May 2, 2026

Pentester

Senior • Remote

Warsaw, Poland

Role Objective

The primary objectives of the role are to:

  • Identify security vulnerabilities in external and internal infrastructure/applications.

  • Validate the effectiveness of existing security controls.

  • Ensure compliance with DORA and PCI-DSS regulations.

  • Provide actionable remediation guidance.

Scope of Work

The Penetration Tester will be responsible for conducting comprehensive penetration tests across the following areas:

Asset Type Environment Notes

  • Web applications Staging/Prod Main customer portal, admin panels, complex business-oriented apps

  • Mobile applications Staging/Prod Android/iOS native apps, React Native

  • Cloud environment Production AWS/Azure/GCP, CIS benchmark

  • Thick client apps Production Desktop agents, use of API

  • External infra Production Firewalls, VPN gateways

  • Internal infra Production AD environment, database servers

  • APIs and microservices Staging/Prod REST API provided with Swagger

Testing Methodology

  • Manual vs Automated: Emphasis on manual exploitation. Automated scanning should not exceed 20% of effort.

  • Standards: Testing must adhere to OWASP Top 10 for web/mobile apps, PTES, or OSSTMM.

  • Credentials: For grey-box testing, accounts will be provided (e.g., admin, user, viewer) for privilege escalation testing.

Key Requirements

  • Proven experience in delivering high-quality pentest services to enterprise clients (at least 5 years of experience delivering pentests) and client references.

  • Team members with relevant certifications (e.g., OSCP, OSCE, OSWE, GPEN, GWAPT, CISSP).

  • High communication quality: clear verbal communication and reporting.

  • Ability to deliver detailed, structured, and actionable reports.

  • Use of industry-standard tools and methodologies.

Similar jobs you might like

Technology

Ness Solution

Tester Penetracyjny

Mid

Remote

Warsaw, Poland

90 - 100 PLN

🏢 Summary: Oferta dotyczy prowadzenia manualnych i automatycznych testów penetracyjnych aplikacji webowych, mobilnych, API oraz infrastruktury IT wraz z analizą podatności i raportowaniem rekomendacji bezpieczeństwa. Rola obejmuje także analizę kodu, testowanie środowisk kontenerowych oraz pracę z systemami IAM i rozwiązaniami chmurowymi. 🗂️ Requirements: Minimum 3 lata doświadczenia w testach penetracyjnych lub bezpieczeństwie ofensywnym, Znajomość OWASP, Znajomość OWASP WSTG, Znajomość OWASP MASVS, Znajomość CVSS, Znajomość MITRE ATT&CK, Znajomość systemów operacyjnych, Znajomość sieci komputerowych i protokołów sieciowych, Doświadczenie w testach bezpieczeństwa aplikacji webowych, Doświadczenie w testach bezpieczeństwa aplikacji mobilnych, Doświadczenie w testach bezpieczeństwa API, Doświadczenie z Active Directory, Doświadczenie z Exchange, Doświadczenie z rozwiązaniami chmurowymi, Doświadczenie z systemami IAM, Znajomość relacyjnych i nierelacyjnych baz danych, Podstawy kryptografii, Znajomość Docker, Znajomość Kubernetes, Umiejętność analizy i deobfuskacji kodu, Umiejętność obchodzenia SSL Pinning 📃 Skills: OWASP, WSTG, MASVS, CVSS, MITRE, ActiveDirectory, Exchange, Keycloak, Docker, Kubernetes, API, IAM, SQL, NoSQL, Cryptography, SSLPinning 🏢 Description: Zakres obowiązków Prowadzenie manualnych i automatycznych testów penetracyjnych aplikacji webowych, mobilnych, infrastruktury oraz systemów IT. Wykonywanie analiz bezpieczeństwa, skanów podatności oraz statycznej analizy kodu. Testowanie bezpieczeństwa interfejsów API, aplikacji mobilnych oraz środowisk kontenerowych. Opracowywanie raportów z testów wraz z rekomendacjami usunięcia wykrytych podatności. Wymagania Minimum 3 lata doświadczenia w obszarze testów penetracyjnych lub bezpieczeństwa ofensywnego. Znajomość technik ataków i standardów bezpieczeństwa, w szczególności OWASP, OWASP WSTG, OWASP MASVS, CVSS oraz MITRE ATT&CK. Praktyczna znajomość systemów operacyjnych, sieci komputerowych, protokołów sieciowych oraz narzędzi do analizy ruchu i testów penetracyjnych. Doświadczenie w testowaniu bezpieczeństwa aplikacji webowych, mobilnych, API oraz infrastruktury opartej o Active Directory, Exchange, rozwiązania chmurowe i systemy IAM (np. Keycloak). Znajomość relacyjnych i nierelacyjnych baz danych, podstaw kryptografii oraz technologii konteneryzacji (Docker, Kubernetes). Umiejętność analizy i deobfuskacji kodu, w tym obchodzenia mechanizmów SSL Pinning.

