GetPro

Pentester (Offensive Security)

Attacks your systems before real attackers do: penetration testing, red teaming, vulnerability exploitation.

Why this hire matters.

An exploited breach costs hundreds of thousands of euros on average — before counting reputational damage, GDPR notification duties and, for B2B SaaS, enterprise deals lost for lack of certification. The pentester is your attacker under contract: they find flaws before criminals do and hand you a prioritized fix list. It's also a commercial prerequisite: security due diligence (SOC 2, ISO 27001) and customer questionnaires demand regular penetration tests. Hiring in-house vs commissioning a firm depends on your attack surface: a product shipping weekly justifies an embedded offensive profile. Verify real-world experience (CTFs, bug bounty, OSCP) — the field attracts many theoretical profiles.

Key missions.

  • Run penetration tests (web, API, infra, mobile)
  • Lead red team and social engineering exercises
  • Document vulnerabilities and prioritize remediation
  • Re-test after fixes
  • Contribute to compliance audits (SOC 2, ISO 27001)
  • Train development teams on secure coding
  • Track emerging attack techniques

Skills.

Technical skills

  • Web (OWASP), network and Active Directory exploitation
  • Offensive tooling (Burp, Metasploit, Nmap)
  • Scripting (Python, Bash)
  • Actionable report writing
  • OSCP/OSEP certifications valued

Expected qualities

  • Impeccable ethics
  • Obsessive curiosity
  • Teaching mindset toward devs

Common stack

Burp SuiteMetasploitNmapBloodHoundCaido

Salaries 2025-2026

LevelExperienceAnnual gross base
Junior0-2 yrs42–50 k€
Mid-level2-5 yrs52–70 k€
Senior5-8 yrs70–95 k€
Lead / Red team8+ yrs95–130 k€

Paris market ranges, 2025-2026.

Outside the Paris region, expect 10 to 20 % less.

Sources : Cyberini 2026 · Get in Talent 2026 · Michael Page 2026

Hiring this profile.

Typical background

Cyber engineering school, or self-taught path validated by CTFs/bug bounty and certifications. Audit-firm experience is a classic accelerator.

When to hire

In-house once product security becomes continuous (Series B+, enterprise customers). Before that, quarterly external pentests often suffice.

Career path

Senior → Pentest lead / Red team lead → CISO, or independent expertise (bug bounty, consulting).

Related job profiles.

Contact GetPro