Cybersecurity Product Penetration Tester, KRAKÓW

Your background

  • Pentesting - performing penetration tests of wide range of systems
  • Research - gathering information about industry technologies, familiarizing with new communication protocols and their weaknesses
  • Documentation preparation - reports creation, team's internal documentation development
  • Meetings - taking part in technical meetings and knowledge exchange sessions

The opportunity

We are looking for a skilled security researcher to join Hitachi Energy Cybersecurity Assurance Center - our product security team that performs the penetration testing of every product we build. In this role you will:
- test every kind of product before release - hardware, software, cloud, mobile, OT solutions
- identify and exploit vulnerabilities across all Hitachi Energy products to eliminate them before releasing product to the market
- work closely with engineers to support security-by-design approach implementation
- use and develop the state-of-the art tools, both hardware and software, including CsAC's custom tools fine-tuned for cryptography and LLM-supported reverse engineering

,[In-depth knowledge of TCP/IP networking and application protocols concepts, Understanding of software exploitation and common vulnerabilities, Understanding of port scanning, vulnerability assessment and fuzzing tools, Knowledge of protocols associated with web technologies, Understanding of OWASP Top 10 and SANS 25 vulnerabilities and their mitigations, Knowledge about security testing of mobile apps and related APIs, Experience in working in multicultural environments, Good English communication skills: verbal and writing of technical reports, Knowledge of control communication protocols and technologies, Proficient with one of the scripting languages (e.g., Python), Knowledge of cryptographic and security protocols, Understanding of penetrating testing tools like Metasploit; able to write auxiliary modules and code exploits, Hands-on experience with reverse engineering and binary analysis is a plus, Experience with hardware exploitation techniques including firmware extraction, UART, JTAG, I2C interfacing is a plus, Understanding RF, Bluetooth, NFC and wireless attack surfaces is a plus] Requirements: Security Additionally: Sport subscription, Private healthcare, International projects, Free coffee, Bike parking, Shower, Free snacks, Free parking, Modern office, No dress code.
Data publikacji: 2026-06-24
APLIKUJ