19 ago
|
Werfen
|
Cataluña
This position is part of the Product Security Department and is responsible for assessing and improving the security posture of the organization's products, applications, cloud environments, and enterprise infrastructure through offensive security activities.
The primary responsibility of this position is to identify, validate, and communicate security vulnerabilities before they can be exploited by attackers. The role involves performing penetration tests, security assessments, and adversary simulations across traditional IT environments, cloud platforms, modern applications, and Artificial Intelligence (AI) systems.
The engineer will collaborate with development, infrastructure, cloud, and engineering teams to improve the organization's overall security posture by providing actionable remediation guidance and security best practices.
- Plan and execute penetration tests of healthcare products, applications, medical devices, and supporting infrastructure in accordance with defined testing methodologies and project timelines.
- Perform security assessments of web applications, APIs, desktop applications, embedded systems, cloud environments, and AI-enabled products to identify exploitable vulnerabilities and security weaknesses.
- Evaluate the security of cloud-native architectures, identity services, and containerized environments supporting healthcare solutions.
- Assess Artificial Intelligence features and applications for security risks, including prompt injection, unauthorized access, sensitive data exposure, and misuse of AI models.
- Contribute to the continuous improvement of penetration testing methodologies, tooling, automation, and testing procedures to address emerging technologies and evolving threats.
- Stay current with the latest offensive security techniques, healthcare cybersecurity threats, cloud technologies, and AI security research to ensure testing methodologies remain effective and aligned with industry best practices.
- Collaborate with product development and engineering teams to communicate security findings, provide technical guidance, and support secure product development throughout the product lifecycle.
- Validate the effectiveness of implemented security fixes through remediation verification and follow-up security testing.
- Produce high-quality technical reports that clearly describe findings, risk levels, exploitation evidence, and practical remediation recommendations for engineering teams.
Networking/Key relationships
A cybersecurity engineer interacts with different stakeholders including:
- Software Development teams to coordinate security assessments, communicate technical findings, and support the remediation and validation of identified vulnerabilities.
- Quality Assurance (QA) teams to integrate penetration testing activities into product release cycles and verify security fixes prior to deployment.
- Cloud Engineering and DevOps teams to assess cloud infrastructure, containerized environments, CI/CD pipelines, and cloud-native services, providing recommendations to improve security posture.
- Product Owners (PO) and Product Security Officers (PSO) to define assessment scope, prioritize security risks based on business impact, and support secure product releases.
- Product Security Architects (PSA) to align penetration testing activities with organizational security strategies, threat models, and vulnerability management processes.
Minimum Knowledge & Experience required for the position:
The qualifications required for this position are:
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or equivalent practical experience.
Minimum professional experience:
- 4+ years in Offensive Security, Penetration Testing or Red Teaming.
Experience in several of the following areas:
- API and Web Application pentesting.
- Cloud security (AWS, GCP and Azure).
- Docker and Kubernetes security
- AI security assessments.
- Active Directory
- Reverse Engineering and Binary Exploitation capabilities.
The following work experience and qualifications are a plus:
- Certifications such as: eJPT, OSCP, CPTS, CRTO, CRTE, or equivalent.
- Knowledge of security frameworks such as OWASP and MITRE ATT&CK.;
Additional valuable experience
- Experience in Red Teaming Operations
- Experience in CTFs in platforms such as Hack The Box
- Knowledge of relevant standards such as ISO 27001.
- Knowledge of medical device regulations (FDA, GDPR).
- Solid knowledge on SW testing process and secure methodology (SSDLC).
Skills & Capabilities:
The skills and capabilities required by the position are:
- Strong analytical and problem-solving skills to identify, validate, and assess security vulnerabilities and recommend effective remediation strategies.
- Effective communication skills to convey complex cybersecurity concepts to both technical and non-technical stakeholders.
- Willingness to stay updated on the latest cybersecurity trends, threats and technologies through continuous learning and professional development.
- Ability to collaborate with cross-functional teams, share information, and work together to enhance overall cybersecurity posture.
- Strong interpersonal skills with the ability to build trust, foster teamwork, and contribute positively to a collaborative working environment.
Travel requirements:
Less than 10% of the time
📌 IT Cybersecurity Engineer (Cataluña)
🏢 Werfen
📍 Cataluña