Offensive Security Expert

Offensive Security Expert

European Bank for Reconstruction and Development (EBRD)

September 18, 2026November 2, 2026SofiaBulgaria
Job Description
Job Posting Organization:
The European Bank for Reconstruction and Development (EBRD) is a pioneering international organization established to support the development of market economies and promote private and entrepreneurial initiatives in countries across Europe, Asia, and beyond. Founded in 1991, the EBRD operates in over 30 countries, employing a diverse workforce that reflects a wide range of backgrounds and experiences. The bank's mission is to foster the transition to open and democratic market economies, and it is committed to sustainability, equality, and digital transformation. The EBRD values inclusiveness, innovation, trust, and responsibility, which are integral to its operations and culture.

Job Overview:
The Offensive security" style="border-bottom: 1px dotted #007bff !important;">Security Expert position is designed for a cyber expert who is passionate about identifying vulnerabilities before they can be exploited by malicious actors. This role involves leading offensive security operations, which include scanning systems for weaknesses, probing for vulnerabilities, and simulating real-world attacks using standard offensive tools. The expert will validate vulnerabilities through hands-on exploitation and create custom scripts to uncover hidden threats. The position requires a deep technical understanding of web technologies and modern attack vectors, as well as the ability to analyze threat intelligence and contribute to the development of smarter detection strategies. The successful candidate will play a crucial role in proactive security measures and will be expected to influence real-world defense strategies.

Duties and Responsibilities:
The duties and responsibilities of the Offensive Security Expert include planning, developing, and executing vulnerability scans of the organization's information systems. The expert will perform penetration tests on various assets, including web, mobile, and network systems. They will identify and resolve false positive findings in assessment results, conduct reconnaissance and information collection on target environments, and identify potential weaknesses and vulnerabilities on assets such as endpoints, applications, and users. The expert will validate weaknesses through exploitation and report their findings, recommending security controls and corrective actions to mitigate technical and business risks. Additionally, they will create hypotheses for analytics and testing of threat data, analyze data from threat and vulnerability feeds, generate reports on assessment findings, and summarize results to facilitate remediation tasks. The expert will also share lessons learned and initial indicators of detection to strengthen signature-based detection capabilities.

Required Qualifications:
Candidates must possess the highest level of technical expertise in cybersecurity, with a strong understanding of penetration and intrusion techniques and attack vectors. A solid grasp of web technologies and core security fundamentals is essential. Knowledge of offensive tools and proficiency in creating custom exploits in a preferred programming language is required. Technical knowledge in system security vulnerabilities, remediation techniques, network and web-related protocols, and security engineering is also necessary. While certifications such as OSCP, OSEP, OSWE, CPTS, CWEE, CWES, and CAPE are desired, they are not mandatory.

Educational Background:
The educational background required for this position typically includes a degree in Computer Science, Information Technology, Cybersecurity, or a related field. Advanced degrees or specialized training in cybersecurity may be advantageous but are not strictly necessary.

Experience:
Candidates should have substantial experience in cybersecurity, particularly in offensive security roles. A proven track record of conducting penetration tests, vulnerability assessments, and security audits is essential. Experience in threat intelligence analysis and the development of security strategies will be highly regarded.

Languages:
Fluency in English is mandatory, as it is the primary language of communication within the organization. Knowledge of additional languages may be considered an asset, particularly those relevant to the regions in which the EBRD operates.

Additional Notes:
This position is a fixed-term contract lasting for three years. The EBRD promotes a hybrid and flexible working culture, with a minimum expectation of in-person collaboration three days a week. The organization is committed to diversity and inclusion, encouraging applications from qualified candidates regardless of their background. The EBRD offers a comprehensive suite of competitive benefits and prioritizes employee wellbeing.
Apply now
Similar Jobs