Penetration Tester (Mid/Senior Level)
EBRD · Sofia, BG · Bulgaria · On-site
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Requisition ID
37058
Office Country
Bulgaria
Office City
Sofia
Division
Information Technology
Contract Type
Fixed Term
Contract Length
3 years
Posting End Date
12/10/2026
Are you a cyber expert with a passion for finding the cracks before the threat actors do? We’re searching for an Offensive Security Expert to join the front lines of our cyber defence. You’ll lead offensive security operations, scanning systems, probing weaknesses, and simulating real-world attacks using standard offensive tooling. From validating vulnerabilities through hands-on exploitation to crafting custom scripts that expose hidden threats, your work will drive critical security insights and real-time risk reduction.
This role is built for someone with deep technical expertise and an hacker mindset, fluent in web technologies and the inner workings of modern attack vectors. You’ll also dive into threat intelligence, develop hypotheses, and contribute to smarter detection strategies. If you’re driven to outsmart adversaries, influence real-world defence strategies, and play an key role in proactive security, your next mission starts here.
Accountabilities & Responsibilities
Plans, develops and executes vulnerability scans of organization information systems
Perform penetration tests on variety of assets. (web, mobile, network)
Identifies and resolves false positive findings in assessment results
Performs reconnaissance and information collection on the target environment or attack surface
Identifies potential weaknesses and vulnerabilities on assets (i.e., endpoints, applications, users)
Validates weaknesses via exploitation, and reports their findings
Recommends security controls and/or corrective actions for mitigating technical and business risk
Creates hypotheses for analytics and testing of threat data
Analyses data from threat and vulnerability feeds and analyses data for applicability to the organisation
Generates reports on assessment findings and summarises to facilitate remediation tasks
Shares lessons learned, initial indicators of detection and opportunities for strengthening signature-based detection capabilities
Knowledge, Skills, Experience & Qualifications
Highest level of technical expertise in cybersecurity, including deep familiarity with relevant penetration and intrusion techniques and attack vectors
Strong understanding of web technologies
Solid grasp of core security fundamentals and concepts
Knowledge of offensive tools such
Proficient at creating their own exploits in their preferred language
Technical knowledge in system security vulnerabilities and remediation techniques, network and web-related protocols.
Technical knowledge in security engineering, system and network security, authentication and security protocols
The following certifications desired but not essential: OSCP, OSEP, OSWE, CPTS, CWEE,…