Technology

emagine Polska

Penetrationstester

Senior

On-site

Copenhagen, Denmark

🏢 Summary: Penetration tester role focused on conducting approximately 25 in-depth penetration tests of applications and networks within the public sector during 2026 (Q2–Q4). The assignment includes vulnerability analysis, retesting, and delivery of detailed technical reports in Danish. The consultant will test both legacy and modern technologies and present findings to stakeholders. 🗂️ Requirements: Proven experience with penetration testing in public sector environments, Strong knowledge of security research and vulnerability analysis, Experience performing application and network penetration tests, Ability to analyze complex systems and networks, Experience writing detailed technical security reports in Danish, Ability to communicate technical findings clearly, Experience with retesting and validation of vulnerabilities 📃 Skills: Penetrationtesting, Vulnerabilityanalysis, Securityresearch, Networksecurity, Applicationsecurity, OSCP, CEH, Scripting, Securityscanners, Reporting 🏢 Description: For en af vores kunder søger vi en dygtig Penetrationstester med erfaring inden for det statslige område til at udføre penetrationstests af diverse løsninger. 1.2 Beskrivelse af opgaven Formålet med gennemførelsen af pentests er at lave dybdegående afprøvning af sårbarheder, hvilke sammenholdes med de sårbarhedsscanninger, som kunden selv udfører løbende. Målet er at forsøge at bryde ind i en given applikation eller netværk, bl.a. gennem udnyttelsen af kendte sårbarheder og usikkert konfigurerede systemer. Der efterspørges en række pentests af applikationer, herunder flere højtprioriterede og gentests. Tests skal gennemføres i 2026 (Q2-Q4) efter en prioriteret rækkefølge aftalt mellem konsulenten og kunden. Opgavens omfang er i omegnen af 25 tests, og applikationerne spænder over både ældre og nyere teknologier. konsulenten skal derfor besidde en bred teknologisk viden og forståelse. Primære ansvarsområder Udførelse af pentests af høj kvalitet. Indsamling og analyse af sårbarheder. Dokumentation af fundne sårbarheder og deres alvorlighed. Udarbejdelse af teknisk, elektronisk rapport på dansk. Udførelse af mundtlig gennemgang af rapportens resultater. Gennemførelse af gentests af applikationer. Nøglekrav Solid erfaring med penetrationstests i det statslige område. Omfattende viden om sikkerhedsforskning og sårbarhedsanalyse. Evne til at kommunikere teknisk information klart og præcist. Erfaring med at udarbejde detaljerede tekniske rapporter. Færdigheder i at analysere komplekse systemer og netværk. Nice to Have Certificeringer inden for IT-sikkerhed (f.eks. OSCP, CEH). Kendskab til moderne programmeringssprog. Erfaring med automatiserede sikkerhedsscannere. Andre detaljer Testene er planlagt til 2026 og vil være delt over Q2 til Q4. Konsulenten vil modtage den nødvendige dokumentation og testbrugere for at udføre pentests effektivt.

Technology

BLUE energy Sp. z o.o.

