Back to jobs

Senior Penetration Tester @Thessaloniki

Hybrid / GreeceFull timeSenior (5+ years)
Apply

About the role

What Impact will you make?

Are you looking for an

opportunity

in

Thessaloniki

that offers you a

hybrid working model

?

Are you ready to work on

large scale

projects for industry-leading clients

around the world and elevate your

career

to an

international level

?

If so, check below for more info about this career

opportunity

!

You bring passion, we bring opportunities!

#YourOpportunity

Deloitte is a worldwide leader in Professional Services with a presence in more than 150 countries and territories. Since 2018, Deloitte has been operating its Alexander

Competence Center in Thessaloniki with satellites in the cities of Patras, Heraklion, and Ioannina

  • which are model hubs of expertise, training, and innovation, specializing in cutting-edge exponential technologies, in which professionals undergo immersive experiences, continuous learning, gaining practical insights and hands-on training that empower them to navigate the complexities of the digital landscape.

Deloitte is an ideal working environment for

both young and senior professionals

who want to take the next step in their careers, offering them a supportive and international working environment that leverages their expertise and potential. Its corporate culture is based on trust and collaboration and ensures diversity and inclusion so that everyone feels part of a great team.

We are currently seeking for experienced and highly motivated professionalsto become part of our Cyber Defense & Resilience team within our

Technology & Transformation

department in

Thessaloniki

.

#YourServiceLine: Technology & Transformation

Our Technology & Transformation teams empower organizations to navigate the future through technology-driven business transformation. Combining deep industry knowledge with cutting-edge technology, we deliver tailored solutions that drive innovation, enhance efficiency, promote cybersecurity, and foster sustainable growth.

#AboutYourTeam

Our Offensive Security Team specializes in identifying, testing, and breaching security boundaries to build unyielding resilience. We simulate sophisticated real-world attacks across hybrid infrastructures, cloud platforms, applications, networks, and complex enterprise environments to expose vulnerabilities before they can be exploited.

Quite simply, we provide the adversarial perspective, delivering rigorous penetration testing and red teaming engagements that stress-test our clients’ defenses and help them strengthen their security posture.

Join us and you could find yourself working on a broad range of offensive security assignments, from focused technical assessments to complex multi-domain penetration testing programs. These may include web applications, APIs, mobile applications, infrastructure, cloud platforms, containerized environments, network infrastructure, wireless networks, firewall and security gateways, source code reviews, thick clients, mainframe applications, telecommunication infrastructure, and risk-based penetration testing.

In short, you will break solutions to help our clients build them stronger, meeting evolving business requirements while contributing to the growth of the team through high-impact delivery, technical leadership, and thought leadership in the offensive security space.

#Core Responsibilities

  • Lead and deliver

penetration testing and offensive security assessments

across web applications, APIs, mobile applications, infrastructure, networks, cloud platforms, and other complex enterprise environments.

  • Perform hands-on vulnerability identification, validation, and exploitation, assessing technical risk and business impact in line with agreed scope and rules of engagement.
  • Apply recognized security methodologies and frameworks such as

OWASP, NIST, PTES, and MITRE ATT&CK

throughout the assessment lifecycle.

  • Prepare clear, actionable reports and present findings to technical and non-technical stakeholders, supporting clients in prioritizing and tracking remediation activities.
  • Mentor junior team members, review technical outputs, and contribute to the continuous improvement of offensive security methodologies, tools, and delivery quality.

#OurRequirements

  • Academic background (BSc and MSc) related to

Information Technology, Computer and Data Science, Business Informatics, Engineering

. We also welcome graduates with a business background, who have major in

Information Systems Management or any other IT-related major.

  • Able to manage office automation tools, such as MS Excel, MS PowerPoint, MS Access
  • Excellent command of the Greek and English language
  • Very good knowledge of Italian and other languages will be considered a plus
  • Strong interest for Offensive Security with active participation in CTFs (e.g., Hack The Box, TryHackMe)
  • Theoretical knowledge of Cloud, Infrastructure, Mobile, API, and Web architectures from an offensive security and exploitation perspective.
  • Proficiency in scripting and code analysis (e.g., Python, Bash, C#) for exploit automation and vulnerability testing.
  • Relevant certifications such as

OSCP

(Offensive Security),

CPTS (Hack The Box)

, or

BSCP

(PortSwigger) are highly preferred.

  • Analytic mindset
  • Good interpersonal and communication skills
  • Aptitude to the team working
  • Client Orientation
  • Academic background in

Information Technology, Computer Science, Cybersecurity, Computer Engineering, Data Science, Business Informatics, Engineering

, or other relevant IT-related disciplines.

  • Minimum 3 years of professional experience in penetration testing, offensive security, vulnerability assessment, red teaming, or similar cybersecurity roles.
  • OSCP certification is required.
  • Additional relevant certifications such as

OSEP, OSWE, CPTS, CRTO, GPEN, GWAPT, eWPTX, eCPPT, CARTP, or BSCP

will be considered a strong asset.

  • Hands-on experience across several penetration testing domains, such as

web applications, APIs, mobile applications, infrastructure, networks, cloud platforms, operating systems, servers, containerized environments, wireless networks, or thick clients

.

  • Strong knowledge of offensive security methodologies, vulnerability exploitation techniques, and security frameworks such as

OWASP, NIST, MITRE ATT&CK

, and related industry standards.

  • Experience with offensive security tools such as

Burp Suite, Nmap, Metasploit, Nessus, BloodHound, Impacket, Cobalt Strike

, or equivalent tools.

