Penetration Tester / Security Engineer (m/f)
On-siteLuxembourg, Luxembourg, Luxembourg or Lu, Piemonte, Italian Republic
Job Summary
Conduct automated and manual penetration testing of web, mobile applications, and cloud/on-premises infrastructures while identifying security weaknesses and proposing mitigation strategies. Analyze customer security requirements, recommend technical solutions, and prepare clear reports with findings. Collaborate with developers and security engineers to improve application security posture, evaluate testing methodologies, and contribute to secure software development practices throughout the lifecycle. Work on various security projects within an international environment, sharing knowledge to drive continuous improvement initiatives. Requires in-person collaboration time; offers flexible work/life support. Join a team supporting complex public sector IT projects for Accenture.
Required Qualifications
- Minimum 2 years of experience in penetration testing or application security
- Experience performing internal penetration tests and/or participating in Red Team exercises
- Good knowledge of penetration testing tools such as Burp Suite Professional, Nmap, Metasploit, Nessus, and Kali Linux
- Good understanding of: OWASP Top 10
- Good understanding of: MITRE ATT&CK
- Good understanding of: DevSecOps and Secure SDLC principles
- Good understanding of: OSI/TCP networking concepts
- Good understanding of: Cloud security principles (AWS/Azure)
- Familiarity with one or more programming or scripting languages such as Java, C/C++, PHP, or Python
- Strong analytical, problem-solving, and communication skills
- Curiosity, creativity, and willingness to continuously learn new technologies and attack techniques
- Experience working in Agile environments
- Fluency in English (written and spoken)
- Master's degree in Computer Science, Information Security, or a related field is preferred
Desired Qualifications
- Experience developing custom exploits or participating in bug bounty platforms such as HackerOne, Hack The Box, or TryHackMe
- Previous experience as a software developer
- One or more of the following certifications: OSCP
- One or more of the following certifications: OSWE
- One or more of the following certifications: eCPPTv2
- One or more of the following certifications: CHFI
- One or more of the following certifications: GIAC GPEN
- One or more of the following certifications: AWS Certified Security – Specialty
- One or more of the following certifications: Azure Security Engineer Associate
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.