Tester Penetracyjny Aplikacji Web

Mid

Hybrid

Poznan, Poland

10,000 - 14,000 PLN

🏢 Summary: Offer for a Web Application Penetration Tester responsible for conducting manual and automated security testing of web applications for external clients. The role focuses on identifying and exploiting vulnerabilities, preparing detailed security reports, and advising on remediation. It involves working with recognized security tools and methodologies to ensure high application security standards. 🗂️ Requirements: Experience in web application penetration testing, Knowledge of web security vulnerabilities (XSS, SQL Injection, CSRF, RCE), Ability to use penetration testing tools (Burp Suite, OWASP ZAP, Nmap, Metasploit), Ability to analyze application code for security flaws, Understanding of web application architecture, Knowledge of OWASP and PTES methodologies, Ability to prepare technical security reports, Relevant security certifications (e.g. CEH, OSCP, CISSP, GWAPT) 📃 Skills: BurpSuite, OWASPZAP, Nmap, Metasploit, XSS, SQLInjection, CSRF, RCE, JavaScript, PHP, Python, OWASP, PTES, CEH, OSCP, CISSP, GWAPT 🏢 Description: Jako firma konsultingowa specjalizująca się w bezpieczeństwie IT, poszukujemy Testera Penetracyjnego Aplikacji Web , który dołączy do naszego zespołu. Osoba na tym stanowisku będzie odpowiedzialna za realizację testów penetracyjnych aplikacji webowych w ramach projektów dla naszych zewnętrznych klientów. Będziesz pracować nad identyfikowaniem luk w zabezpieczeniach aplikacji, wspierając naszych klientów w zapewnianiu najwyższego poziomu bezpieczeństwa ich systemów. Zakres obowiązków: Realizacja testów penetracyjnych aplikacji webowych dla różnych klientów, w tym identyfikowanie i eksploatowanie luk w zabezpieczeniach Audytowanie aplikacji pod kątem zagrożeń takich jak XSS, SQL Injection, CSRF, RCE i innych typowych wektorów ataków Przeprowadzanie testów manualnych oraz automatycznych przy użyciu narzędzi takich jak Burp Suite, OWASP ZAP, Metasploit, itp. Przygotowywanie szczegółowych raportów z przeprowadzonych testów, w tym rekomendacji dotyczących poprawy zabezpieczeń Współpraca z zespołami deweloperskimi klientów, doradztwo w zakresie implementacji poprawek bezpieczeństwa Udział w analizach ryzyka i opracowywanie zaleceń dla klientów w zakresie bezpieczeństwa aplikacji webowych Wymagania: Doświadczenie w przeprowadzaniu testów penetracyjnych aplikacji webowych, w tym znajomość narzędzi i metod wykorzystywanych w tej dziedzinie (Burp Suite, OWASP ZAP, Nmap, Metasploit, itp.) Doskonała znajomość zagrożeń związanych z bezpieczeństwem aplikacji webowych (XSS, SQL Injection, CSRF, RCE, itp.) Umiejętność analizowania kodu aplikacji i identyfikowania potencjalnych luk w zabezpieczeniach Dobre rozumienie architektury aplikacji webowych i technologii wykorzystywanych w aplikacjach (JavaScript, PHP, Python, itp.) Umiejętności raportowania i przedstawiania wyników testów w sposób zrozumiały dla osób nietechnicznych (np. menedżerowie projektów, klienci) Certyfikaty z zakresu bezpieczeństwa (np. CEH, OSCP, CISSP, GWAPT) będą dodatkowym atutem Praktyczna znajomość metodologii testowania oraz standardów bezpieczeństwa (np. OWASP, PTES) Umiejętność pracy w zespole, komunikatywność oraz umiejętność pracy z klientami Oferujemy: Pracę nad interesującymi projektami z zakresu bezpieczeństwa aplikacji webowych dla klientów z różnych branż Atrakcyjne wynagrodzenie oraz pakiet benefitów (m. in. Multisport, ubezpieczenie i pakiet medyczny) Możliwość rozwoju zawodowego i certyfikacji w zakresie bezpieczeństwa IT Współpracę z zespołem ekspertów oraz wsparcie w realizacji wyzwań technicznych Elastyczne godziny pracy oraz możliwość pracy zdalnej lub hybrydowej Jeśli jesteś pasjonatem bezpieczeństwa aplikacji webowych i chcesz dołączyć do naszego zespołu, zapraszamy do aplikowania!

