Offensive Security Engineer (Penetration Testing | Red Team | Adversary Simulation)
Thales is hiring an Offensive Security Engineer (Penetration Testing | Red Team | Adversary Simulation) for a remote role open to applicants in Portugal. Level rates it ; you can apply on Level.
AI in this role
Conduct offensive security assessments, penetration testing, and incident response activities across enterprise environments.
About the Role
We are looking for a skilled Penetration Tester to support offensive security assessments and incident response activities across enterprise environments.
In this role, you will identify vulnerabilities, simulate real-world attack scenarios, and collaborate closely with DFIR, SOC, and security operations teams. The position combines advanced penetration testing with hands-on support during cyber incidents, threat investigations, and continuous security improvement initiatives.
Key Responsibilities
Conduct web, network, cloud, and Active Directory penetration tests using modern offensive security techniques and tools.
Support incident response engagements, including forensic analysis, threat hunting, containment validation, and attacker activity reconstruction.
Prepare detailed technical reports and executive summaries with clear, actionable remediation recommendations.
Collaborate with blue team, DFIR, SOC, and security engineering teams to improve detection capabilities and validate security controls.
Contribute to strengthening the organization’s cyber resilience through proactive testing and technical analysis.
Requirements
Minimum 3 years of experience in penetration testing or offensive security roles.
Strong hands-on experience in:
Web and API security testing
Network and infrastructure assessments
Cloud security testing
Active Directory security
Experience supporting or collaborating with incident response (DFIR) teams.
Ability to communicate technical findings clearly to both technical and non-technical stakeholders.
Portuguese (C1) and English (C1) proficiency.
Availability for medium travel.
Preferred Qualifications
Offensive Security certifications:
OSCP, OSEP, OSWE
SANS certifications:
GPEN, GCFA
Experience in:
Threat hunting and forensic analysis
Security validation and purple teaming
Attack simulation and adversary techniques
What We Offer
Competitive compensation package and benefits.
Opportunity to work on advanced offensive security and incident response projects.
Continuous training and access to certifications and learning programs.
Collaborative environment with SOC, DFIR, and Threat Intelligence teams.
Hybrid/office flexibility (depending on local policy) and international exposure.
YOUR CAREER AT THALES
Future opportunities will allow you to discover other domains or sites. You will be able to evolve and grow your competences in different areas:
Room and attention to personal development
Build your talents in another domain of Thales Group, discovering new products, new customers, new country or go to a more complex Solution
Choose between a technical expertise or a leadership path
Build an international career within a leading Engineering Group
How we rate this
Offensive Security Engineer (Penetration Testing | Red Team | Adversary Simulation) at Thales rates 10 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where penetration testing was part of your work. What did you do?
- Tell me about a project where incident response was part of your work. What did you do?
- Tell me about a project where threat hunting was part of your work. What did you do?
- Tell me about a project where active directory was part of your work. What did you do?
- Tell me about a project where cloud security was part of your work. What did you do?
Adapt your resume
- List these exact terms on your resume: Penetration Testing, Incident Response, Threat Hunting, Active Directory, and Cloud Security. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new remote cybersecurity jobs by email
One email a week with the new remote cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step