Pentester & Security Engineer

Skopje, North Macedonia
Bitola, North Macedonia
Ohrid, North Macedonia

G+D Netcetera operates in a fast-paced B2B environment and is specialized in secure financial sector applications. The company is growing and active in the Research & Development of new Products and Services for customers.

G+D Netcetera is an early adopter and a specialist in digital payment systems and the corresponding security and compliance needs.

We’re looking for a versatile Pentester & Security Engineer who can shift seamlessly between deep technical testing and hands-on enablement of engineering teams. You’ll perform penetration tests, drive threat modeling and security requirements engineering, and take ownership of developing, maintaining, and operating cloud‑security tools, guardrails, and configurations. You will help teams remediate vulnerabilities at speed. This role is perfect for a pragmatic engineer who can read and write code, understands how products are built and shipped, and loves to partner with developers to make secure delivery the default.

The job ad is valid until 31.03.2026

Your Tasks

  • Perform targeted penetration tests and security assessments across:
    • K8s and containerized workloads
    • Web applications and APIs
    • AWS and Cloud Infrastructure
  • Support development teams in Secure software engineering
    • Security Architecture support
    • Security Requirements support
    • Threat modelling 
    • Secure code reviews
    • Security Tooling usage (CI/CD, SAST, DAST etc)
  • Vulnerability Management
    • Support teams in their vulnerability management lifecycle ( discovery → triage → remediation → validation) 
    • Champion secure coding practices and provide targeted remediation guidance with code snippets.
  • Security Operations
    • Build or enhance security telemetry using AWS-native tooling (CloudTrail, GuardDuty, WAF, Security Hub, CloudWatch)
    • Implement and maintain policy-as-code tools & solutions (Kyverno, OPA)
    • Implement and maintain a variety of security tools such as (Neuvector, Trivy, Dependencytrack, Defectdojo)

Your profile

  • Bachelor’s degree in computer science, information security, engineering, or a related field.
  • A minimum of 3+ years of solid, hands‑on experience in Software engineering, IT security engineering, systems engineering, or cloud security within a corporate or high‑tech environment.
  • 2+ years penetration testing or application security experience.
  • Proven ability to read, write, and understand production code.
  • Container & Kubernetes security experience (RBAC, admission controls etc).
  • Understanding of cloud-native attack vectors (privilege escalation, SSRF, misconfigured IAM policies).
  • Familiarity with traditional, modern, and software‑defined networking concepts and technologies.
  • Fluent English speaker and writer.

Nice to haves:

  • Experience in fintech, payments, banking, or regulated industries.
  • Knowledge of relevant standards (PCI DSS, SOC 2, ISO 27001, EBA/FINMA guidelines).
  • Familiarity with compliance expectations in regulated environments.
  • Strong knowledge of AWS security fundamentals, including IAM, KMS, network segmentation, workload identity, and monitoring.
  • Professional experience with Terraform.
  • Certifications such as OSCP, OSWE, AWS Security Specialty

Über G+D Netcetera

G+D Netcetera ist ein führendes Schweizer Softwareunternehmen mit zukunftsweisenden digitalen Lösungen für Digital Banking, Payment, Mobility, Healthcare und Publishing. G+D Netcetera ermöglicht Unternehmen Wachstumschancen und schafft für sie neue Möglichkeiten in der digitalen Welt. Mit ihren Fachkenntnissen und über 25 Jahren Erfolgsbilanz entwickelt das Unternehmen zukunftssichere und skalierbare Software, die echten Mehrwert für ihre Kunden und die Verbraucher:innen bringt. G+D Netcetera ist Expertin für nahtlose und sichere User Journeys in hochsicheren und Datenschutz getriebenen Umgebungen.

1996 gegründet, beschäftigt G+D Netcetera rund 800 Expert:innen an ihrem Hauptsitz in Zürich, Schweiz, und den verschiedenen Standorten in Europa. Seit 2020 ist das Unternehmen als Trusted Software Division das digitale Powerhouse innerhalb des Konzerns für SecurityTech Giesecke+Devrient (G+D). G+D ist ein weltweit tätiges Unternehmen mit Hauptsitz in München und schafft mit integrierten Sicherheitstechnologien Vertrauen im digitalen Zeitalter.

Weitere Informationen auf netcetera.com und LinkedIn.

Seite teilen: