liaison between the global TechOps cyber security function and our local manufacturing sites across the globe. Your mission...Inicio inmediato
- The Network Solutions Architect is responsible for the design, governance, and evolution of network solutions that support organisational objectives across enterprise, cloud, and hybrid environments. The role combines strategic architecture leadership with operational ...ContratistaRemotoTrabajo híbridoTurno de noche
de 59687 a 72951 €/año
...providing actionable risk-reduction recommendations. You have a strong understanding of cyber security tools and services, such as penetration testing, programming languages, malware assessment, and risk management frameworks. A recognized cyber security certification...PrácticaTiempo completoEmpleo permanenteContratoRemotoOffshoreTrabajo híbridoHorario flexible- Técnico especialista en redes y seguridad perimetral L2 Jornada Completa España Provincia: Comunidad de Madrid Evolutionace después de más de 30 años prestando servicios en el mercado español con la marca BT (British Telecom) con una nueva visión: ser el ...PrácticaTiempo completoRemotoLunes a miércoles
- Buscamos una persona proactiva, constante y organizada para encargarse del soporte y la gestión diaria de nuestras redes sociales. No se requiere experiencia previa, solo buen manejo de plataformas digitales, atención al detalle y ganas de aprender. Publicación Diaria...Tiempo parcial
- Buscamos una persona constante, organizada y con iniciativa para sumarse a nuestro equipo de forma 100% remota. Te encargarás de la gestión diaria y la adaptación gráfica o escrita del contenido para nuestras plataformas digitales. No se requiere experiencia previa, solo...Por horaFreelanceEmpleo permanenteDesde casaRemoto
- Sirt está buscando incorporar un perfil para el área de redes y seguridad en un servicio 24x7. Se ofrece contrato indefinido desde el primer día y desarrollo profesional, con la posibilidad de trabajar desde cualquier región de España. El ambiente laboral es favorable ...IndefinidoRemoto
- This position is at KPMG España The selection process will be fully managed by KPMG España. -- Desde nuestro departamento de Ciberseguridad buscamos incorporar Consultores de Ciberseguridad. ¿Qué necesitas saber? * Formación académica: Ingeniería Informática, Desarrollo...Tiempo completoTrabajo híbridoHorario flexible
- Consultor/a junior de Ciberseguridad En GMV te unirás a un equipo experto en ciberseguridad que lidera proyectos estratégicos para proteger la información y los sistemas de organizaciones líderes. Tu misión será ayudar a nuestros clientes a fortalecer su postura de seguridad...Trabajo de veranoAprendizPrácticaTiempo completoRemotoTrabajo híbridoJornada intensivaHorario flexible
¿Quieres recibir más ofertas?
Suscríbete y recibe ofertas similares para Penetration Tester. ¡Entérate antes que nadie!



