Pentester Web (m/f/d)
- Luxemburg
- Unbefristet
- Vollzeit
- Work on penetration testing projects with a strong focus on web applications, APIs, and other internet-facing assets.
- Identify, validate, and document vulnerabilities affecting modern applications, including access control flaws, authentication weaknesses, injection issues, business logic vulnerabilities, and other common web security risks.
- For more senior profiles, define testing strategies, scope complex assessments, and guide the execution of engagements to ensure high-quality technical delivery.
- Produce clear, concise, and technically accurate penetration test reports for both technical and executive audiences.
- Present findings and recommendations to clients, and support debriefing sessions with technical teams, project stakeholders, and management.
- Contribute to the preparation of proposals for penetration tests and technical projects, including effort estimation and scoping.
- Help improve our labs, tooling, knowledge base, and internal methodologies for web and API security testing.
- Contribute to a culture of continuous learning through mentoring, technical exchanges, and shared research.
- Get involved in pre-sales discussions, scoping, budget sizing, project management, and other growth areas depending on your personal career aspirations, or, alternatively, deepen your technical expertise in application security testing.
- Work with a global network, collaborating with colleagues across offices worldwide and contributing to our broader cybersecurity expertise.
- Evolve in a high-performing team that values trust, flexibility, and balance.
- Be part of a team where R&D is not marketing language but a real part of the job. We invest time in hands-on research, practical experimentation, reproducing emerging attack techniques, and refining application security tradecraft.
- Join colleagues who attend and contribute to leading cybersecurity events including DEF CON, Hack.lu, leHACK, BruCON, Black Alps, and BSides Luxembourg, and who publish and share their expertise with the wider community. In 2025, four team members presented internal research at Hack.lu. The next one could be you
- Have a strong academic background in Computer Science, Network Engineering, Cybersecurity, Offensive Security, or a related field.
- Are technically curious and driven to understand how web applications fail and how attackers abuse them.
- Enjoy learning by doing and want to sharpen your offensive skills through real-world application security assessments.
- Bring experience according to your level, from strong potential and first hands-on exposure for junior candidates to proven web application penetration testing experience for senior profiles.
- Have hands-on familiarity with web testing tools and techniques, such as Burp Suite or equivalent, intercepting and manipulating web traffic, manual testing, scripting, and vulnerability validation.
- Are familiar with common web application security standards, testing methodologies, and guidance, such as the OWASP Top 10, OWASP Testing Guide, and API security best practices, and can apply them in practice.
- Have a solid understanding of web technologies, authentication mechanisms, modern application architectures, and common web application security concepts.
- Can communicate clearly and professionally in English, both verbally and in writing. Additional languages are a plus.
- Value ethics, discretion, and professionalism.
- Thrive both autonomously and as part of a strong team.
- For more senior profiles, are comfortable leading client engagements, coordinating assessment activities, mentoring junior colleagues, and acting as a technical point of contact.
- Have prior experience in offensive security, cybersecurity consulting, or hands-on web application security testing.
- Hold recognised certifications such as OSWE, OSCP, OSEP, or equivalent.
- Have shared knowledge with the community through talks, blogs, tools, open source, research, or CVEs.
- Have an interest in offensive R&D and staying close to the evolution of web exploitation techniques and attacker tradecraft.
- Know the Luxembourg market and/or its regulatory environment.