Senior Penetration Tester

Mindbox Sp. z o.o. KRAKÓW 2026-09-10


  • Strong experience in penetration testing, with at least 3+ years of hands-on experience.

  • Demonstrated expertise in testing web applications, infrastructure, and mobile technologies using both manual and automated methods.

  • Knowledge across key pentesting domains: application, network, and/or mobile.

  • Understanding of platform security models for iOS and Android and associated mobile security risks.

  • Excellent TCP/IP knowledge and understanding of security implications at multiple protocol layers.

  • Ability to analyze and explain security vulnerabilities and cryptographic principles from first principles.

  • Proven programming or scripting skills for test automation and exploit development.

  • Critical thinking and strong ability to articulate issues and recommendations to both technical and non-technical audiences.

  • Strong organizational skills with the ability to work independently or lead testing engagements.


Nice to have:



  • Familiarity with common vulnerabilities in financial applications and highly regulated environments.

  • Awareness of application security scanning tools (e.g., SAST, DAST, MAST).

  • Relevant certifications (e.g., OSCP, OSWE, CREST, GPEN) – not mandatory but highly valued.




Joining this project you’ll become part of Mindbox – a tech-driven company where consulting, engineering, and talent meet to build meaningful digital solutions. We’ll back you up every step of the way, accelerate your development, and ensure your skills make a difference. 



At Mindbox we connect top IT talents with technology projects for leading enterprises across Europe. 



 


We are seeking an experienced Penetration Testing Specialist to join our global Cybersecurity team. You will be responsible for conducting and leading penetration tests across multiple technology domains – including infrastructure, applications, web services, and mobile platforms – while ensuring the organization operates within defined risk appetite.


This role goes beyond testing; you will proactively identify vulnerabilities, articulate risks in business terms, and advocate risk mitigation strategies. As a subject matter expert, you will collaborate with engineering teams, business stakeholders, and global security groups to improve security posture, influence best practices, and mentor junior testers.




Sounds like your kind of challenge? 



What you get in return


  • Flexible cooperation model 

  • Hybrid work setup – 6 days from the office per month

  • Collaborative team culture – work alongside experienced professionals eager to share knowledge 

  • Continuous development – access to training platforms and growth opportunities 

  • Comprehensive benefits – including Interpolska Health Care, Multisport card, Warta Insurance, and more 

  • High quality equipment – laptop and essential software provided 


,[Lead and perform manual penetration testing across diverse environments – infrastructure, custom applications, web services, APIs, and mobile platforms (iOS and Android)., Own the design, execution, and documentation of penetration testing engagements, ensuring high-quality deliverables., Translate highly technical findings into clear, actionable business risk statements., Conduct source code and configuration reviews where applicable., Maintain an objective, risk-based approach in line with the organization’s Cybersecurity and compliance frameworks., Provide guidance, supervision, and mentoring to junior team members., Continuously improve security testing processes, tools, and methodologies to increase quality and efficiency., Collaborate with global stakeholders to ensure compliance with internal standards and regulatory requirements.] Requirements: Testing, Web applications, Security, iOS, Android, TCP, Test automation, SAST, DAST, OSCP, OSWE