Hotelbeds logo
HotelbedsPosted 1 month ago

Security Expert (Red Team)

On-siteValencia, Valencia, Spain

Full TimeLargeTravel Services

Job Summary

Conduct penetration testing across web applications, APIs, cloud platforms, and infrastructure to identify vulnerabilities, attack paths, and exposure risks. Execute realistic Red Team engagements using MITRE ATT&CK methodologies to emulate threat actors and validate detection capabilities. Assess Generative AI, LLMs, and machine learning systems for prompt injection, data poisoning, and supply chain threats while collaborating on secure-by-design solutions. Perform source code reviews and cloud configuration assessments for AWS, Azure, and GCP to mitigate misconfigurations and privilege escalation opportunities. Partner with Blue Team, DevOps, and engineering groups to remediate findings and strengthen cyber resilience throughout the software development lifecycle.

Required Qualifications

  • Previous experience in a Red Team, Penetration Testing, Offensive Security or equivalent security-focused role
  • Strong understanding of offensive security methodologies, attack techniques and adversary emulation practices
  • Up-to-date knowledge of cyber security threats, exploitation techniques and offensive tooling
  • Experience performing vulnerability assessments, penetration testing and security validation activities
  • Knowledge of application security, secure development practices and source code reviews
  • Good understanding of DevOps and Agile principles, with the ability to support security activities in fast-moving delivery environments
  • Knowledge of cloud and container technologies, including Kubernetes, Docker and cloud environments such as AWS, GCP or Azure
  • Experience using scripting languages and automation tools to improve offensive security capabilities and testing efficiency

Desired Qualifications

  • Ability to translate technical security findings into clear risk-based recommendations
  • Strong analytical mindset, with the ability to investigate complex attack scenarios and identify realistic exploitation paths
  • Good collaboration skills, with the ability to work effectively with Security, Engineering, DevOps and infrastructure teams
  • Proactive approach to learning and staying current with emerging threats, attack techniques and security technologies
  • Ability to balance security requirements with business priorities in agile and cloud-based environments

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce