Gmv logo
Moves you to
Spain
Support
Relocation support
Posted
Sep 28, 2026
Is this job info correct?
Pentester Senior

Do you want to participate in advanced offensive security assessments? The GMV Technical Audits team is looking for you!

We´ll get to the point; we'll tell you what's not on the web. If you want to know more about de GMV

WHAT CHALLENGE WILL YOU BE TAKING ON?

As a Senior Pentester, you will not only execute technical assessments but also design realistic attack scenarios based on MITRE ATT&CK TTPs and lead audit projects, helping organizations understand how they could be compromised… before a real attacker does.

You will work on web and mobile applications, network infrastructures, Wi-Fi networks, cloud environments (AWS, Azure, GCP), Active Directory and AI-based systems.

You will also participate in Red Team and Purple Team exercises, simulating real attacks and collaborating with Blue Team professionals to improve threat detection and response capabilities.

In your day-to-day work you will:
🛠️ Execute and lead penetration tests in complex corporate environments.
🎯 Participate in Red Team exercises, applying evasion techniques against EDR, XDR, WAF and antivirus solutions.
🔎 Identify vulnerabilities, analyze their impact and propose effective mitigation strategies.
⚙️ Develop or adapt offensive tools and automations using Python, Bash or PowerShell.
📝 Produce clear technical and executive reports focused on risk.
🗣️ Present findings to both technical and business audiences.
📊 Manage technical audit projects, coordinating scope, timelines and deliverables.

WHAT DO WE NEED IN OUR TEAM?

We are looking for someone with strong experience in offensive cybersecurity, comfortable working in complex environments and able to independently lead technical security assessments.

For this position, it is important to have:
🏅 5+ years of experience in penetration testing (web, mobile, network, cloud, Active Directory, Wi-Fi).
🕵️ Experience in Red Team operations designing and executing simulated attacks.
🧰 Advanced knowledge of tools such as Burp Suite, Nmap, Metasploit or C2 frameworks.
💻 Ability to automate offensive tasks through scripting (Python, Bash or PowerShell).
📄 Experience producing technical and executive reports focused on risk.
🤝 Strong communication skills and ability to present results clearly.
📌 Experience managing cybersecurity or technical audit projects.
🎓 Offensive certifications such as OSCP, OSEP, OSWE, eCPPT, CRTP or equivalent.
📚 Knowledge of frameworks and methodologies such as PTES, MITRE ATT&CK or OWASP.
🤖 Experience assessing security in AI or LLM-based systems (OWASP Top 10 for LLMs).

WHAT DO WE OFFER?

🕑 Hybrid working model and 8 weeks per year of teleworking outside your usual geographical area.

💻 Flexible start and finish times, and intensive working hours Fridays and in summer.

🚀 Personalized career plan development, training and language learning support.

🌍 National and international mobility. Do you come from another country? We can offer you a relocation package.

💰 Competitive compensation with ongoing reviews, flexible compensation and discount on brands.

💪Wellbeing program: Health, dental and accident insurance; free fruit and coffee, physical, mental and financial health training, and much more!

⚠️ In our recruitment processes you will always have telephone and personal contact, face-to-face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through another process, please get in touch with the person responsible for the selection process.

❤️ We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.

WHAT ARE YOU WAITING FOR? JOIN US

#LI-Hybrid

Similar jobs

Apply for this job