EFG International seeks a Mid-level Cybersecurity Internal Penetration Tester in Geneva to conduct offensive security assessments and support the ICT Risk Management Framework.
This position is integral to the bank's ICT Risk Management Framework, ensuring compliance with regulatory standards. The specialist performs continuous, in-house offensive security evaluations of the institution's infrastructure, applications, and controls. By simulating real-world attack scenarios, the role combines deep technical expertise with practical penetration testing to identify and mitigate vulnerabilities within the corporate environment.
Responsibilities
- Plan, define the scope, and carry out internal penetration tests on core banking platforms and business applications.
- Create test scenarios that reflect realistic banking threat models and internal risk assessments.
- Conduct hands-on security testing against internal networks, servers, endpoints, web applications, APIs, cloud workloads, Active Directory, and other critical infrastructure systems.
- Produce clear, risk-based reports containing evidence and actionable remediation guidance tailored for both technical and non-technical stakeholders.
- Collaborate with infrastructure, development, DevOps, and risk teams to support remediation efforts and conduct re-testing.
- Develop and maintain internal testing methodologies, playbooks, and tools to ensure repeatable and efficient assessments.
- Partner with the Security Operations Center (SOC) on purple-team exercises to enhance detection and response capabilities.
- Stay updated on emerging threats, vulnerabilities, and tactics, techniques, and procedures (TTPs), integrating them into internal testing practices.
Requirements
- Degree or background in cybersecurity, computer science, or a related field.
- 3-5 years of hands-on experience in penetration testing or red-teaming.
- Strong understanding of network protocols, operating systems (Windows, Linux), web technologies, and cloud environments.
- Proficiency with common offensive tools and techniques, with the ability to perform manual testing beyond automated tools.
- Solid knowledge of secure coding concepts and common application vulnerabilities, such as the OWASP Top 10.
- Strong communication skills, with the ability to explain complex technical findings to both technical and non-technical audiences.
Nice to have
- Experience in the banking or financial services sector.
- Familiarity with core banking architectures.
- Professional certifications such as OCSP, GXPN, or similar offensive security credentials in good standing.
About the company
EFG International is a global private banking group providing private banking and asset management services. The company strives to be an employer of choice by fostering a stimulating and dynamic work environment. It is committed to providing an equitable and inclusive workplace founded on mutual respect, believing that team diversity drives better decision-making and innovation. The company's purpose is to empower entrepreneurial minds to create value today and for the future.
- Stimulating and dynamic work environment.
- Equitable and inclusive workplace founded on mutual respect.
- Diversity of teams fosters better decision-making and greater innovation.
- Purpose: Empowering entrepreneurial minds to create value – today and for the future.
- Values: Accountability, Hands-on, Passionate, Solution-driven, and Partnership-oriented.
How to apply
Documents to submit:
Quelle: öffentlich zugängliche Karriereseite des Arbeitgebers. Batchly ist nicht der Arbeitgeber und steht nicht notwendigerweise in einem Vertragsverhältnis mit dem Unternehmen.