Cybersecurity Internal Penetration Tester — EFG International AG

CHF 85'500 - 150'000
EFG International AG · Geneve (GE)
Categoria: finance Contratto: permanent Salario: CHF 85'500 - 150'000
Apply now
Location
Geneve
Contract
permanent
Posted
106 days ago
SalaryCHF 85'500 - 150'000

Role overview

General Info

  • Department: Information Security & BCM

  • Work time Percentage: 100%

  • Location: Geneva (preferred), Zurich or Lugano

Our Company

EFG International is a global private banking group, offering private banking and asset management services. We serve clients in over 40 locations worldwide. EFG International offers a stimulating and dynamic work environment and strives to be an employer of choice.

EFG is committed to providing an equitable and inclusive working environment that is founded on the principle of mutual respect. Joining our team means experiencing a supportive environment, where your contributions are valued and recognised. We strongly believe that the diversity of our teams gives us a competitive advantage by fostering better decision-making and greater innovation.

Our Purpose and Mission

Empowering entrepreneurial minds to create value – today and for the future.

We are a private bank, offering personalised solutions on a global scale to private and institutional clients. Our sustainable success is based on our talents and on how we partner with our clients and communities to create lasting value.

Job Description

Context - The Information Security & BCM, under the lead of the Group Chief Information Security Officer (CISO) and part of the Chief Operating Officer (COO) organization, defines, leads, and coordinates information security efforts across EFG International and its entities globally. It outlines the information security strategy, identifies, and runs security initiatives and sets standards.

To support the ICT Risk Management Framework, in compliance with regulatory requirements (FINMA, DORA and relevant financial-sector regulations), we are looking for a Cybersecurity Intermal Penetration Tester.

The successful candidate will be responsible for performing ongoing, in-house offensive security assessments of the Bank’s infrastructure, applications and controls.

This role combines hands-on technical experience conducting penetration testing and simulating real-world attacks exercises on corporate environments, with close collaboration with Security, IT, development and risk teams to proactively identify, exploit and advise on the remediation of vulnerabilities in critical banking systems.

Key responsibilities include:

  • Plan, scope and execute internal penetration tests on core banking platforms and business applications, with a strong focus on services supporting critical and important functions

  • Design test scenarios aligned with realistic baking threat models (fraud, data exfiltration, privilege escalation, lateral movements to critical systems,…) and internal risk assessments

  • Execute hands-on tests against internal networks, servers, endpoints, web applications, APIs, cloud workloads, AD and other core infrastructure systems

  • Document findings in clear, risk-based reports with evidence and actionable remediation guidance for technical and non-technical audiences

  • Work closely with infrastructure, development, DevOps and risk teams to support remediation plans and re-testing, ensuring critical findings are tracked to closure within the ICT risk and governance processes.

  • Develop and maintain internal testing methodologies, playbooks and tools to support repeatable and efficient assessments

  • Collaborate with SOC on purple-team style exercises to test and improve detection and response capabilities

  • Stay current on emerging threats, vulnerabilities, TTPs, etc, and incorporate into internal testing

Skills and experience

  • Background in cybersecurity, computer science, or related fields

  • 3-5 years of hands-on penetration testing or red-team experience, with demonstrable work on internal network, web applications and API; banking or financial services experience is a strong plus

  • Strong understanding of network protocols, operating systems (Windows, Linux), web and cloud technologies; familiarity with core banking architectures is a plus

  • Proficiency with common offensive tools and techniques (e.g. Burp Suite, Metasploit, Cobalt Strike-like frameworks, Kali-based tooling) and ability to perform manual testing beyond tools

  • Solid knowledge of secure coding concepts and common application vulnerabilities (e.g. OWASP Top 10) to assess web and API targets

  • Professional certifications such as OCSP, GXPN, or similar offensive security credentials in good standing

  • Strong communication skills and ability to explain complex technical findings to technical and non-technical audience

Our Values

  • Accountability: Taking ownership for tasks and challenges, as well as seeking continuous improvement

  • Hands-on: Being proactive to rapidly deliver high-quality results

  • Passionate: Being committed and striving for excellence

  • Solution-driven: Focusing on client outcomes and treating clients fairly with a risk-aware mindset

  • Partnership-oriented: Promoting collaboration and teamwork. Working together with an entrepreneurial spirit.

Application

Please ensure to attach a cover letter to your CV when filling the application.

Description

- Department : Information Security & BCM

- Location : Geneva (preferred), Zurich or Lugano

Context - The Information Security & BCM, under the lead of the Group Chief Information Security Officer (CISO) and part of the Chief Operating Officer (COO) organization, defines, leads, and coordinates information security efforts across EFG International and its entities globally. It outlines the information security strategy, identifies, and runs security initiatives and sets standards.

Apply now

Questions about this listing

What salary does EFG International AG offer for this role?

EFG International AG lists CHF 85'500 - 150'000 gross per year for this position in Geneve. This is the salary published in the original listing (or, when the employer omits a figure, a realistic estimate for the role and sector) — the calculator on this site converts it to your actual net take-home once cross-border tax and social contributions are applied.

Is this a full-time role, and what type of contract does EFG International AG offer?

This listing is a full-time position. The contract type shown here comes directly from the employer's original posting; always confirm exact hours, notice period and probation length with EFG International AG during the application process, since these details can vary by role even within the same contract category.

Do I need a cross-border work permit for a role in Geneva?

EU/EFTA residents living in the border zone of the country adjoining Canton Geneva can apply for a G permit; the Swiss employer files it with that canton's migration office after the contract is signed. Border-zone rules and processing times vary by neighbouring country and canton, so confirm the specifics with Geneva's cantonal migration office or with HR during the application.

How do I apply for this position at EFG International AG?

Use the "Apply now" button on this page — it links directly to EFG International AG's original listing at fa-eqai-saasfaprod1.fa.ocs.oraclecloud.com, so your application goes straight to the employer's own applicant-tracking system. Frontaliere Ticino does not collect or forward applications itself.

Logo EFG International AG
Company
EFG International AG · Geneve
Frontaliere Ticino discovered this opportunity through company monitoring.

All EFG International AG jobs in Geneve →

Explore similar jobs

Hiring? Publish your job ad

Reach thousands of cross-border and local candidates every week: featured listing, dedicated SEO page and newsletter blast included.

Publish your ad →