This job was posted more than 40 days ago and might be expired.
ecosio logo

Senior Pentester / Red Teamer

Posted about 2 months ago

RemoteAustria, Germany, Spain, UK, Italy, Hungary, Portugal, Croatia, Poland - RemoteSE

Company Description

ecosio is a fast-growing, innovative service company and a leading provider of B2B integration, specialising in electronic data interchange (EDI), Web EDI and e-invoicing. ecosio is part of Vertex, Inc., a leading global provider of indirect tax solutions listed on Nasdaq (VERX).

Our brand slogan is Connections That Work as we believe strong connections are central to successful business relationships - both external and internal. At ecosio, we hire individuals from all backgrounds and are committed to creating an inclusive work environment. We are technology lovers, set the highest standards for our solutions, and put innovative ideas first.

Job Description

As a Senior Pentester / Red Teamer, you will operate as a highly autonomous security specialist responsible for proactively identifying vulnerabilities, simulating real-world attack scenarios, and hardening our infrastructure and applications. You will design and execute offensive security engagements — including penetration tests, red team exercises, and threat hunting campaigns — across cloud-native and hybrid environments. A core part of your mandate is to build and maintain automated security testing pipelines, leveraging AI-assisted tooling to continuously assess and improve the organisation's security posture.

You'll connect with the role if you enjoy...

  • Plan and execute penetration tests against internal and external infrastructure, web applications, APIs, and cloud environments (primarily AWS)
  • Conduct red team engagements simulating advanced persistent threats (APTs) and real-world attack chains
  • Design, build, and maintain automated pentesting and security scanning pipelines integrated into CI/CD workflows
  • Leverage AI and machine-learning–based tools (e.g., LLM-assisted vulnerability discovery, automated exploit generation, AI-driven anomaly detection) to scale offensive security operations
  • Develop custom exploit code, scripts, and tooling tailored to the organisation's technology stack
  • Assess and harden Kubernetes and AWS environments (IAM, VPC, EKS, Lambda, S3, CloudTrail, GuardDuty, etc.)
  • Document findings in clear, actionable reports with risk ratings and remediation guidance
  • Collaborate with SOC, DevOps, and engineering teams to validate fixes and improve detection capabilities
  • Contribute to purple team exercises bridging offensive findings with defensive improvements
  • Stay current on emerging attack techniques, CVEs, threat intelligence, and offensive security research
  • Mentor junior security team members on offensive methodologies and tooling

Qualifications

To connect with ecosio it is important to have…

  • 5+ years of hands-on experience in penetration testing, red teaming, or offensive security roles in Cloud environments
  • Proven track record of security assessments in AWS environments (IAM misconfigurations, privilege escalation, serverless exploitation, container breakouts)
  • Deep understanding of OWASP Top 10, MITRE ATT&CK, and common exploit frameworks (Metasploit, Cobalt Strike, Sliver, etc.)
  • Strong proficiency in scripting and automation (Python, Bash, Go, or similar)
  • Strong proficiency in subject matter tools e.g. Pacu or Prowler
  • Solid knowledge of networking, operating systems (Linux/Windows), and cloud-native architectures
  • Familiarity with AI/ML-assisted offensive security tools and techniques
  • Excellent analytical thinking and ability to work independently with minimal supervision
  • Strong written and verbal communication skills for technical and executive reporting

And nice to have...

  • Relevant certifications such as OSCP, OSEP, OSCE, CRTO, GPEN, GXPN, or AWS Security Specialty
  • Experience with Kubernetes / EKS security assessments and container escape techniques
  • Experience in physical pentesting of hardware devices such as firewalls, wifi aps and contactless card readers
  • Background in malware analysis, reverse engineering, or exploit development
  • Hands-on experience with AI-powered pentesting frameworks (e.g., PentestGPT, Nuclei AI, custom LLM agents for recon/exploitation)
  • Contributions to open-source security tools or published security research / CVEs
  • Experience with threat intelligence platforms and adversary emulation frameworks
  • Familiarity with compliance frameworks relevant to offensive testing (ISO 27001, NIS2, SOC 2)

Additional Information

By connecting with us you will experience...

  • Our remote-first culture lets you work remotely from one of our designated countries
  • Flexible working hours to suit your schedule and priorities
  • Annual personal development budget to invest in conferences, courses, or career coaching
  • Access to training and learning paths from Datadog and CrowdStrike
  • Home office allowance to create a workspace that fits your needs
  • Regular events and trips to connect, celebrate, and have fun with the team
  • Workations of up to 90 days per year within the EU, combining travel and productivity
  • Wellbeing support, including mental health resources and employee assistance programs
  • Additional country-specific benefits based on your location

Sounds like a connection that works? Then apply now and we will get in touch soon!

As part of our hiring process at ecosio, we conduct standard background checks. You can find more information about them by clicking HERE.

Our mission is to build Connections That Work by fostering a diverse and inclusive team. We are committed to making everyone feel valued and empowered to contribute their unique skills, experiences and perspectives. And now we want to connect with you

Job details
Workplace
Remote
Location
Austria, Germany, Spain, UK, Italy, Hungary, Portugal, Croatia, Poland - Remote
Experience
SE

ecosio implements automated B2B communication with customers, suppliers and authorities - providing flexible and future-proof electronic data interchange (EDI) and e-invoicing services as a single effortless solution covering everything from the initial partner approach to ongoing operation.

Employees
259
Industry
IT-Dienstleistungen und IT-Beratung
Headquarters
Vienna
Company location
Wiedner Gürtel 9, Vienna, 1100, AT
Specialties
Electronic Data Interchange, EDI outsourcing, X.400, AS2, OFTP2, EDIFACT, EANCOM, B2B processes, EDI, Supply Chain Management, e-Invoicing, ZUGFeRD, EDI converter, XML, VDA, Automotive, XRechnung, SAP SD, SAP MM, SAP PI, SAP PO, SAP Cloud Platform Integration, Microsoft Dynamics, proALPHA, abas ERP, Oracle NetSuite, myfactory ERP, Web EDI, ERP integration, XRechnung, FatturaPA, NAV, Peppol und Supplier Portals

Key team members

Wolfgang Deutsch

Wolfgang Deutsch

Csaba Kiss

Csaba Kiss

Luis Ronda

Luis Ronda

Florian Gottschall

Florian Gottschall

Apply smarter with Jobr

Jobr aggregates jobs directly from company career portals — no middlemen. Our team applies on your behalf with AI-tailored resumes, reviewed by a human before submission.

Direct from company career pages
AI-personalised cover letters
Human review before every submit
Application tracking & follow-ups