The posting
Are you a Penetration Tester & Red Team Operator? Think bigger about your next move!
Build your future with QnR Group. JOIN THE NEXT EUROPEAN TECHNOLOGY POWERHOUSE 🚀
Penetration Tester & Red Team Operator | SysteCom, member of QnR Group
Role overview
We are looking for a Penetration Tester & Red Team Operator to test the resilience of networks, applications, cloud environments and people through authorised security assessments and adversary simulation.
About QnR Group
QnR Group is a technology group with 35 years of experience, 8 companies, 4 delivery centers and 210+ professionals across Greece, Belgium, Cyprus and Poland. Listed on the Athens Stock Exchange since 2000, we deliver mission-critical digital transformation projects for the public and private sector. The Group’s capabilities covers software engineering, enterprise and generative AI, cybersecurity, cloud infrastructure, SAP and ServiceNow solutions, core banking and maritime intelligence.
About SysteCom
SysteCom, a member of QnR Group, specializes in cybersecurity, digital resilience and IT infrastructure. The company delivers solutions and services that help organizations protect their systems and data, strengthen operational continuity and modernize their technology environments. Bringing together security and infrastructure expertise, SysteCom supports businesses across sectors in building secure, reliable and resilient digital operations.
Requirements
What you'll work on:
- Conduct scoped vulnerability assessments and penetration tests
- Perform manual validation and exploitation, not only automated scanning
- Document findings, business impact, evidence and practical remediation
- At senior levels, design red-team scenarios and lead client-facing engagements
- Work with defensive teams to improve prevention and detection
What you bring:
- Hands-on authorised testing experience across one or more of web applications, APIs, infrastructure, Active Directory, wireless, mobile or cloud environments
- Strong understanding of OWASP guidance, common attack paths, vulnerability classes and safe rules of engagement
- Ability to combine automated tooling with manual validation, exploitation and business-impact analysis
- Proficiency with common testing toolsets and scripting in Python, PowerShell, Bash or a comparable language
- Ability to produce clear, reproducible findings with evidence, severity rationale and practical remediation advice
- Understanding of operational security, data handling, legal boundaries and controlled test execution
- For red-team candidates, experience planning adversary scenarios, command-and-control operations, lateral movement and detection-evasion testing
- For senior candidates, experience scoping engagements, leading delivery and presenting findings to technical and executive stakeholders.
Required certifications:
Mid-level and Senior: at least one recognised practical certification, such as OSCP, OSWA, OSWE, GPEN, GWAPT, CRTO or equivalent
Senior red-team roles may require an advanced certification such as OSEP, OSED, OSCE3, GXPN or equivalent
Nice to have:
- OSCP, OSWA/OSWE, GPEN, GWAPT, CRTO or equivalent practical capability
- Purple-team, exploit-development or social-engineering experience where authorised



