Job Summary
We are seeking an Exposure Management Technical Expert with a focus on penetration testing to strengthen our proactive security testing program. The role sits within the Security Compliance Competence Centre (SCCC) in Madrid and involves hands‑on work on a strategic project for a global wealth‑management client.
Key Responsibilities
- Reproduce and validate external security findings (vulnerabilities and remediation) using tools such as Burp Suite and Nmap.
- Apply manual and automated techniques across web applications, APIs, and infrastructure.
- Review penetration testing reports for accuracy, completeness, clarity, and reproducibility.
- Support risk‑based scoping of penetration testing engagements.
- Serve as a technical advisor on testing methodologies, findings interpretation, remediation strategies, and security standards (OWASP Testing Guide, OWASP Top10, internal security standards).
- Analyze reported vulnerabilities, identify false positives, and ensure correct classification and prioritization.
- Provide technical guidance to development and infrastructure teams on remediation and hardening, collaborating with architects on secure baseline configurations.
- Collaborate with Exposure Managers, general technical teams, and external vendors to share insights and improve internal testing practices.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Security, or equivalent experience.
- 3–5years of hands‑on experience in penetration testing, application security, and vulnerability assessment.
- Strong experience with web‑application security testing tools (e.g., Burp Suite).
- Solid understanding of OWASP Top10 vulnerabilities and exploitation techniques.
- Ability to read, understand, and reproduce penetration testing findings and communicate technical topics to non‑technical stakeholders.
- Knowledge of HTTP/S protocols, authentication mechanisms, and modern web architectures (APIs, microservices).
- Strong analytical and problem‑solving skills.
- Professional proficiency in English and Spanish.
- Eligibility to work in Spain.
Nice to Have
- Certifications such as OSCP, eWPT, CEH, GWAPT, or Burp Suite Certified Practitioner.
- Experience reviewing third‑party security reports and working with external testing vendors.
- Infrastructure/network penetration testing or secure code review experience.
- Programming/scripting skills (Python, JavaScript).
- Experience in financial services or regulated environments.
- Familiarity with DevSecOps or CI/CD security integration.
- German language skills.
Location & Working Arrangement
Hybrid. Madrid city centre (Sol area), 3 days a week in the office.
Benefits
23 days of annual leave plus discretionary days (24th and 31st December), health‑care plan, teleworking compensation, life and accident insurance, flexible remuneration program (meals, transport, online English lessons, training platform access). Options for 12 or 14 monthly payments, work‑life balance measures, club and gym discounts.
Equal Opportunity Statement
UST is committed to equal opportunities in our selection processes and does not discriminate based on race, gender, disability, age, religion, sexual orientation, or nationality. We are particularly interested in hiring people with disability certificates.
#J-18808-Ljbffr
📌 Exposure Management Technical Expert - Penetration Testing Focus | Madrid at UST - UST
🏢 Ust
📍 Madrid