Technology

DataArt

Penetration Tester

Mid

Remote

Wroclaw, Poland

12,000 - 15,000 PLN

🏢 Summary: The offer is for a Middle Penetration Tester responsible for conducting network and application-level security assessments using automated and manual techniques. The role involves identifying and validating vulnerabilities, preparing detailed reports, collaborating with clients, and contributing to internal security tools and processes. The position focuses on strengthening security posture through structured testing methodologies and technical research. 🗂️ Requirements: Minimum 1 year of experience in vulnerability assessments and penetration testing, Minimum 3 years of experience in IT industry, Experience with Linux, Windows, Active Directory, JavaScript, .NET, SQL, Experience applying structured penetration testing methodologies, Understanding of web application vulnerabilities, Ability to document vulnerabilities and remediation steps, Experience with Burp Suite, Nessus, Metasploit, Nmap, sqlmap, Knowledge of programming or scripting for security tools development 📃 Skills: Burp, Nessus, Metasploit, Nmap, sqlmap, Linux, Windows, ActiveDirectory, JavaScript, .NET, SQL, Scripting 🏢 Description: Project overview A security-focused initiative aimed at performing vulnerability assessments and penetration tests for a variety of digital systems. The project supports continuous improvement of security practices and contributes to the development of internal tools and methodologies. The work includes research activities, process enhancement, and collaboration with technical teams to strengthen the overall security posture. Team You will join a security-oriented team that consists of penetration testers, security analysts, and engineers. The team collaborates closely, shares knowledge, and supports research and internal tool development. Position overview We are looking for a Middle Penetration Tester who will be involved in network and application-level security assessments. You will use automated tools and manual techniques to identify and verify security vulnerabilities. This role includes preparing assessment reports, interacting with clients to clarify scope and gather information, and contributing to the improvement of security processes and tools. Technology stack Burp Suite, Nessus, Metasploit, Nmap, sqlmap, Linux, Windows, Active Directory, JavaScript, .NET, SQL, scripting languages Responsibilities Conduct network and application-level security assessments Use automated tools and manual techniques to identify and validate vulnerabilities Prepare clear and comprehensive assessment reports with root cause details and remediation steps Communicate with clients to gather information, clarify scope, and discuss security controls Support internal security competence development through research, tool creation, and process improvement Collaborate with other team members across security and engineering domains Requirements One year of experience performing vulnerability assessments and penetration tests Three years of experience in the IT industry with familiarity across technologies such as Linux, Windows, Active Directory, JavaScript, .NET, SQL Experience applying structured methodology for vulnerability assessments and penetration tests Understanding of web application vulnerabilities Ability to describe and report vulnerabilities along with typical remediation activities Experience with open source and commercial security tools, including Burp Suite, Nessus, Metasploit, Nmap, and sqlmap Knowledge of programming or scripting for creating auxiliary security tools Ability to work effectively with customers and self-manage in challenging situations Nice to have Security certifications, including OSCP, CRTO, CPTS, eWPT, BSCP Strong programming experience in a modern language Experience with mobile application penetration testing Experience with reverse engineering and binary analysis Experience publishing technical content or speaking at industry events Familiarity with security standards, including PCI DSS and ISO 27000

