Security Engineer - Pentester
Job description
About the role
You will own the end-to-end penetration testing lifecycle across Scaleway's cloud infrastructure, applications, and APIs, designing realistic attack scenarios that mirror adversarial tactics. You will simulate sophisticated cyber threats to uncover security weaknesses before malicious actors can exploit them, directly contributing to the robustness of our sovereign cloud platform. Your work will focus on offensive security activities that validate the effectiveness of existing controls and uncover hidden attack surfaces. You will assess, exploit, and document findings with a high level of precision and ethical responsibility. Collaboration with product and engineering teams will be central as you guide remediation efforts and verify the successful implementation of security fixes. You will continuously refine testing methodologies and tooling to keep pace with evolving threats and cloud architectures. Your role will directly support the integrity and trustworthiness of Scaleway services for customers across Europe.
Key facts
What you'll do
- Conduct web, API, network, and infrastructure penetration tests on Scaleway products and internal systems using advanced methodologies.
- Simulate realistic cyberattack scenarios across the full stack to identify vulnerabilities and understand their business impact.
- Perform Red Team operations and adversarial simulations, including targeted social engineering campaigns to test organizational resilience.
- Assess identified vulnerabilities using risk-based prioritization frameworks that consider exploitability and potential impact.
- Author clear, structured, and actionable security reports tailored for both technical and executive stakeholders.
- Partner closely with product and engineering teams to support the timely remediation of discovered vulnerabilities.
- Contribute to the architecture, development, and enhancement of the internal pentesting tool stack and workflows.
- Monitor and integrate emerging vulnerabilities, exploits, and offensive security techniques into active testing coverage.
- Support the continuous security testing workflow by automating processes and improving test coverage across Scaleway products.
- Maintain up-to-date knowledge of cloud security best practices, attack vectors, and compliance requirements relevant to scalable platforms.
- Collaborate with SOC and CSIRT teams to correlate pentesting findings with real-time threat intelligence and incident response activities.
- Validate the effectiveness of security controls through controlled exploitation and verify that remediation efforts resolve identified issues.
- Document tactics, techniques, and procedures (TTPs) to enhance internal playbooks and improve future testing iterations.
- Participate in threat modeling sessions to proactively identify risks during the design phase of new products and features.
- Act as a subject matter expert for offensive security within the Trust & Security Operations team, mentoring junior team members when appropriate.
Requirements
- Demonstrate hands-on experience with penetration testing across web, APIs, networks, and infrastructure environments in a professional context.
- Show a solid understanding of the OWASP Top 10, MITRE ATT&CK framework, common CVEs, and exploitation techniques used in the wild.
- Exhibit proficiency with security tools such as Nmap, Metasploit, Burp Suite, and OWASP ZAP in real-world testing scenarios.
- Apply strong scripting and development capabilities in languages such as Python, Bash, SQL, and PHP to automate testing tasks and develop proof-of-concept exploits.
- Possess a deep understanding of vulnerability exploitation techniques including cross-site scripting (XSS), SQL injection, buffer overflows, and reverse engineering methods.
- Maintain a strong analytical mindset characterized by natural curiosity and the ability to think critically about complex security problems.
- Approach problem solving with creativity and an "outside the box" mindset to discover non-obvious vulnerabilities and attack paths.
- Adhere to the highest standards of ethics and integrity when conducting offensive security work and handling sensitive findings.
- Produce clear, concise, and well-structured reports that effectively communicate risk to diverse audiences.
- Thrive in a collaborative environment, demonstrating a genuine team spirit and a willingness to share knowledge and support colleagues.
- Comply with all organizational security policies, procedures, and regulatory requirements during testing activities.
- Commit to continuous professional development by staying informed about the latest security research, tools, and industry best practices.
- Respect the principles of responsible disclosure and follow established processes for reporting and remediating vulnerabilities.
- Meet all contractual and employment eligibility requirements as defined by Scaleway's human resources and legal policies.
Nice to have
- Familiarity with cloud security architectures, particularly within public cloud and hybrid environments.
- Experience with bug bounty programs and responsible disclosure practices.
- Knowledge of DevSecOps pipelines and how security testing integrates into CI/CD workflows.
- Exposure to infrastructure as code (IaC) security assessment techniques.
- Understanding of identity and access management (IAM) concepts and common misconfigurations.
Practical notes
- This is a full-time, long-term position based in Paris.
- The role may require occasional travel within France for on-site assessments or client engagements.
- Candidates must be eligible to work in France without sponsorship.
- Visa sponsorship is not available for this position.
- Applicants must meet all stated requirements; partial profiles will not be considered.
- The selected candidate will be expected to integrate quickly into a fast-paced, international team environment.
- All communications regarding this role will be conducted in French or English.