Company Description
The Bosch Group has more than [phone removed] employees around the world, present in 60 countries, and we are proud to impact people’s lives and to work towards a more sustainable future.
In the city of Aveiro, Bosch has one of its biggest production sites for Bosch Home Comfort division, as well as a Research and Development Center for new and improved heating solutions for the residential segment. With more than 1400 employees, focused on innovation, sustainability and collaboration, Bosch Aveiro joins together experts in diverse areas, from mechanical engineering to connectivity and software solutions, as well as industrialization and quality.
At Bosch, we shape the future by inventing high-quality technologies and services that spark enthusiasm and enrich people’s lives. Our promise to our associates is rock-solid: we grow together, we enjoy our work, and we inspire each other. Join in and feel the difference in mindsets, cultures, generations, identities and perspectives. Everyone should bring their authenticity and work together respectfully. Bosch is an employer that values diversity and equal opportunities. We welcome applications from people with disabilities and we can provide reasonable accommodations during the recruitment process and in the performance of professional activity. By including everyone and ensuring equal opportunities we unleash our full potential.
Job Description
As a Senior Penetration Tester, you will play a central role in identifying, assessing, and mitigating security vulnerabilities across our digital ecosystem. You will lead complex technical evaluations spanning modern web applications, backend architectures, APIs, and cloud-native environments, helping engineering teams build resilient, secure-by-design solutions.
Your contribution to something big:
• Drive Offensive Security: Plan, scope, and execute comprehensive penetration tests on modern web applications, backend microservices, REST/GraphQL APIs, and cloud-native environments (AWS, Azure, or GCP).
• Threat Modeling & Architecture Review: Collaborate closely with development and DevOps teams early in the design phase to conduct threat modeling and review architectures, ensuring security is baked in from day one.
• Vulnerability Analysis & Exploitation: Perform deep-dive manual and automated vulnerability analyses, uncovering complex flaws like business logic bypasses, authorization failures, and server-side request forgeries.
• Technical Reporting & Remediation Guidance: Author high-quality, actionable technical reports that translate complex technical risks into clear business impacts, providing pragmatic remediation guidance to our engineering squads.
• Tooling & Innovation: Develop custom testing scripts and explore cutting-edge offensive workflows, including integrating AI-assisted security testing and LLM-augmented vulnerability analysis to maximize speed and coverage.
Qualifications
What distinguishes you:
Education
• Degree in Computer Science, Cybersecurity, IT, Software Engineering, or equivalent practical experience in offensive security.
Experience
• Hands-on experience (ideally 3+ years) conducting technical security assessments, with a strong focus on web applications, APIs, and cloud infrastructure.
Know how
• Offensive Security Expertise: In-depth knowledge of backend technologies, secure protocols, and security standards (e.g., OWASP Top 10, ASVS, WSTG, OAuth 2.0).
• Cloud & Modern Tech: Solid familiarity with assessing cloud environments (AWS, Azure, or GCP), IAM configurations, container security (Docker, Kubernetes), and microservices.
• Tools & Scripting: High proficiency with industry-standard offensive tools (e.g., Burp Suite Pro, OWASP ZAP, Postman) combined with scripting skills (e.g., Python, Bash) to automate testing workflows.
Languages
• Excellent communication skills with fluency in English (written and spoken) to effectively present findings to both technical teams and business stakeholders.
Working Style and Methods
• An analytical and structured problem-solver who enjoys working collaboratively across cross-functional teams to build collective security resilience.
Personality
• A curious, continuous learner with a passion for offensive security, exploring new technologies, and a strong drive to mentor and share knowledge with others.
We also welcome (Preferred / Nice-to-have):
• Enthusiastic interest or experience in AI-driven offensive workflows (e.g., automated payload generation, LLM security evaluations).
• Industry certifications such as OSCP, OSWE, OSCE, CRTP, GWAPT, GPEN, or cloud-specific security certifications.
• Experience with source code reviews (SAST) in common modern languages (Java, Python, Go, TypeScript).
Additional Information
Work #LikeABosch includes:
⚖️ Flexible work conditions
🔀 Hybrid work system
🌐 Exchange with colleagues around the world
🧑⚕️ Health insurance and medical office on site (general surgeon, psychology, physiotherapy, general clinic)
📚 Training opportunities (p.e., technical training, foreign languages training) & certifications
📈 Opportunities for career progression and continuous professional development
💲 Access to great discounts in partnerships and Bosch products
🏋️ Sports and health related activities
💰 Flexible benefits platform
🅿️ Free parking lot
🍽️ Canteen
Success stories don´t just happen. They are made...
Make it happen! We are looking forward to your application!
Interested in this role?
See your match score
Sign in to compare your skills and get AI-powered application help.
Get started freeAlready have an account? Sign inNo specific skills listed for this role. Check the job description for requirements.
Job DNA
groundedA deterministic fingerprint of this role, read from its description. No AI.