Penetration Tester (Mid/Senior Level)

European Bank for Reconstruction and Development

Location:
Sofia, Bulgaria
Category:
Professional Staff
Posted Sep 9, 2026Apply by Sep 30, 2026 (8d left)
See your match score & apply

The Penetration Tester will lead offensive security operations by performing vulnerability scans, penetration tests, and exploitation to identify and mitigate security risks. The role involves analyzing threat intelligence and contributing to the development of detection strategies to enhance the organization's cyber defense posture.

Responsibilities

  • Plans, develops and executes vulnerability scans of organization information systems
  • Perform penetration tests on variety of assets (web, mobile, network)
  • Identifies and resolves false positive findings in assessment results
  • Performs reconnaissance and information collection on the target environment or attack surface
  • Identifies potential weaknesses and vulnerabilities on assets (i.e., endpoints, applications, users)
  • Validates weaknesses via exploitation, and reports their findings
  • Recommends security controls and/or corrective actions for mitigating technical and business risk
  • Creates hypotheses for analytics and testing of threat data
  • Analyses data from threat and vulnerability feeds and analyses data for applicability to the organisation
  • Generates reports on assessment findings and summarises to facilitate remediation tasks
  • Shares lessons learned, initial indicators of detection and opportunities for strengthening signature-based detection capabilities

Requirements

  • Highest level of technical expertise in cybersecurity, including deep familiarity with relevant penetration and intrusion techniques and attack vectors
  • Strong understanding of web technologies
  • Solid grasp of core security fundamentals and concepts
  • Knowledge of offensive tools
  • Proficient at creating their own exploits in their preferred language
  • Technical knowledge in system security vulnerabilities and remediation techniques, network and web-related protocols
  • Technical knowledge in security engineering, system and network security, authentication and security protocols
  • The following certifications desired but not essential: OSCP, OSEP, OSWE, CPTS, CWEE, CWES, CAPE

Skills

  • Cybersecurity
  • Basic Penetration Testing
  • Intrusion Techniques
  • Attack Vectors
  • Web Technology
  • Security Fundamentals
  • Offensive Security Tools
  • Exploit Development
  • Computer Security Vulnerabilities
  • Remediation Technologies
  • Networking Protocols
  • Web Protocols
  • Security Engineering
  • System Security
  • Network Security
  • Security Protocols
  • Vulnerability Auditing
  • Threat Intelligence
  • Detection Strategy Development