- Hiring from
- Portugal
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
About the role
We are looking for an experienced Senior Offensive Security Auditor to join our Offensive Security team in Portugal.
This is a hands-on senior role for an offensive security professional with strong experience in penetration testing, red teaming and security assessments, who will act as a technical reference for our Offensive Security activities in Portugal.
You will lead complex security assessments from planning through delivery, working closely with our SOC, DFIR, Threat Hunting, Threat Intelligence and Security Engineering teams to identify vulnerabilities, validate security controls and strengthen our customers' cyber resilience.
This role offers the opportunity to combine deep technical expertise, client interaction and technical leadership.
What you'll do
- Lead and deliver complex penetration testing, red team, adversary simulation and security assessment engagements.
- Define scope, testing approaches and methodologies for offensive security engagements.
- Perform hands-on security testing across web applications, APIs, infrastructure and cloud environments.
- Conduct vulnerability assessments, exploitation and security validation activities.
- Develop and execute adversary emulation and red team scenarios based on real-world attack techniques.
- Work closely with SOC, DFIR, Threat Hunting and Threat Intelligence teams to provide offensive security expertise and support security investigations when required.
- Identify, assess and communicate security risks, translating technical findings into clear and actionable remediation recommendations.
- Prepare high-quality technical reports and present findings to both technical and non-technical stakeholders.
- Act as a technical reference for Offensive Security activities in Portugal, supporting the quality and continuous improvement of local engagements.
- Contribute to the development and improvement of methodologies, playbooks, testing procedures and reporting standards.
- Support and share knowledge with other members of the offensive security team.
What you bring
Required
- 5+ years of professional experience in offensive security, penetration testing, red teaming or security auditing.
- Strong hands-on experience in:Web application and API security testing.Infrastructure and network penetration testing.Cloud security assessments.Vulnerability assessment and exploitation.Red Team / adversary simulation activities.
- Strong understanding of attack techniques, vulnerabilities and security controls.
- Ability to independently plan and deliver complex security assessments.
- Excellent analytical, reporting and communication skills.
- Ability to communicate technical risks and recommendations clearly to both technical and business stakeholders.
- Ability to work effectively with SOC, DFIR, Threat Intelligence and Security Engineering teams.
- English level C1.
- Professional working proficiency in Portuguese.
Nice to have
- Experience with Purple Team exercises and security control validation.
- Experience with cloud offensive security, mobile security, OT/ICS, IoT or social engineering.
- Experience supporting incident response or post-incident investigations from an offensive security perspective.
- Knowledge of frameworks such as MITRE ATT&CK and experience applying them to adversary simulation.
- Experience working directly with customers and presenting technical findings.
Certifications
Relevant certifications will be highly valued, including:
- Offensive Security: OSEP, OSCP, OSCE3
- SANS: GXPN, GPEN, GWAPT, etc.
- CREST: CCT, CCSAM, CCTIM or equivalent
- Altered Security: CRTE, CARTP
- Other recognised offensive security certifications
What we offer
- A senior technical role within a leading cybersecurity organisation.
- The opportunity to become a technical reference for Offensive Security in Portugal.
- Exposure to complex and diverse cybersecurity projects and customers.
- Continuous learning and professional development through training and certifications.
- Collaboration with highly experienced cybersecurity professionals across different areas and countries.
- Flexible working model according to local policy.
- Medium travel depending on project requirements.
- Competitive compensation package and benefits.
Your career at Thales
At Thales, your career can evolve in different directions. You will have the opportunity to develop your expertise, explore new technologies and work with international teams and customers.
You can continue developing as a technical cybersecurity expert, move towards technical leadership, or explore new areas and opportunities across the Thales Group.
Join Thales and help us build a safer digital world.
About Thales
In a world that is increasingly fast moving, unpredictable – and full of opportunities, trust is essential for societies to flourish. Trust in our institutions. Trust in our systems. Trust in technology. Trust in each other.
And the people we all rely on to make the world go round, they rely on Thales. They come to us with big ambitions: to make life better, to keep us safer.
From the bottom of the oceans to the depths of space and cyberspace, we help our customers navigate uncertainty with confidence and new frontiers with optimism. Thinking smarter and acting faster - mastering ever greater complexity and every decisive moment along the way.
We collaborate to architect and deliver high technology solutions that are both imaginative and resilient, human-centered and sustainable. So that together we can harness the extraordinary power of technology to build a future we can all trust.