Penetration Tester (Mid/Senior Level) - European Bank for Reconstruction and Development (Sofia)
About this position
The summary below is published by European Bank for Reconstruction and Development on the official vacancy notice. Our own analysis — salary realism, comparable openings, career trajectory, language profile — follows further down the page.
Requisition ID 37058 Office Country Bulgaria Office City Sofia Division Information Technology Contract Type Fixed Term Contract Length 3 years Posting End Date 30/09/2026
Are you a cyber expert with a passion for finding the cracks before the criminals do? We’re searching for an Offensive Security Expert to join the front lines of our cyber defense. You’ll lead offensive security operations, scanning systems, probing weaknesses, and simulating real-world attacks using standard offensive tooling. From validating vulnerabilities through hands-on exploitation to crafting custom scripts that expose hidden threats, your work will drive critical security insights and real-time risk reduction.
This role is built for someone with deep technical expertise and an hacker mindset, fluent in web technologies, OWASP Top 10, and the inner workings of modern attack vectors. You’ll also dive into threat intelligence, develop hypotheses, and contribute to smarter detection strategies. If you’re driven to outsmart adversaries, influence real-world defense strategies, and play an key role in proactive security, your next mission starts here.
Accountabilities & Responsibilities
- Plans, develops…
Excerpt shown; read the full notice on the official page. The structured breakdown below covers the key facts.
Key responsibilities
According to the vacancy notice, the role centres on the following duties:
- Plans, develops and executes vulnerability scans of organization information systems
- Identifies and resolves false positive findings in assessment results
- Performs reconnaissance and information collection on the target environment or attack surface
- Identifies potential weaknesses and vulnerabilities on assets (end points, applications, users)
- Validates weaknesses via exploitation, and reports findings
- Recommends security controls and/or corrective actions for mitigating technical and business risk
- Creates hypotheses for analytics and testing of threat data
- Analyses data from threat and vulnerability feeds for applicability to the organisation
Are you eligible?
Check these requirements from the notice before investing time in an application:
- Key skills: Highest level of technical expertise in cybersecurity, Deep familiarity with penetration and intrusion techniques and attack vectors, Strong understanding of web technologies, Solid grasp of core security fundamentals and concepts, Familiarity with OWASP top 10 vulnerabilities, Knowledge of offensive tools such as Metasploit, Kali Linux, Cobalt Strike, Mimikatz or similar, Proficient at creating own scripts and regular expressions in preferred scripting language, Technical knowledge in system security vulnerabilities and remediation techniques, Technical knowledge in network and web-related protocols (TCP/IP, UDP, IPSEC, HTTP, etc.), Technical knowledge in security engineering, system and network security, authentication and security protocols
Contract and working arrangements
Contract duration: 3 years.
Working arrangements: Hybrid with minimum 3 days per week in person.
Hiring unit: Information Technology.
Position overview
This is the official EU Careers listing for Penetration Tester (Mid/Senior Level) at EBRD based in Sofia.
Requisition ID 37058 Office Country Bulgaria Office City Sofia Division Information Technology Contract Type Fixed Term Contract Length 3 years Posting End Date 30/09/2026
Are you a cyber expert with a passion for finding the cracks before the criminals do? We’re searching for an Offensive Security Expert to join the front lines of our cyber defense. You’ll lead offensive security operations, scanning systems, probing weaknesses, and simulating real-world attacks using standard offensive tooling. From validating vulnerabilities through hands-on exploitation to crafting custom scripts that expose hidden threats, your work will drive critical security insights and real-time risk reduction.
This role is built for someone with deep technical expertise and an hacker mindset, fluent in web technologies, OWASP Top 10, and the inner workings of modern attack vectors. You’ll also dive into threat intelligence, develop hypotheses, and contribute to smarter detection strategies. If you’re driven to outsmart adversaries, influence real-world defense strategies, and play an key role in proactive security, your next mission starts here.
