We're looking for a senior security pentester to test IoT devices, embedded systems, cloud infrastructure and applications. You'll lead authorised assessments independently, from scoping and rules of engagement to reporting and remediation.
What you'll do
- Analyse architectures, data flows and attack surfaces.
- Perform black-box, grey-box and white-box .
- Develop proof-of-concepts for controlled exploitation.
- Produce reproducible technical reports and executive summaries.
- Advise on remediation and retest fixes.
- Mentor less experienced security specialists.
What you bring
- At least 10 years of experience in offensive security.
- Firmware analysis, UART/JTAG/SWD, OTA updates and secure boot.
- , DNS, HTTP/HTTPS, REST//WebSocket/, MQTT/AMQP/CoAP, RTSP, VPN, Wi-Fi/BLE and TLS/mTLS/PKI.
- , AWS or GCP: IAM, segmentation, storage, databases, and .
- and /iOS security, including 2.0/OIDC/SAML/JWT.
- , , , post-exploitation and lateral movement.
- : WSTG, ASVS, Top 10, API Security Top 10 and MASVS/MSTG.
- or Parrot; or ZAP; , Wireshark, Nessus, Metasploit and Impacket.
- , , and at least one additional programming language.
- Higher degree in IT, , electronics or telecommunications, or equivalent professional experience.
- (B2).
- (B2).
- (B2).
Nice to have
- Offensive security certifications such as /OSCP+, OSWE, OSEP, GPEN/GWAPT or SEC556/PIPA.
What's next?
The people who do well here are the ones who saw themselves in this description. Not because they match every line, but because the mission felt right for them.
We are actively hiring for this position. Applications are reviewed by our team, and matching profiles receive a call to discuss the role in detail.
It takes under a minute to apply. Your email, your CV. That is all we need to start the conversation.

