Details about the role
Job description
As a Penetration Tester / Red Teamer, you will be responsible for conducting security assessments and simulating real-world attack scenarios to help organizations identify and address security weaknesses. You will work on penetration testing engagements, red team exercises, vulnerability assessments, and security research projects across a variety of technologies and environments.
Your role will involve identifying and validating vulnerabilities, documenting findings, presenting recommendations to clients, and contributing to the continuous improvement of internal tools, methodologies, and offensive security capabilities. You will collaborate closely with colleagues across Estonia and the wider NEVERHACK Group while supporting customers in strengthening their cybersecurity posture.
Expectations for the candidate
Candidate profile
We are looking for a motivated and ethically minded cybersecurity professional with a passion for offensive security and continuous learning.
Required qualifications and skills:
- Practical knowledge of penetration testing, red team operations, software development, or system administration.
- Understanding of application, operating system, identity, cloud, and network security concepts.
- Familiarity with common protocols and services, including HTTP, DNS, SMTP, Active Directory, and Microsoft Entra.
- Experience using offensive security tools and manual testing techniques.
- Strong analytical and problem-solving skills.
- Ability to clearly document technical findings and communicate effectively in English.
- A responsible and ethical approach to handling customer systems, data, credentials, and confidential information.
- Residence in Estonia and willingness to participate in occasional on-site customer engagements.
Considered an advantage:
- Previous penetration testing or red team experience.
- Knowledge of recognized security testing methodologies and frameworks.
- Experience with MITRE ATT&CK, OSINT, operational security, or adversary simulation.
- Software development, scripting, or secure code review experience.
- Relevant certifications such as OSCP, OSWE, or equivalent.
- A cybersecurity-related degree or a technical portfolio demonstrating hands-on security work.
Opportunities
Opportunities
By joining NEVERHACK Estonia, you will become part of one of the leading cybersecurity organizations in the region and gain access to an international network of security experts.
What we offer:
- Flexible working hours and hybrid work opportunities.
- Ongoing training, mentorship, and professional development.
- Collaboration with offensive security teams across the NEVERHACK Group.
- Access to modern offensive security tools, AI-assisted capabilities, and testing environments.
- Opportunities to contribute to security research, internal tools, and methodology development.
- Career growth opportunities, including the possibility to lead engagements and specialize in advanced offensive security disciplines.
- A collaborative and international work environment.
- A modern office with complimentary snacks and beverages.
- Free on-site parking.
- Five additional paid vacation days after the first year of employment.
- A choice between sports compensation or private health insurance.
- Primarily remote project delivery for customers outside Estonia.
Applying for a job
One can apply until the end of the application period.