Cybersecurity Senior Penetration Tester
- 3+ years of hands-on penetration testing experience.
- Strong practical experience in at least one penetration testing domain, such as:
- Web applications
- Mobile applications
- APIs
- Infrastructure and networks
- Strong understanding of common vulnerabilities, attack techniques and security testing methodologies.
- Excellent knowledge of TCP/IP, networking and security protocols.
- Strong web application security testing experience.
- Practical experience with both manual and automated security testing.
- Good programming or scripting skills.
- Strong analytical and critical-thinking skills.
- Ability to understand the business impact of technical security findings.
- Ability to communicate complex security topics clearly to both technical and non-technical audiences.
- Ability to work independently, manage priorities and take ownership of assigned security assessments.
- Strong written and spoken English.
- Ability to solve complex technical problems and adapt to new technologies and scenarios.
Mobile Security – nice to have
Experience with mobile application security testing would be a strong advantage, particularly:
- Android and/or iOS security models.
- Common mobile application vulnerabilities and attack techniques.
- OWASP MASVS and OWASP MSTG.
- Mobile application testing frameworks and tools.
- Static and dynamic analysis.
- Security testing of authentication and authorization mechanisms.
- SSL/TLS and certificate pinning.
- Biometric authentication.
- JWT, OAuth 2.0 and SAML.
- RASP and other application security controls.
- Reverse engineering and application disassembly.
Application Security & Development – nice to have
- Experience with SAST, DAST and IAST tools and understanding of their limitations.
- Experience with security code reviews.
- Knowledge of Java, Kotlin, Swift and/or Objective-C.
- Understanding of software development lifecycles and DevOps practices.
- Experience testing cloud-hosted applications and services.
- Understanding of enterprise application architectures and common security issues.
- Previous software development experience, particularly for Android or iOS, would be an advantage.
- Experience with technologies such as HTML, XML, JavaScript, JSON, REST and microservices.
- Understanding of applied cryptography in application development.
Certifications
Professional security certifications are not required, but relevant certifications such as OSCP, OSWE, OSEP, CREST or equivalent will be considered an advantage.
Senior Penetration Tester
We are looking for an experienced Senior Penetration Tester to join a cybersecurity team responsible for identifying vulnerabilities, assessing security risks and helping engineering teams build more secure applications and services.
In this role, you will perform hands-on security assessments across web applications, APIs, mobile applications, infrastructure and networks. You will combine manual testing, automated security tools, source code and configuration reviews to identify vulnerabilities and demonstrate their potential impact.
The role is highly technical, but also requires strong communication skills. You will work closely with technical and non-technical stakeholders, explain security risks in a clear and practical way, and provide guidance on remediation and secure development.
What we offer
- B2B contract
- Hybrid working model – 6 days per month from the office in Kraków
- Private healthcare – Lux Med
- MyBenefit cafeteria
- Dedicated support from a Contractor Care Specialist