Job

Arbejd sammen med os

Vi har én stilling ledig lige nu, øverst på listen. Under den står de profiler vi altid gerne hører fra, uanset om der er et opslag ude, for vi kigger løbende og er altid åbne for den rigtige.

Senior Offensive Security Consultant Ledig stilling Full-time · Herlev

Offensive and purple team work from our Herlev office: deep, hands-on testing of live client environments, and helping the people who own them close what you find. You would carry the technical lead on engagements, and say what our tooling should look like.

Hvad du kommer til at lave

  • Carry out advanced penetration tests across web applications, APIs, networks, and cloud and on-premise environments, and document each finding so it can be acted on
  • Validate fixes through re-testing and support client teams through remediation
  • Run purple team engagements where that is what the client needs
  • Contribute to the tools, scripts and testing methodologies the team works from
  • Carry the technical lead on engagements
  • Keep current with emerging threats, vulnerabilities and attack techniques

Hvad vi kigger efter

  • Five or more years of hands-on experience in offensive security; OSCP, OSEP, OSCE, CRTO, GXPN, eCPTX or an equivalent certification is welcome
  • Strong knowledge of web application security, including the OWASP Top 10, API security and authentication flaws
  • A solid understanding of network protocols, of Linux and Windows, and of at least one of AWS, Azure and GCP
  • Strong skills in at least one scripting or programming language, such as Python, Bash or PowerShell
  • The ability to explain a complex security issue clearly to both a technical and a non-technical audience
  • The work is done from our Herlev office and on client sites in Denmark, so you are based here or ready to relocate, with a clean police record and the ability to pass a security background check

Søg stillingen Send dit CV, og skriv hvornår du kan starte.

Penetration Tester Herlev

This is a profile we are always glad to hear from: a penetration tester who treats a finding as the start of a conversation, not the end of a checklist. The work is testing real environments for real clients and helping them understand not just what is broken, but what it means for their business.

Hvad arbejdet går ud på

  • Plan and carry out authorised penetration tests across networks, web applications, Active Directory and cloud environments
  • Verify and safely demonstrate the business impact of each finding, rather than reporting raw scanner output
  • Write clear reports that both a technical team and a leadership team can act on
  • Work with clients through remediation, and validate that fixes hold

Hvad vi kigger efter

  • Hands-on experience with offensive security testing and common tooling
  • A solid grasp of how Windows, Active Directory and cloud identity are attacked and defended
  • The judgement to distinguish a theoretical weakness from a genuine business risk
  • Clear written English and the discipline to work within scope and authorisation
  • The work is done from our Herlev office and on client sites in Denmark, so it suits someone based here or ready to relocate
  • A relevant certification (OSCP or similar) is welcome but not required if the experience is there

Præsentér dig selv

GRC Consultant Herlev

This is a profile we are always glad to hear from: a governance, risk and compliance consultant who can turn a framework into something a business actually runs on. The work is helping clients meet ISO 27001, NIS2 and DORA so it supports the business rather than becoming a binder no one opens.

Hvad arbejdet går ud på

  • Run gap assessments and readiness reviews against ISO 27001, NIS2 and DORA
  • Build practical governance structures, policies and risk registers that fit the client's size and maturity
  • Translate regulatory requirements into a prioritised, realistic roadmap
  • Support clients through audits and help them demonstrate evidence with confidence

Hvad vi kigger efter

  • Experience implementing or auditing against recognised security frameworks
  • A working understanding of how NIS2 and DORA apply across different sectors
  • The ability to explain risk to a board and to an engineer in their own language
  • Strong written English and a structured, evidence-led way of working
  • The work is done from our Herlev office and on client sites in Denmark, so it suits someone based here or ready to relocate
  • A relevant qualification (ISO 27001 Lead Implementer or Auditor, or similar) is a plus

Præsentér dig selv