Information Security Engineer – Senior Penetration Tester (Madrid)

Information Security Engineer – Senior Penetration Tester (Madrid)

08 oct
|
Ryanair Group Holdings
|
Madrid

08 oct

Ryanair Group Holdings

Madrid

Job Description

About the role
A hands-on, individual-contributor role in a lean airline security team. You find exploitable weaknesses before attackers do across web and mobile applications, APIs, internal networks, identity and multicloud (AWS, GCP, Azure) including the AI-enabled systems we build and buy. You don't stop at the report: you prove impact, drive fixes with owners, re-test, and turn what you learn into detection and hardening requirements.

How you'll work: scope → test → prove → fix → verify

- Scope. Maintain an attack-surface inventory (external, internal, cloud, SaaS, AI systems); threat-model with owners; define rules of engagement and safety constraints, especially around operational systems.
- Test. Manual-first testing following recognised methodologies (OWASP WSTG/ASVS/MASVS, PTES, MITRE ATT&CK;), with automation for breadth.
- Prove. Demonstrate real impact with safe proof-of-concept exploits and attack chains; rate with CVSS plus business context. Scanner output is not a finding.
- Fix. Write remediation owners can act on; pair with engineers; convert findings into detection requirements and control improvements for the detection team.
- Verify. Re-test,



track closure, measure time-to-remediate and recurrence.

What you'll do

- Test passenger-facing and internal web, mobile and API applications.
- Test internal/external networks, Active Directory / Entra ID and identity attack paths.
- Cloud penetration testing across AWS, GCP and Azure: IAM privilege escalation, misconfigurations, exposed services, CI/CD and secrets.
- AI/LLM application testing: direct and indirect prompt injection, jailbreaks, insecure output handling, excessive agency and tool abuse, RAG data leakage and poisoning, agent/MCP integration weaknesses mapped to OWASP Top 10 for LLM Applications and MITRE ATLAS.
- Run adversary emulation and purple-team exercises with detection engineering.
- Build and maintain tooling and automation; use LLM assistants and agentic coding tools (Claude Code, OpenCode) for recon automation, PoC development, output parsing and report drafting, validating results and respecting data-handling boundaries.
- Write clear reports and executive summaries; present findings to engineers and leadership.

📌 Information Security Engineer – Senior Penetration Tester (Madrid)
🏢 Ryanair Group Holdings
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: information security engineer – senior penetration tester (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: information security engineer – senior penetration tester (madrid) / madrid