Senior Cybersecurity Penetration Tester (f/m/div.)
Bosch Group · Aveiro
Sobre a função
As a Senior Penetration Tester, you will play a central role in identifying, assessing, and mitigating security vulnerabilities across our digital ecosystem. You will lead complex technical evaluations spanning modern web applications, backend architectures, APIs, and cloud-native environments, helping engineering teams build resilient, secure-by-design solutions.
Your contribution to something big:
- Drive Offensive Security: Plan, scope, and execute comprehensive penetration tests on modern web applications, backend microservices, REST/GraphQL APIs, and cloud-native environments (AWS, Azure, or GCP).
- Threat Modeling & Architecture Review: Collaborate closely with development and DevOps teams early in the design phase to conduct threat modeling and review architectures, ensuring security is baked in from day one.
- Vulnerability Analysis & Exploitation: Perform deep-dive manual and automated vulnerability analyses, uncovering complex flaws like business logic bypasses, authorization failures, and server-side request forgeries.
- Technical Reporting & Remediation Guidance: Author high-quality, actionable technical reports that translate complex technical risks into clear business impacts, providing pragmatic remediation guidance to our engineering squads.
- Tooling & Innovation: Develop custom testing scripts and explore cutting-edge offensive workflows, including integrating AI-assisted security testing and LLM-augmented vulnerability analysis to maximize speed and coverage.
What distinguishes you:
Education
- Degree in Computer Science, Cybersecurity, IT, Software Engineering, or equivalent practical experience in offensive security.
Experience
- Hands-on experience (ideally 3+ years) conducting technical security assessments, with a strong focus on web applications, APIs, and cloud infrastructure.
Know how
- Offensive Security Expertise: In-depth knowledge of backend technologies, secure protocols, and security standards (e.g., OWASP Top 10, ASVS, WSTG, OAuth 2.0).
- Cloud & Modern Tech: Solid familiarity with assessing cloud environments (AWS, Azure, or GCP), IAM configurations, container security (Docker, Kubernetes), and microservices.
- Tools & Scripting: High proficiency with industry-standard offensive tools (e.g., Burp Suite Pro, OWASP ZAP, Postman) combined with scripting skills (e.g., Python, Bash) to automate testing workflows.
Languages
- Excellent communication skills with fluency in English (written and spoken) to effectively present findings to both technical teams and business stakeholders.
Working Style and Methods
An analytical and structured problem-solver who enjoys working collaboratively across cross-functional teams to build collective security resilience.
Personality
A curious, continuous learner with a passion for offensive security, exploring new technologies, and a strong drive to mentor and share knowledge with others.
We also welcome (Preferred / Nice-to-have):
- Enthusiastic interest or experience in AI-driven offensive workflows (e.g., automated payload generation, LLM security evaluations).
- Industry certifications such as OSCP, OSWE, OSCE, CRTP, GWAPT, GPEN, or cloud-specific security certifications.
- Experience with source code reviews (SAST) in common modern languages (Java, Python, Go, TypeScript).
Work #LikeABosch includes:
⚖️ Flexible work conditions
🔀 Hybrid work system
🌐 Exchange with colleagues around the world
🧑⚕️ Health insurance and medical office on site (general surgeon, psychology, physiotherapy, general clinic)
📚 Training opportunities (p.e., technical training, foreign languages training) & certifications
📈 Opportunities for career progression and continuous professional development
💲 Access to great discounts in partnerships and Bosch products
🏋️ Sports and health related activities
💰 Flexible benefits platform
🅿️ Free parking lot
🍽️ Canteen
Success stories don´t just happen. They are made...
Make it happen! We are looking forward to your application!