Cenobe is a specialised offensive security company founded in 2020 and based in Athens with a team spread across Europe. We are part of the Qualco Group — enterprise clients and enterprise-scale pipeline with a team small enough that you own your engagements end to end instead of being one name on a rotation. Alongside the services practice we build Morpheus our own platform bringing offensive tooling findings and remediation workflows together in one place. We also do vulnerability research and publish it CVE-2026-1496 (CVSS 9.3 Black Duck Coverity) CVE-2026-27823 (critical RCE in EGroupware) CVE-2025-24813 (Apache Tomcat) CVE-2025-27407 (GraphQL-Ruby). Research is not a side project here — it is part of how we work and disclosures go out with the researcher's name on them. If you are the person who keeps digging after the scanner has finished this is the team for you. What the job actually looks like You plan scope and run tests across web and mobile apps network and Active Directory cloud (AWS/Azure/GCP) and whatever else a client puts in front of you. You go deep and manual. Business logic chained exploitation auth and authz flaws — the findings a scanner will never produce. You write reports people actually read and you present them yourself. To engineers and to the CISO or CEO in the room. You lead engagements technically. You review other people's work and they review yours. You build your own tooling and exploits and we keep them. You feed what you learn into Morpheus our own security platform. Your detection logic and testing modules ship to real customers. Very few consultancies can offer you that. When you find something in a product you take it through responsible disclosure with your name on it.
- Around 5 years of hands-on offensive security work consulting or in-house. - Real depth in at least two of applications network/AD cloud red teaming. - Strong exploitation and post-exploitation. Comfortable when the tooling stops helping. - You can explain why a finding matters in business terms in clear written English. - OSCP OSWE OSEP CRTO or equivalent evidence that you can do the work. A good writeup or a public tool counts with us. - Authorised to work in the EU and available in European business hours. Weighs meaningfully in your favour red team experience (adversary emulation C2 evasion and detection bypass social engineering physical) published CVEs talks or open-source tooling OT/ICS or IoT TIBER-EU DORA or NIS2 work Kubernetes and CI/CD pipeline attacks. Greek is useful for some client work. It is not a requirement. If you do not tick every box apply anyway. We have hired people who were missing something on this list and were obviously right for the role. We would rather read your CV and decide ourselves.
Unlock: Sign Up for free / Sign In and use the searches from your home page or the links in the footer.