senior associate, offensive security 4960976
8 Αυγ 2026 · Pfizer Hellas
Τι θα κάνεις
- Διεξάγεις δοκιμές offensive security, συμπεριλαμβανομένων penetration tests και ασκήσεων προσομοίωσης αντιπάλων σε on‑premises, cloud και hybrid περιβάλλοντα
- Υποστηρίζεις red team και purple team engagements εκτελώντας test plans, συλλέγοντας αποδείξεις και αξιολογώντας την αποτελεσματικότητα των αμυντικών ελέγχων
- Εντοπίζεις, επικυρώνεις και τεκμηριώνεις αδυναμίες ασφαλείας με τεχνικές λεπτομέρειες, αποδεικτικά στοιχεία και σαφείς συστάσεις άρσης
- Μεταφράζεις ευρήματα offensive security σε actionable βελτιώσεις για τις ομάδες ανίχνευσης, μηχανικής και διόρθωσης
- Συνεισφέρεις σε threat‑informed testing χαρτογραφώντας τεχνικές επιτιθέμενων και αναδεικνύοντας ρεαλιστικές επιθετικές διαδρομές
- Διατηρείς υψηλά πρότυπα αναφοράς, διασφαλίζοντας τεκμηριωμένα και ολοκληρωμένα παραδοτέα σύμφωνα με τις ηθικές και εσωτερικές απαιτήσεις
- Υποστηρίζεις τη συνεχή βελτίωση εργαλείων offensive security, αυτοματοποίησης, επαναλαμβανόμενων μεθόδων δοκιμών και playbooks
- Συνεργάζεσαι με διαλειτουργικές ομάδες για τον συντονισμό των δοκιμών και τη μείωση των διαταραχών στη λειτουργία
- Κλιμακώνεις τεχνικά περίπλοκα ζητήματα ή ευρήματα υψηλού κινδύνου
Βασικές προϋποθέσεις
- 2+ χρόνια εμπειρίας
- Προηγμένη γνώση offensive security, penetration testing και vulnerability research
- Ικανότητα εκτέλεσης red team μεθοδολογιών, adversary simulation και purple team ασκήσεων
- Καλή κατανόηση attack techniques και enterprise security σε δίκτυα, cloud και διαχείριση ταυτοτήτων
- Γνώση scripting/programming languages όπως Python, PowerShell ή Bash
- Ικανότητες documentation and reporting με σαφή τεχνική τεκμηρίωση ευρημάτων
- Ικανότητα collaboration skills σε ρυθμιζόμενα περιβάλλοντα
- Εμπειρία στην χρήση offensive security tooling και automation
- Ασφάλεια Πληροφοριών / Πληροφορική / Μηχανική / Οποιοδήποτε Πεδίοκατά προτίμηση
Περιγραφή Θέσης
Our Global Cyber Defense team is responsible for safeguarding Pfizer’s digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Senior Associate, Offensive Security supports offensive security activities that proactively identify, validate, and help prioritize security weaknesses across the digital environment. This role contributes to penetration testing, adversary simulation, and purple team exercises that continuously assess the organization’s exposure to real‑world threats. Operating within a highly regulated pharmaceutical environment, the Senior Associate partners closely with detection, remediation, engineering, and risk teams to ensure findings are clearly documented, actionable, and translated into measurable security improvements. This role will report to the Sr. Manager, Offensive Security.
ROLE RESPONSIBILITIES
Conduct offensive security testing activities including penetration tests and adversary simulation exercises across on‑premises, cloud, and hybrid environments.
Support red team and purple team engagements by executing test plans, collecting evidence, and helping evaluate defensive control effectiveness.
Identify, validate, and document security weaknesses, including technical details, proof of concept evidence, and clear remediation recommendations.
Assist with translating offensive findings into actionable improvement items for detection, engineering, and remediation teams.
Contribute to threat‑informed testing by mapping observed techniques to common attacker behaviors and helping highlight realistic attack paths.
Maintain high quality reporting standards and ensure deliverables are accurate, complete, and aligned to ethical testing expectations and internal requirements.
Support continuous improvement efforts for offensive security tooling, automation, repeatable test methods, and playbooks.
Collaborate with cross‑functional partners (e.g., detection, incident response, vulnerability management, infrastructure, cloud) to coordinate testing logistics and minimize business disruption.
Escalate complex technical issues, high‑risk findings, or unexpected conditions.
BASIC QUALIFICATIONS
Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field, or equivalent practical experience.
2+ years of experience in cybersecurity with hands‑on focus in offensive security, penetration testing, vulnerability research, or security engineering.
Practical experience executing penetration tests or security assessments, including reconnaissance, exploitation validation, and reporting.
Strong understanding of common attack techniques and enterprise security concepts across identity, endpoints, networks, and cloud services.
Ability to clearly document technical findings and communicate risk and remediation guidance to technical stakeholders.
Working knowledge of at least one scripting/programming language commonly used for security work (e.g., Python, PowerShell, Bash).
Strong collaboration skills and ability to operate in a process‑driven, highly regulated environment.
PREFERRED QUALIFICATIONS
Strong hands‑on knowledge of:
Red team and adversary emulation methodologies (MITRE ATT&CK–aligned)
Application, cloud, network, and identity penetration testing
Social engineering and phishing simulations (where appropriate)
Tooling and frameworks commonly used in offensive security
Experience in pharmaceutical, biotech, life sciences, or similarly regulated industries.
Demonstrated capability supporting offensive security testing in cloud or hybrid environments.
Exposure to partnering with detection engineering / SOC teams to improve detections based on offensive findings.
Experience working in regulated industries (e.g., healthcare, life sciences, pharmaceuticals) or environments with high compliance expectations.
Relevant certifications (e.g., CISSP, OSCP, CRTO, GPEN/GXPN), or similar offensive security credentials.
Demonstrated interest in improving repeatability through tooling, automation, and standardized playbooks.

