Description
Summary:
Seeking a skilled Penetration Tester to conduct offensive security assessments, identify vulnerabilities, simulate real-world attacks, and support incident response activities within enterprise environments.
Highlights:
1. Support offensive security assessments and incident response activities
2. Conduct web, network, cloud, and Active Directory penetration tests
3. Collaborate with DFIR, SOC, and security operations teams
Location: Leca do Balio, Portugal**About the Role**
We are looking for a skilled **Penetration Tester** to support **offensive security assessments** and **incident response activities** across enterprise environments.
In this role, you will identify vulnerabilities, simulate real\-world attack scenarios, and collaborate closely with **DFIR, SOC, and security operations teams**. The position combines advanced penetration testing with hands\-on support during cyber incidents, threat investigations, and continuous security improvement initiatives.
**Key Responsibilities**
* Conduct **web, network, cloud, and Active Directory penetration tests** using modern offensive security techniques and tools.
* Support **incident response engagements**, including forensic analysis, threat hunting, containment validation, and attacker activity reconstruction.
* Prepare **detailed technical reports and executive summaries** with clear, actionable remediation recommendations.
* Collaborate with **blue team, DFIR, SOC, and security engineering teams** to improve detection capabilities and validate security controls.
* Contribute to strengthening the organization’s **cyber resilience** through proactive testing and technical analysis.
**Requirements**
* Minimum **3****years of experience** in penetration testing or offensive security roles.
* Strong hands\-on experience in:
+ Web and API security testing
+ Network and infrastructure assessments
+ Cloud security testing
+ Active Directory security
* Experience supporting or collaborating with **incident response (DFIR) teams**.
* Ability to communicate technical findings clearly to both **technical and non\-technical stakeholders**.
* **Portuguese (C1\)** and **English (C1\)** proficiency.
* Availability for **medium travel**.
**Preferred Qualifications**
* Offensive Security certifications:
+ **OSCP, OSEP, OSWE**
* SANS certifications:
+ **GPEN, GCFA**
* Experience in:
+ Threat hunting and forensic analysis
+ Security validation and purple teaming
+ Attack simulation and adversary techniques
**What We Offer**
* Competitive compensation package and benefits.
* Opportunity to work on **advanced offensive security and incident response projects**.
* Continuous training and access to **certifications and learning programs**.
* Collaborative environment with **SOC, DFIR, and Threat Intelligence teams**.
* Hybrid/office flexibility (depending on local policy) and **international exposure**.
YOUR CAREER AT THALES
Future opportunities will allow you to discover other domains or sites. You will be able to evolve and grow your competences in different areas:
Room and attention to personal development
Build your talents in another domain of Thales Group, discovering new products, new customers, new country or go to a more complex Solution
Choose between a technical expertise or a leadership path
Build an international career within a leading Engineering Group