Senior Penetration Tester @Thessaloniki
What Impact will you make?
Are you looking for an opportunity in Thessaloniki that offers you a hybrid working model?
Are you ready to work on large scale projects for industry-leading clients around the world and elevate your career to an international level?
If so, check below for more info about this career opportunity!
You bring passion, we bring opportunities!
#YourOpportunity
Deloitte is a worldwide leader in Professional Services with a presence in more than 150 countries and territories. Since 2018, Deloitte has been operating its Alexander Competence Center in Thessaloniki with satellites in the cities of Patras, Heraklion, and Ioannina - which are model hubs of expertise, training, and innovation, specializing in cutting-edge exponential technologies, in which professionals undergo immersive experiences, continuous learning, gaining practical insights and hands-on training that empower them to navigate the complexities of the digital landscape.
Deloitte is an ideal working environment for both young and senior professionals who want to take the next step in their careers, offering them a supportive and international working environment that leverages their expertise and potential. Its corporate culture is based on trust and collaboration and ensures diversity and inclusion so that everyone feels part of a great team.
We are currently seeking for experienced and highly motivated professionalsto become part of our Cyber Defense & Resilience team within our Technology & Transformation department in Thessaloniki.
#YourServiceLine: Technology & Transformation
Our Technology & Transformation teams empower organizations to navigate the future through technology-driven business transformation. Combining deep industry knowledge with cutting-edge technology, we deliver tailored solutions that drive innovation, enhance efficiency, promote cybersecurity, and foster sustainable growth.
#AboutYourTeam
Our Offensive Security Team specializes in identifying, testing, and breaching security boundaries to build unyielding resilience. We simulate sophisticated real-world attacks across hybrid infrastructures, cloud platforms, applications, networks, and complex enterprise environments to expose vulnerabilities before they can be exploited.
Quite simply, we provide the adversarial perspective, delivering rigorous penetration testing and red teaming engagements that stress-test our clients’ defenses and help them strengthen their security posture.
Join us and you could find yourself working on a broad range of offensive security assignments, from focused technical assessments to complex multi-domain penetration testing programs. These may include web applications, APIs, mobile applications, infrastructure, cloud platforms, containerized environments, network infrastructure, wireless networks, firewall and security gateways, source code reviews, thick clients, mainframe applications, telecommunication infrastructure, and risk-based penetration testing.
In short, you will break solutions to help our clients build them stronger, meeting evolving business requirements while contributing to the growth of the team through high-impact delivery, technical leadership, and thought leadership in the offensive security space.
#Core Responsibilities
· Lead and deliver penetration testing and offensive security assessments across web applications, APIs, mobile applications, infrastructure, networks, cloud platforms, and other complex enterprise environments.
· Perform hands-on vulnerability identification, validation, and exploitation, assessing technical risk and business impact in line with agreed scope and rules of engagement.
· Apply recognized security methodologies and frameworks such as OWASP, NIST, PTES, and MITRE ATT&CK throughout the assessment lifecycle.
· Prepare clear, actionable reports and present findings to technical and non-technical stakeholders, supporting clients in prioritizing and tracking remediation activities.
· Mentor junior team members, review technical outputs, and contribute to the continuous improvement of offensive security methodologies, tools, and delivery quality.
#OurRequirements
- Academic background (BSc and MSc) related to Information Technology, Computer and Data Science, Business Informatics, Engineering. We also welcome graduates with a business background, who have major in Information Systems Management or any other IT-related major.
- Able to manage office automation tools, such as MS Excel, MS PowerPoint, MS Access
- Excellent command of the Greek and English language
- Very good knowledge of Italian and other languages will be considered a plus
- Strong interest for Offensive Security with active participation in CTFs (e.g., Hack The Box, TryHackMe)
- Theoretical knowledge of Cloud, Infrastructure, Mobile, API, and Web architectures from an offensive security and exploitation perspective.
- Proficiency in scripting and code analysis (e.g., Python, Bash, C#) for exploit automation and vulnerability testing.
- Relevant certifications such as OSCP (Offensive Security), CPTS (Hack The Box), or BSCP (PortSwigger) are highly preferred.
- Analytic mindset
- Good interpersonal and communication skills
- Aptitude to the team working
- Client Orientation
- Academic background in Information Technology, Computer Science, Cybersecurity, Computer Engineering, Data Science, Business Informatics, Engineering, or other relevant IT-related disciplines.
- Minimum 3 years of professional experience in penetration testing, offensive security, vulnerability assessment, red teaming, or similar cybersecurity roles.
- OSCP certification is required.
- Additional relevant certifications such as OSEP, OSWE, CPTS, CRTO, GPEN, GWAPT, eWPTX, eCPPT, CARTP, or BSCP will be considered a strong asset.
- Hands-on experience across several penetration testing domains, such as web applications, APIs, mobile applications, infrastructure, networks, cloud platforms, operating systems, servers, containerized environments, wireless networks, or thick clients.
- Strong knowledge of offensive security methodologies, vulnerability exploitation techniques, and security frameworks such as OWASP, NIST, MITRE ATT&CK, and related industry standards.
- Experience with offensive security tools such as Burp Suite, Nmap, Metasploit, Nessus, BloodHound, Impacket, Cobalt Strike, or equivalent tools.
- Proficiency in scripting and code analysis, for example with Python, Bash, PowerShell, C#, or other relevant languages used for automation, testing, and tooling.