Accountabilities & Responsibilities
- Plans, develops and executes vulnerability scans of organization information systems - Identifies and resolves false positive findings in assessment results - Performs reconnaissance and information collection on the target environment or attack surface - Identifies potential weaknesses and vulnerabilities on assets (i.e., end points, applications, users) - Validates weaknesses via exploitation, and reports their findings - Recommends security controls and/or corrective actions for mitigating technical and business risk - Creates hypotheses for analytics and testing of threat data - Analyses data from threat and vulnerability feeds and analyses data for applicability to the organisation - Generates reports on assessment findings and summarises to facilitate remediation tasks - Shares lessons learned, initial indicators of detection and opportunities for strengthening signature-based detection capabilities
Knowledge, Skills, Experience & Qualifications
- Highest level of technical expertise in cybersecurity, including deep familiarity with relevant penetration and intrusion techniques and attack vectors - Strong understanding of web technologies - Solid grasp of core security fundamentals and concepts - Familiarity with the Open Web Application Security Project (OWASP) top 10 vulnerabilities - Knowledge of offensive tools such as: Metaspoit, Kali Linux, Cobalt Strike, Mimikatz or a similar tool - Proficient at creating their own scripts regular expressions in their preferred scripting language - Technical knowledge in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, etc.) - Technical knowledge in security engineering, system and network security, authentication and security protocols - The following certifications desired but not essential: Certified ethical hacker (CEH), global information assurance certification (GIAC), GIAC certified pen tester (GPEN), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), offensive certified security professional (OSCP) and offensive security certified (OSC)
What is it like to work at the EBRD? / About EBRD
Our agile and innovative approach is what makes life at the EBRD a unique experience! You will be part of a pioneering and diverse international organisation, and use your talents to make a real difference to people's lives and help shape the future of the regions we invest in.
At EBRD, our Values – Inclusiveness, Innovation, Trust, and Responsibility – are at the heart of how we work. We bring these to life through our Workplace Behaviours: listening well and speaking up, collaborating smartly, acting decisively with full commitment, and simplifying to amplify our impact. These principles shape our culture and define our success. We seek individuals who not only share these values but are also committed to embedding them in their daily work, fostering a positive and high-performing environment.
The EBRD environment provides you with:
- Varied, stimulating and engaging work that gives you an opportunity to interact with a wide range of experts in the financial, political, public and private sectors across the regions we invest in. - A working culture that embraces inclusion and celebrates diversity. Our workforce reflects a broad range of backgrounds, perspectives, and experiences, bringing fresh ideas, energy, and innovation and enhancing our ability to serve our clients, shareholders, and counterparties effectively. - We offer hybrid and flexible working arrangements and believe we operate at our best when collaborating 3 days a week in person (minimum). - An environment that places sustainability, equality and digital transformation at the heart of what we do. - A workplace that prioritises employee wellbeing and provides a comprehensive suite of competitive benefits.
Diversity is one of the Bank’s core values which are at the heart of everything it does. As such, the EBRD seeks to ensure that everyone is treated with respect and given equal opportunities and works in an inclusive environment. The EBRD encourages all qualified candidates who are nationals of the EBRD member countries to apply regardless of their racial, ethnic, religious and cultural background, gender, gender identity, sexual orientation, age, socio-economic background or disability.
Please note, that due to the high volume of applications received, we regret to inform you that we are unable to provide detailed feedback to candidates who have not been shortlisted (for further consideration).
Job Segment:Military Intelligence, Sustainability, Database, Information Systems, Test Engineer, Government, Energy, Technology, Engineering
Application timeline
This vacancy was first listed on 9 September 2026, 6 days ago.
No closing date is published in the source feed for this position. EU vacancies typically remain open for four to eight weeks; check the official vacancy notice for the cut-off date and time.
Last verified against the EU Careers feed on 15 September 2026.
Where to learn more
For headcount, mission, and other open vacancies at EBRD see the EBRD institution page; for the cost of living, correction coefficient, and other postings in Sofia see our Sofia location page.
New to EU careers? Our beginner's guide walks through entry routes, EPSO competitions, and what to prepare. For application logistics see application tips and EPSO competitions.
Career trajectory
Language profile
Application cadence
Visit the official European Bank for Reconstruction and Development website
Source: This job listing was sourced from the officialEU Careers portal (EPSO). First published: .