10 oct
|
Ryanair
|
Madrid
Experteer Overview
In this hands-on, individual-contributor role, you will identify exploitable weaknesses across web, mobile, APIs, networks, identity, and multi-cloud environments (AWS, GCP, Azure) including AI-enabled systems. You’ll prove impact with safe exploits, drive fixes with owners, and translate findings into detection and hardening requirements. You work across scope, test, prove, fix, and verify to shorten remediation cycles and strengthen security. You’ll collaborate with engineering and detection teams, shaping defense across the tech stack in aviation-focused systems.
Compensaciones / Incentivos
• Scope the attack surface and model threats across external, internal, cloud, SaaS, and AI systems
• Conduct manual-first testing following established methodologies (OWASP WSTG/ASVS/MASVS, PTES, MITRE ATTu0026CK) with automation for breadth
• Demonstrate real impact with safe PoC exploits and attack chains; rate findings with CVSS plus business context
• Collaborate with remediation owners to fix issues and convert findings into detection requirements and control improvements
• Re-test, track closure, and measure time-to-remediate and recurrence
• Test passenger-facing and internal web, mobile, and API apps
• Assess internal/external networks, AD/Entra ID, and identity attack paths
• Perform cloud pentesting across AWS, GCP, Azure focusing on IAM and identity paths
• Test AI/LLM applications for prompt injection, jailbreaks, and data leakage,
mapped to OWASP Top 10 for LLMs and MITRE ATLAS
• Run adversary emulation and purple-team exercises with detection engineering
• Build and maintain tooling and automation; validate results using LLM assistants and coding tools while respecting data handling boundaries
• Prepare clear reports and executive summaries; present findings to engineers and leadership
Responsabilidades
• 4+ years hands-on penetration testing / offensive security
• Strong web/API and network/AD testing with manual exploitation
• Cloud pentesting in at least two of AWS, GCP, Azure (IAM and identity paths)
• Scripting in Python (plus Bash/PowerShell); able to read/modify/write exploits and tooling
• Practical use of MITRE ATTu0026CK and OWASP methodologies; CVSS and risk-based reporting
• AI skillset: daily use of LLM assistants and agentic coding tools with validation; knowledge of LLM applications, RAG pipelines, and ATLAS; ability to design/run tests against AI systems
• Safe testing discipline in production and safety-critical environments; strict rules of engagement
• Clear written and verbal communication to technical and non-technical stakeholders
Requisitos principales
• competitive technical career plan
• career growth in a growing team
• hybrid work model up to three days remote
• modern Madrid offices
• health insurance discounts
• travel discounts
📌 Information Security Engineer - Senior Penetration Tester (Madrid)
🏢 Ryanair
📍 Madrid