04 ago
|
Bank Julius Bär Ltd.
|
Madrid
04 ago
Bank Julius Bär Ltd.
Madrid
ph3Responsibilities /h3ulliFindings Verification: Reproduce and validate mitigation of vulnerabilities using tools such as Burp Suite. /liliTechnical Quality Assurance: Perform in-depth reviews of penetration testing reports to ensure clarity, completeness, technical accuracy, and reproducibility of findings. /liliScoping Support: Collaborate with Exposure Managers, Application Owners, and Technology teams to define appropriate and risk‑based scopes for external penetration testing engagements. /liliHardening Baseline: Discuss with Technology teams and architects hardening options to collectively define safe and resilient baseline choices. /liliTechnical Advisory: Serve as the technical point of contact for questions related to technology security testing methodologies, findings interpretation, and remediation approaches. /liliTooling Techniques: Utilize industry‑standard tools (e.g., Burp Suite, Nmap) and manual techniques to validate vulnerabilities across web applications, APIs, and supporting infrastructure. /liliStandards Alignment: Ensure testing approaches and findings align with industry’s best practices (e.g., OWASP Testing Guide, OWASP Top 10) and internal security standards. /liliFalse Positive Management: Analyze and challenge reported vulnerabilities where necessary, identifying false positives and ensuring appropriate classification. /liliRemediation Support: Provide technical guidance to development and infrastructure teams on how to address identified vulnerabilities effectively and sustainably. /liliKnowledge Sharing: Contribute to the continuous improvement of internal practices by sharing insights, patterns, and lessons learned across teams. /liliCollaboration:
Work closely with Exposure Managers and general technical experts to ensure consistent quality and execution across all penetration testing activities. /li /ulh3Requirements /h3ulliBachelor’s degree in computer science, information security, or equivalent practical experience. /lili3–5 years of hands‑on experience in penetration testing, application security, or vulnerability assessment. /liliStrong practical experience with web application security testing and tools (e.g., Burp Suite). /liliSolid understanding of common vulnerabilities (e.g., OWASP Top 10) and exploitation techniques. /liliAbility to read, understand, and reproduce technical findings from penetration testing reports. /liliExperience with HTTP/S protocols, authentication mechanisms, and modern web architectures (APIs, microservices). /liliStrong analytical and problem‑solving skills with attention to detail. /liliEffective communication skills, especially in explaining technical issues to non‑technical stakeholders. /liliProfessional proficiency in English and Spanish; eligible to work in Spain. /li /ulh3Preferred Qualifications /h3ulliRelevant certifications (e.g., OSCP, eWPT, CEH, GWAPT, Burp Suite Certified Practitioner). /liliExperience reviewing third‑party security assessment reports or managing testing vendors. /liliFamiliarity with infrastructure/network penetration testing concepts. /liliExperience in secure code review or secure development practices. /liliScripting or programming skills (e.g., Python, JavaScript) for automation or advanced testing. /liliExperience in financial services or regulated environments. /liliExposure to CI/CD security integration or DevSecOps practices. /liliGerman language skills. /li /ul /p #J-18808-Ljbffr
📌 Exposure Management Technical Expert 100% (f/m/d) (Madrid)
🏢 Bank Julius Bär Ltd.
📍 Madrid