  • Proficiency in scripting and code analysis, for example with

Python, Bash, PowerShell, C#

, or other relevant languages used for automation, testing, and tooling.

  • Strong reporting, communication, and client-facing skills, with the ability to produce clear deliverables and interact effectively with technical teams and senior stakeholders.
  • Excellent command of the

Greek and English language

; knowledge of Italian or other languages will be considered a plus.

If you are ready to apply your offensive security expertise in a challenging international environment, contribute to high-impact projects, and collaborate with teams across Greece and abroad, you are ready for Deloitte!

#WhatWeOffer

At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits:

  • Modern hybrid workplace, characterized by flexibility and Smart Working
  • Empowered well-being: We provide multiple program offerings to support your well-being needs (flexible working arrangements, extra days of leave, parental allowances)
  • Engagement within international large-scale teams and projects, with opportunities to travel for training or client purposes.
  • Constant opportunities for learning with unlimited access to internal and external learning platforms and sponsored certificates aligned with business needs and technology trends
  • Challenging and innovating environment where personal development and growth are encouraged, always with transparency and trust
  • Diverse culture and active communities that enable you to bring yourself to work
  • Team Building and Corporate Social Responsibility Activities
  • A buddy to support you with your onboarding
  • Extra days of annual leave
  • Private medical health insurance plan
  • Ticket restaurant card
  • Exclusive Discounts to several retail providers, restaurants and others
  • Mobile phone
  • Fresh fruits and unlimited coffee everyday at our offices

Please note that all the well-being benefits mentioned above are subject to annual review

Sounds like the sort of role for you? Apply now.

Location:

Thessaloniki

Search the jobs. Check the details. Make your move.

Compare recent openings by location, work format, pay, and experience level in one place.

Explore jobs
Smiling man pointing at a “Job offer!” notification on his phone

Excellent

Rated 4.8 out of 5 based on 617 reviewsTrustpilot

by Megan F.

Job seeker

The filters made it easier to see roles that actually matched the way I want to work. I could compare options without opening dozens of tabs.

by Daniel B.

Developer

I liked being able to narrow the search to remote roles and check the requirements before taking the next step.

by Rachel A.

People operations

The listings are easy to scan. Work format, location, and experience level are right where I expect them.

by Marcus H.

Data analyst

Salary and location filters helped me focus on roles that were worth a closer look.

by Aisha K.

QA engineer

I found the job details clear and useful. It was simple to see which skills mattered for each role.

by Olivia G.

Support specialist

The search felt straightforward, and I could quickly switch between different kinds of jobs.

by Kevin T.

Account manager

It is easy to revisit roles that fit my experience. I would like to see even more openings in my area.

by Sophia R.

Product designer

I could check work format and salary before reading the full description. That made my search feel much clearer.

by Hannah S.

Project coordinator

The job pages put the important details together, so I knew what to expect before deciding to continue.

by Victor A.

DevOps engineer

The remote filter is useful and the listings are quick to scan. A few more country options would make it even better.

by Brandon L.

Job seeker

After a break from work, a simple search and clear filters helped me start looking again without feeling overwhelmed.

by Jessica M.

Marketing coordinator

The search is straightforward. I can move from a short result to the full role description in one click.

by Christopher H.

Operations manager

I like seeing salary, location, and experience level next to each role. It saves time when comparing openings.

by Ethan M.

Sales representative

The layout is clean and the job cards are easy to read. I am looking forward to a larger selection of listings.

by David R.

Support specialist

I found the different work formats easy to browse and could quickly open roles that matched my schedule.

Frequently asked questions

Answers about finding your next role

What can I search for?

Search by job title or keyword, then browse remote, hybrid, and onsite openings in one list.

Where can I find remote jobs?

Browse remote openings on Remote Amigo. Search by job title or keyword, then choose Remote in the work format filter. Check each listing for location or country requirements.

How do I narrow the results?

Choose a country, work format, minimum annual salary, and experience level. You can change or clear the filters at any time.

What will I see on a job page?

Each listing shows the role, company, location, work format, salary when available, skills when provided, and a job description.

Do I need an account to browse jobs?

No. You can search and read the available listings without signing in.

Does this site submit job applications for me?

No. You can search and review listings here. The Apply button starts the job preference quiz; it does not submit an application to an employer.

Where do the jobs come from?

Listings are imported from public job feeds and job sites. Job details may change at the original source, so confirm the latest information before applying.

How recent are the listings?

Search results include listings with a publication date in the last 30 days. If a source provides no publication date, the import date is used; the actual posting may be older.

Can I search for remote jobs only?

Yes. Select Remote in the job type filter to show remote listings. You can switch to Hybrid or Onsite whenever you want.

What is the difference between remote, hybrid, and onsite?

Remote roles are intended to be done away from an office. Hybrid roles combine remote and office work. Onsite roles are based at a workplace. Always read the listing for its exact location requirements.

Can I filter jobs by country?

Yes. Choose a country in the search form to narrow the listings. A remote role may still have country restrictions, so check its description before applying.

Why do some jobs have no salary listed?

Some listings do not include pay information. We show a salary when it is available and leave it out when it is not provided.

Is the salary filter a monthly or annual amount?

The minimum salary field uses US dollars per year. It filters listings that have comparable salary information.

Can I change or clear my search filters?

Yes. Change the keyword, country, job type, salary, or level in the search form. You can clear individual fields and run a broader search again.