Mid-level Security Engineer Vulnerability & Pen Test
EBRD Sofia, Sofia-City, Bulgaria
Banking · 1,001-5,000 employees
About the role
The role involves planning and executing vulnerability scans, performing reconnaissance on target environments, and validating weaknesses through hands-on exploitation. Additionally, the engineer will recommend security controls, analyze threat data, and contribute to the development of detection strategies.
What they look for
Requirements
Candidates must possess deep technical expertise in cybersecurity, including familiarity with penetration testing techniques and offensive security tools. A strong understanding of web technologies, security fundamentals, and the ability to script are essential for this position.
Benefits
Full description
Requisition ID 37058
Office Country Bulgaria
Office City Sofia
Division Information Technology
Contract Type Fixed Term
Contract Length 3 years
Posting End Date 30/09/2026
Are you a cyber expert with a passion for finding the cracks before the criminals do? We’re searching for an Offensive Security Expert to join the front lines of our cyber defense. You’ll lead offensive security operations, scanning systems, probing weaknesses, and simulating real-world attacks using standard offensive tooling. From validating vulnerabilities through hands-on exploitation to crafting custom scripts that expose hidden threats, your work will drive critical security insights and real-time risk reduction.
This role is built for someone with deep technical expertise and an hacker mindset, fluent in web technologies, OWASP Top 10, and the inner workings of modern attack vectors. You’ll also dive into threat intelligence, develop hypotheses, and contribute to smarter detection strategies. If you’re driven to outsmart adversaries, influence real-world defense strategies, and play an key role in proactive security, your next mission starts here.
Accountabilities & Responsibilities
- Plans, develops and executes vulnerability scans of organization information systems
- Identifies and resolves false positive findings in assessment results
- Performs reconnaissance and information collection on the target environment or attack surface
- Identifies potential weaknesses and vulnerabilities on assets (i.e., end points, applications, users)
- Validates weaknesses via exploitation, and reports their findings
- Recommends security controls and/or corrective actions for mitigating technical and business risk
- Creates hypotheses for analytics and testing of threat data
- Analyses data from threat and vulnerability feeds and analyses data for applicability to the organisation
- Generates reports on assessment findings and summarises to facilitate remediation tasks
- Shares lessons learned, initial indicators of detection and opportunities for strengthening signature-based detection capabilities
Knowledge, Skills, Experience & Qualifications
- Highest level of technical expertise in cybersecurity, including deep familiarity with relevant penetration and intrusion techniques and attack vectors
- Strong understanding of web technologies
- Solid grasp of core security fundamentals and concepts
- Familiarity with the Open Web Application Security Project (OWASP) top 10 vulnerabilities
- Knowledge of offensive tools such as: Metaspoit, Kali Linux, Cobalt Strike, Mimikatz or a similar tool
- Proficient at creating their own scripts regular expressions in their preferred scripting language
- Technical knowledge in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, etc.)
- Technical knowledge in security engineering, system and network security, authentication and security protocols
- The following certifications desired but not essential: Certified ethical hacker (CEH), global information assurance certification (GIAC), GIAC certified pen tester (GPEN), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), offensive certified security professional (OSCP) and offensive security certified (OSC)
What is it like to work at the EBRD? / About EBRD
Our agile and innovative approach is what makes life at the EBRD a unique experience! You will be part of a pioneering and diverse international organisation, and use your talents to make a real difference to people's lives and help shape the future of the regions we invest in.
At EBRD, our Values – Inclusiveness, Innovation, Trust, and Responsibility – are at the heart of how we work. We bring these to life through our Workplace Behaviours: listening well and speaking up, collaborating smartly, acting decisively with full commitment, and simplifying to amplify our impact. These principles shape our culture and define our success. We seek individuals who not only share these values but are also committed to embedding them in their daily work, fostering a positive and high-performing environment.
The EBRD environment provides you with:
- Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public and private sectors across the regions we invest in.
- A working culture that embraces inclusion and celebrates diversity. Our workforce reflects a broad range of backgrounds, perspectives, and experiences, bringing fresh ideas, energy, and innovation and enhancing our ability to serve our clients, shareholders, and counterparties effectively.
- We offer hybrid and flexible working arrangements and believe we operate at our best when collaborating 3 days a week in person (minimum).
- An environment that places sustainability, equality and digital transformation at the heart of what we do.
- A workplace that prioritises employee wellbeing and provides a comprehensive suite of competitive benefits.
Diversity is one of the Bank’s core values which are at the heart of everything it does. As such, the EBRD seeks to ensure that everyone is treated with respect and given equal opportunities and works in an inclusive environment. The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, gender identity, sexual orientation, age, socio-economic background or disability.
Please note, that due to the high volume of applications received, we regret to inform you that we are unable to provide detailed feedback to candidates who have not been shortlisted (for further consideration).
Similar roles
-
Director Cybersecurity Operational Risk Oversight
Citizens Bank Johnston, Rhode Island, United States · $178K–$220K/yr
-
Senior Security Engineer, Detection & Response
Aircall.io, Inc. San Francisco, California, United States · $180K–$220K/yr
-
Senior Security Engineer (m/w/d)
Yoummday GmbH Munich, Bavaria, Germany
-
Senior Security Engineer, Cloud and Infrastructure Security
Weight Watchers United States · $210K–$225K/yr
-
Staff Security Engineer - AI Security
Qube Research & Technologies London, England, United Kingdom
-
Cybersecurity Engineer - CBO
INNOVIM United States · $90K–$107K/yr