- Strong reporting, communication, and client-facing skills, with the ability to produce clear deliverables and interact effectively with technical teams and senior stakeholders.
- Excellent command of the Greek and English language; knowledge of Italian or other languages will be considered a plus.
If you are ready to apply your offensive security expertise in a challenging international environment, contribute to high-impact projects, and collaborate with teams across Greece and abroad, you are ready for Deloitte!
#WhatWeOffer
At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits:
- Modern hybrid workplace, characterized by flexibility and Smart Working
- Empowered well-being: We provide multiple program offerings to support your well-being needs (flexible working arrangements, extra days of leave, parental allowances)
- Engagement within international large-scale teams and projects, with opportunities to travel for training or client purposes.
- Constant opportunities for learning with unlimited access to internal and external learning platforms and sponsored certificates aligned with business needs and technology trends
- Challenging and innovating environment where personal development and growth are encouraged, always with transparency and trust
- Diverse culture and active communities that enable you to bring yourself to work
- Team Building and Corporate Social Responsibility Activities
- A buddy to support you with your onboarding
- Extra days of annual leave
- Private medical health insurance plan
- Ticket restaurant card
- Exclusive Discounts to several retail providers, restaurants and others
- Mobile phone
- Fresh fruits and unlimited coffee everyday at our offices
About Deloitte
#OurServices
Deloitte offers integrated services that include Audit, Consulting, Financial Advisory, Risk Advisory, Tax and Legal. Our approach combines insight and innovation from multiple disciplines with global business and industry expertise to help our clients excel anywhere in the world. We deliver outstanding impact on the reputation and success of our clients, in Italy and globally. In pursuing this we contribute to a sustainable and prosperous society, and are firm believers in the positive impact business can and should have on the world it operates within.
#OurPurpose
We are led by a purpose, to make an impact that matters with clients, people and society. This purpose defines who we are and what we stand for. It's not about being the biggest. It’s about being the first choice for the largest and most influential clients, and the first choice for the best talent.
#OurValues
At Deloitte we foster a collaborative culture where talented individuals can produce their best work. We value innovative thinking, diverse insights and a genuinely distinctive level of customer service through our expertise and professionalism. We value difference, with respect at the heart of our inclusive culture.
#OurTalentExperience
From day one at our firm, practitioners are part of a community. Our development and career progression framework will help them develop the skills and capabilities to succeed. The wellness of our people and the ability to offer agile working arrangements is at the center of our unique talent experience. We create a workplace that encourages collaboration, creativity, inclusiveness to ensure our staff are supported, encouraged and feel a sense of purpose and meaning in what they do each day.
Sounds like the sort of role for you? Apply now.
Location: Thessaloniki
This document has been prepared by Deloitte Business Solutions Societe Anonyme of Business Consultants, Deloitte Certified Public Accountants Societe Anonyme and Deloitte Alexander Competence Center Single Member Societe Anonyme of Business Consultants.
Deloitte Business Solutions Societe Anonyme of Business Consultants, a Greek company, registered in Greece with registered number 000665201000 and its registered office at Marousi Attica, 3a Fragkokklisias & Granikou str., 151 25, Deloitte Certified Public Accountants Societe Anonyme, a Greek company, registered in Greece with registered number 0001223601000 and its registered office at Marousi, Attica, 3a Fragkokklisias & Granikou str., 151 25 and Deloitte Alexander Competence Center Single Member Societe Anonyme of Business Consultants, a Greek company, registered in Greece with registered number 144724504000 and its registered office at Thessaloniki, PAEGA Building, Land Port Zone of the Port of Thessaloniki, 54626 Thessaloniki, Greece, are all companies of the Deloitte Central Mediterranean S.r.l. (“DCM”) geography. DCM, a company limited by guarantee registered in Italy with registered number 09599600963 and its registered office at Via Santa Sofia no.28, 20122, Milan, Italy is one of the Deloitte NSE LLP geographies. Deloitte NSE LLP is a UK limited liability partnership and member firm of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee.
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms and their related entities (collectively, the “Deloitte organization”). DTTL (also referred to as “Deloitte Global”) and each of its member firms and related entities are legally separate and independent entities, which cannot obligate or bind each other in respect of third parties. DTTL and each DTTL member firm and related entity is liable only for its own acts and omissions, and not those of any of each other. DTTL does not provide services to clients. Please see www.deloitte.com/ about to learn more.
DTTL, Deloitte NSE LLP and Deloitte Central Mediterranean S.r.l. do not provide services to clients. Please see www.deloitte.com/about to learn more about our global network of member firms.
Deloitte is a leading global provider of audit and assurance, consulting, tax and related services. Our global network of member firms and related entities in more than 150 countries and territories serves four out of five Fortune Global 500® companies. Learn how Deloitte’s approximately 470,000 people make an impact that matters at www.deloitte.com.
This communication contains general information only, and Deloitte Business Solutions Societe Anonyme of Business Consultants, Deloitte Certified Public Accountants Societe Anonyme and Deloitte Alexander Competence Center Single Member Societe Anonyme of Business Consultants, is not, by means of this communication, rendering professional advice or services. Before making any decision or taking any action that may affect your finances or your business, you should consult a qualified professional adviser. No entity in the Deloitte organization shall be responsible for any loss whatsoever sustained by any person who relies on this communication. Deloitte organization refers to Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms and their related entities collectively.
© 2026 For more information contact Deloitte Central Mediterranean.