Mid-level Security Engineer Vulnerability & Pen Test
European Bank for Reconstruction and Development
- Location:
- Sofia, Bulgaria
- Category:
- Professional Staff
Posted Sep 9, 2026Apply by Sep 30, 2026 (8d left)
See your match score & applyThe role involves leading offensive security operations including vulnerability scanning, penetration testing, and threat intelligence analysis to identify and mitigate security risks. The position requires deep technical expertise in cybersecurity and a hacker mindset to proactively defend the organization's information systems.
Responsibilities
- Plans, develops and executes vulnerability scans of organization information systems
- Identifies and resolves false positive findings in assessment results
- Performs reconnaissance and information collection on the target environment or attack surface
- Identifies potential weaknesses and vulnerabilities on assets (i.e., end points, applications, users)
- Validates weaknesses via exploitation, and reports their findings
- Recommends security controls and/or corrective actions for mitigating technical and business risk
- Creates hypotheses for analytics and testing of threat data
- Analyses data from threat and vulnerability feeds and analyses data for applicability to the organisation
- Generates reports on assessment findings and summarises to facilitate remediation tasks
- Shares lessons learned, initial indicators of detection and opportunities for strengthening signature-based detection capabilities
Requirements
- Highest level of technical expertise in cybersecurity, including deep familiarity with relevant penetration and intrusion techniques and attack vectors
- Strong understanding of web technologies
- Solid grasp of core security fundamentals and concepts
- Familiarity with the Open Web Application Security Project (OWASP) top 10 vulnerabilities
- Knowledge of offensive tools such as: Metasploit, Kali Linux, Cobalt Strike, Mimikatz or a similar tool
- Proficient at creating their own scripts regular expressions in their preferred scripting language
- Technical knowledge in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, etc.)
- Technical knowledge in security engineering, system and network security, authentication and security protocols
- The following certifications desired but not essential: Certified ethical hacker (CEH), global information assurance certification (GIAC), GIAC certified pen tester (GPEN), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), offensive certified security professional (OSCP) and offensive security certified (OSC)
Skills
- Cybersecurity
- Basic Penetration Testing
- Intrusion Techniques
- Web Technology
- Security Fundamentals
- OWASP Top 10
- Metasploit
- Kali Linux
- Cobalt Strike
- Mimikatz
- Scripting
- Regular Expressions
- System Security Vulnerabilities
- Remediation Techniques
- Networking Protocols
- Web Protocols
- Security Engineering
- System Security
- Network Security
- Security Protocols
Languages
English