Location: 

Madrid, M, ES

Penetration Tester (Hybrid set up)

Join a team of cybersecurity professionals and help Swiss Re fulfil its mission to make the world more resilient.  

As the Penetration Tester, you will improve and develop the strategy of penetration testing within Swiss Re, ensuring security assessments of web applications and APIs are delivered and remediations are coordinated and fulfilled.  

What's more, you'll be working in a hybrid setup, perfectly balancing work from home and the office premises. 

 

 

About the team 

 

The Penetration Testing team simulates real-world cyberattacks on Swiss Re's computer systems, networks, applications, services and platforms. As part of the Group Security & Technology Platforms (GSTP) division, the team detects security weaknesses and fixes them before malicious hackers can exploit them 

We're looking for an experienced Penetration Tester who's ready to help us protect our digital assets through comprehensive testing, research, fixing and reporting. If this sounds like you, we'd like to hear from you! 
 

 

 

About the role 

 

Nobody is perfect and meets 100% of our requirements. If you, however, meet some of the criteria below and are curious about the world of penetration testing inside a large reinsurance company, we'll be more than happy to meet you!  

  • Continuously improve existing processes and develop long-term strategy for the penetration testing service 

  • Efficiently own, perform and deliver security assessments of web applications, APIs and infrastructure penetration reports, and coordinate the remediation of all findings and recommendations 

  • Compile "lessons-learnt" sessions and educational material for IT developers and other relevant parties 

  • Manage relations with internal partners and external security companies providing penetration tests 

  • Cooperate closely with global teams from IT application owners, information security specialists and chief information security officers 

  • Be someone who believes in continuous innovation, is curious and relentless in finding a better way every day 

  • Use your knowledge of Open Web Application Security Project (OWASP) Top 10 Vulnerabilities, testing procedures and remediation recommendations 

 

 

Your qualifications 

 

What we need from you 

  • At least 2 years of experience in information security and penetration testing 

  • Good understanding of software development and architecture 

  • Sound understanding of security frameworks (ISO27001/2, NIST, OWASP Top 10) 

  • Experience with vulnerability management and penetration testing tools (Burp Suite, nmap, Qualys, etc.) 

  • Exposure to AI/LLM security concepts or a strong interest in learning about securing AI-enabled applications and agentic systems 

  • Analytical thinking, structured approach to address complex matters 

  • Ability to communicate complex technical concepts clearly and unambiguously to both business and technical audiences 

  • Good communication and writing skills; proficiency in English is required, other languages are a plus 

  • You are a phenomenal teammate, results-oriented, focused and fond of international professional relationships 

  • You are curious, like to drive things forward, raise your voice for improvement and possess a great interest in learning new things 

 

Nice-to-have 

  • Industry-relevant certifications (SANS, CEH, Offensive Security, eLearn Security, etc.) 

  • Familiarity with the OWASP Top 10 for LLM Applications, prompt injection risks,  AI security testing 

 

 

For Spain the base salary range for this position is between EUR 42,000 and EUR 70,000 (for a full-time role). The specific salary offered considers:

  • the requirements, scope, complexity and responsibilities of the role,
  • the applicant’s own profile including education/qualifications, expertise, specialisation, skills and experience.

 

In the situation where you do not meet all the requirements or you significantly exceed these, the offered salary may be below or above the advertised range.

In addition to your base salary, you may be eligible for additional rewards and benefits including an attractive performance-based bonus.

 

About Swiss Re

 

Swiss Re is one of the world’s leading providers of reinsurance, insurance and other forms of insurance-based risk transfer, working to make the world more resilient. We anticipate and manage a wide variety of risks, from natural catastrophes and climate change to cybercrime. Combining experience with creative thinking and cutting-edge expertise, we create new opportunities and solutions for our clients. This is possible thanks to the collaboration of more than 15,000 employees across the world.

Our success depends on our ability to build an inclusive culture encouraging fresh perspectives and innovative thinking. We embrace a workplace where everyone has equal opportunities to thrive and develop professionally regardless of their age, gender, race, ethnicity, gender identity and/or expression, sexual orientation, physical or mental ability, skillset, thought or other characteristics. In our inclusive and flexible environment everyone can bring their authentic selves to work and their passion for sustainability.

If you are an experienced professional returning to the workforce after a career break, we encourage you to apply for open positions that match your skills and experience.

 

We may use AI-powered tools to support the review and evaluation of applications for this position. These tools provide additional insights to our recruitment teams, but all hiring decisions are carefully reviewed and made by people. To learn more about how we use AI in recruitment and how we handle your personal data, please review our Data Privacy Statement before applying.

 

Keywords:  
Reference Code: 138932 

 

 


Job Segment: Research