Penetration Tester / Red Teamer
About the role
We are looking for a Penetration Tester / Red Teamer to join our offensive security team in Estonia.
Your main focus will be ethical hacking through: Penetration testing and Red-team operations.
Depending on your experience and demonstrated capabilities, you may join us at a junior, mid-level, or senior level.
Our security testing is primarily manual, supported by automation and AI-assisted tools where they improve quality, coverage, and efficiency. We also use threat exposure management to support testing, reporting, and vulnerability tracking.
Job responsibilities
As part of our offensive security team, your primary responsibilities will include:
- Conducting penetration tests of applications and IT infrastructure
- Participating in red-team and adversary-simulation engagements
- Identifying, validating, and documenting vulnerabilities and attack paths
- Working within the agreed scope, objectives, timeline, and rules of engagement
- Preparing clear and actionable reports for technical and non-technical audiences
- Presenting findings, business impact, and remediation recommendations to customers
- Using threat exposure management for testing, reporting and vulnerability tracking
- Contributing to internal tools, testing methodologies, technical research, and knowledge sharing
- Providing technical support to sales colleagues when needed
- Participating in occasional customer-site engagements
Who we’re looking for
These challenges require someone with a positive attitude, a strong work ethic, and a genuine passion for offensive security. We welcome candidates with different levels of experience. We value practical ability, technical curiosity, ethical judgment, and a willingness to continuously learn and improve.
Required qualifications
- Practical knowledge of penetration testing, red-team operations, software development, system administration
- Understanding of application, operating system, identity, cloud, and network security concepts
- Understanding of common protocols and services, including HTTP, DNS, SMTP, AD and Entra
- Familiarity with offensive security tools
- Ability to use manual testing techniques to identify and validate vulnerabilities
- Ability to clearly document technical work and communicate findings in English
- Analytical and problem-solving skills
- A responsible and ethical approach to customer systems, data, credentials and confidential information
The role requires residence in Estonia and availability for occasional customer-site engagements.
Work for customers outside Estonia is usually performed remotely, and international travel is not common.
Nice-to-have skills
- Previous experience conducting penetration tests or participating in red-team operations
- Knowledge of recognized penetration-testing methodologies and standards
- Experience testing different technologies and environments
- Understanding of adversary simulation MITRE ATT&CK, operational security and OSINT
- Software development, scripting, or secure code-review experience, OWASP ASVS WSTG
- Experience using AI-assisted tools in offensive security workflows
- An offensive security certification, such as OSCP, OSWE, or a comparable certification
- A technical portfolio that includes security research, tools, scripts, responsible disclosures, lab work, or publications
- A degree in cybersecurity, information technology, computer science, or a related field
What do we offer?
Examples of what you can expect:
- Flexible working hours and hybrid work opportunities
- Training, mentorship, and continuous technical development
- Support from the offensive security team in Estonia and other offensive security teams across the group
- Access to modern offensive security tools, AI-assisted capabilities, and testing environments
- Opportunities to contribute to internal tools, methodologies, technical research, and knowledge sharing
- Opportunities to develop deeper technical expertise, lead engagements
- A collaborative international working environment
- Free on-site parking
- A modern, well-equipped office with complimentary snacks and beverages
- Five additional days of paid vacation after your first year with us
- A choice between sports compensation or private health insurance
- Primarily remote delivery for customers outside Estonia
Are you ready to join the best cybersecurity team in Northern Europe? Send your application via CV.ee.
The confidentiality of all candidates will be guaranteed.