Senior Cybersecurity Penetration Tester (f/m/div.)

Bosch Global Software (BGSW)•Aveiro, , Portugal•Hybrid

About the Role

As a Senior Penetration Tester, you will play a central role in identifying, assessing, and mitigating security vulnerabilities across our digital ecosystem. You will lead complex technical evaluations spanning modern web applications, backend architectures, APIs, and cloud-native environments, helping engineering teams build resilient, secure-by-design solutions.Your contribution to something big:Drive Offensive Security: Plan, scope, and execute comprehensive penetration tests on modern web applications, backend microservices, REST/GraphQL APIs, and cloud-native environments (AWS, Azure, or GCP).Threat Modeling & Architecture Review: Collaborate closely with development and DevOps teams early in the design phase to conduct threat modeling and review architectures, ensuring security is baked in from day one.Vulnerability Analysis & Exploitation: Perform deep-dive manual and automated vulnerability analyses, uncovering complex flaws like business logic bypasses, authorization failures, and server-side request forgeries.Technical Reporting & Remediation Guidance: Author high-quality, actionable technical reports that translate complex technical risks into clear business impacts, providing pragmatic remediation guidance to our engineering squads.Tooling & Innovation: Develop custom testing scripts and explore cutting-edge offensive workflows, including integrating AI-assisted security testing and LLM-augmented vulnerability analysis to maximize speed and coverage.What distinguishes you: EducationDegree in Computer Science, Cybersecurity, IT, Software Engineering, or equivalent practical experience in offensive security.ExperienceHands-on experience (ideally 3+ years) conducting technical security assessments, with a strong focus on web applications, APIs, and cloud infrastructure.Know howOffensive Security Expertise: In-depth knowledge of backend technologies, secure protocols, and security standards (e.g., OWASP Top 10, ASVS, WSTG, OAuth 2.0).Cloud & Modern Tech: Solid familiarity with assessing cloud environments (AWS, Azure, or GCP), IAM configurations, container security (Docker, Kubernetes), and microservices.Tools & Scripting: High proficiency with industry-standard offensive tools (e.g., Burp Suite Pro, OWASP ZAP, Postman) combined with scripting skills (e.g., Python, Bash) to automate testing workflows.LanguagesExcellent communication skills with fluency in English (written and spoken) to effectively present findings to both technical teams and business stakeholders.Working Style and MethodsAn analytical and structured problem-solver who enjoys working collaboratively across cross-functional teams to build collective security resilience.PersonalityA curious, continuous learner with a passion for offensive security, exploring new technologies, and a strong drive to mentor and share knowledge with others.We also welcome (Preferred / Nice-to-have):Enthusiastic interest or experience in AI-driven offensive workflows (e.g., automated payload generation, LLM security evaluations).Industry certifications such as OSCP, OSWE, OSCE, CRTP, GWAPT, GPEN, or cloud-specific security certifications.Experience with source code reviews (SAST) in common modern languages (Java, Python, Go, TypeScript).Work #LikeABosch includes: ⚖️ Flexible work conditions🔀 Hybrid work system🌐 Exchange with colleagues around the world🧑‍⚕️ Health insurance and medical office on site (general surgeon, psychology, physiotherapy, general clinic)📚 Training opportunities (p.e., technical training, foreign languages training) & certifications📈 Opportunities for career progression and continuous professional development💲 Access to great discounts in partnerships and Bosch products🏋️ Sports and health related activities💰 Flexible benefits platform🅿️ Free parking lot🍽️ Canteen Success stories don´t just happen. They are made...Make it happen! We are looking forward to your application!