Description
**Description:**
----------------
SEAT S.A. is the only company in Spain that designs, develops, manufactures, and markets automobiles. As part of the Volkswagen Group, this multinational corporation is headquartered in Martorell (Barcelona). SEAT S.A. already offers the latest connectivity technology across its vehicle range and is undergoing a global digital transformation to drive the mobility of the future.
**"Inspire Courage, Achieve Success, Together as a Team"**, are the four values guiding our daily work and relationships with colleagues and stakeholders — they represent the essence of our culture and constitute our DNA.
At SEAT, we work with **autonomy**, live **honesty**, and bravely challenge the **status quo**. We continuously **challenge ourselves**, believing we can **achieve everything**, experiment, and learn from our mistakes when we err. We provide support and seek help when needed, and together, we **share and celebrate** successes.
The candidate will join the IT Security department and assume the following responsibilities:
**Key Responsibilities**
* Conduct continuous attack surface analysis, identifying exposed assets, misconfigured services, obsolete technologies, and unauthorized changes; correlate findings with real-world exploitation risks.
* Perform penetration testing on applications, infrastructure, and external services, including enumeration, controlled exploitation, vulnerability validation, and creation of verifiable technical evidence.
* Collaborate with security, architecture, and operations teams to contextualize findings, prioritize remediations, propose hardening controls, and verify effective mitigation of identified risks.
* Prepare technical and executive reports covering impact, exploitability, evidence, and actionable recommendations, and present results during review sessions with technical teams and business owners.
**Requirements**
**Education**: Technical or university degrees in Computer Science, Telecommunications, Mathematics, Physics, or related fields, or official certifications will be valued.
**Experience and Technical Knowledge:**
* Offensive pentesting (web, infrastructure, cloud) with proficiency in methodologies such as OSSTMM, PTES, or MITRE ATT\&CK, including real exploitation, payload development/adaptation, and advanced use of tools like Burp Suite, Nmap, Metasploit, Impacket, or red team frameworks.
* External attack surface mapping and analysis: discovery of exposed assets, fingerprinting, enumeration, analysis of weak configurations, identification of attack paths, and context-aware business-risk assessment.
* Linux/Windows/macOS/Public Cloud platforms.
* Familiarity with vulnerability management tools.
* System administration-level knowledge of Windows/Linux/macOS operating systems.
* Scripting and automation skills in languages such as Python.
**Languages:** Technical English is mandatory.
**Competencies:**
* Ability to analyze complex information with a structured and methodical approach.
* Problem-solving skills.
* Teamwork.
* Customer orientation.
* Efficiency and cost awareness.
* Passion for cybersecurity.
*
**What We Offer?**
* Competitive salary according to our collective bargaining agreement.
* Collective transportation to our workplaces (Barcelona and Martorell).
* Hybrid work model: 2 remote workdays per week.
* Subsidized cafeteria service.
* Access to SEAT’s network of medical centers.
* Group life insurance.
* SEAT Employment Pension Plan starting from the 2nd month of employment.
* Special discounts for purchasing new and used SEAT vehicles.
* Advantages in SEAT vehicle leasing for employees.
* Eligibility to apply for a personal loan starting from the second year of employment.
* Continuous training through our internal Learning platform.
* Activities and employee discounts at SEAT.
*At SEAT, we firmly believe in the power of* ***diversity*** *and* ***inclusion*** *as fundamental pillars of our culture — one where every individual can be authentically free and freely authentic. We work passionately to create an environment where every voice is heard and valued, ensuring* ***equal opportunities*** *for all, regardless of gender, sexual orientation, nationality, ethnicity, cultural identity, age, beliefs, or any other dimension of diversity.*
*Our commitment to diversity and inclusion is a daily priority we hold ourselves accountable to.*