Technology

TSS

Tester Bezpieczeństwa

Mid

Remote

Warsaw, Poland

80 - 95 PLN

🏢 Summary: Role focused on conducting comprehensive security testing of web applications, APIs, and IT infrastructure, including penetration testing and vulnerability assessments. The position involves identifying security risks, simulating real-world attacks, and providing remediation recommendations in close collaboration with development teams. It requires hands-on use of professional security tools and active participation in code reviews and technical consultations. 🗂️ Requirements: Minimum 3 years of commercial experience in security testing, Experience in penetration testing and vulnerability scanning, Practical experience in manual web application security testing, Experience in API security testing, Experience in network infrastructure security assessment, Proficiency with Burp Suite, OWASP ZAP, Wireshark, SQLMap, Ability to identify vulnerabilities and assess security risks, Experience collaborating with development teams and participating in code reviews, Fluent Polish, Working knowledge of English for technical documentation 📃 Skills: BurpSuite, OWASPZAP, Wireshark, SQLMap, PenetrationTesting, VulnerabilityScanning, WebSecurity, APITesting, Networking, Cybersecurity, OWASP, Cloud, Agile, Scrum 🏢 Description: W TSS napędzamy cyfrową rewolucję. Tworzymy zaawansowane systemy i innowacyjne rozwiązania z zakresu Software Development, FinTech, AI oraz Cybersecurity. Zakres odpowiedzialności: Testy bezpieczeństwa aplikacji webowych: Planowanie, przygotowywanie i realizacja manualnych testów bezpieczeństwa aplikacji webowych, identyfikacja podatności oraz analiza ryzyk bezpieczeństwa. Testowanie API: Przeprowadzanie testów bezpieczeństwa interfejsów API, weryfikacja mechanizmów uwierzytelniania, autoryzacji oraz odporności na najczęściej występujące zagrożenia. Testy infrastruktury sieciowej: Ocena bezpieczeństwa infrastruktury IT, usług sieciowych oraz konfiguracji systemów pod kątem potencjalnych podatności. Testy penetracyjne: Realizacja testów penetracyjnych systemów i aplikacji, symulowanie rzeczywistych scenariuszy ataków oraz analiza skuteczności wdrożonych zabezpieczeń. Skanowanie podatności: Wykorzystywanie specjalistycznych narzędzi do wykrywania luk bezpieczeństwa, analiza wyników oraz przygotowywanie rekomendacji naprawczych. Wykorzystanie narzędzi bezpieczeństwa: Codzienna praca z narzędziami takimi jak Burp Suite, OWASP ZAP, Wireshark, SQLMap oraz innymi rozwiązaniami wspierającymi proces testów bezpieczeństwa. Współpraca z zespołem deweloperskim: Aktywna współpraca z programistami, architektami i analitykami w zakresie identyfikacji oraz eliminacji zagrożeń bezpieczeństwa, udział w code review i konsultacjach technicznych. Raportowanie i rekomendacje: Przygotowywanie raportów z przeprowadzonych testów, dokumentowanie wykrytych podatności oraz rekomendowanie działań naprawczych i usprawnień. Wymagania: Doświadczenie komercyjne: Minimum 3 lata doświadczenia w obszarze testów bezpieczeństwa obejmujących testy penetracyjne, skanowanie podatności oraz symulacje ataków. Testy bezpieczeństwa aplikacji: Praktyczne doświadczenie w manualnym testowaniu bezpieczeństwa aplikacji webowych, API oraz infrastruktury sieciowej. Narzędzia bezpieczeństwa: Bardzo dobra znajomość narzędzi takich jak Burp Suite , OWASP ZAP, Wireshark, SQLMap oraz innych rozwiązań wykorzystywanych w testach bezpieczeństwa. Znajomość zagadnień cyberbezpieczeństwa: Umiejętność identyfikowania podatności, analizowania ryzyk bezpieczeństwa oraz proponowania skutecznych działań naprawczych. Komunikacja i współpraca: Wysoko rozwinięte umiejętności komunikacyjne oraz doświadczenie we współpracy z zespołami deweloperskimi, w tym udział w code review i konsultacjach technicznych. Znajomość języków: Biegłe posługiwanie się językiem polskim w mowie i piśmie oraz znajomość języka angielskiego umożliwiająca efektywną pracę z dokumentacją techniczną. Dodatkowym atutem będzie: Znajomość standardów i metodyk bezpieczeństwa, w szczególności OWASP Top 10. Doświadczenie w testowaniu środowisk chmurowych oraz nowoczesnych architektur aplikacyjnych. Posiadanie certyfikatów branżowych związanych z bezpieczeństwem, np. eJPT, PNPT, OSCP, CEH lub pokrewnych. Doświadczenie w pracy w środowiskach Agile/Scrum. Otwartość na dzielenie się wiedzą oraz aktywne wspieranie rozwoju zespołu. Co zyskujesz, dołączając do teamu? Stabilność i elastyczność: Długofalową współpracę w oparciu o kontrakt B2B. Realny wpływ: Pracę nad kluczowymi projektami, gdzie Twoje rekomendacje i działania realnie wpływają na poziom bezpieczeństwa tworzonych rozwiązań. Zdrowie pod kontrolą: Dofinansowanie do prywatnej opieki medycznej w PZU. Stały rozwój: Dostęp do wewnętrznych, specjalistycznych szkoleń z zakresu m.in . cyberbezpieczeństwa. Środowisko entuzjastów: Pracę w zespole, gdzie pasja łączy się z profesjonalizmem, a dobra atmosfera to standard, nie benefit.

Technology

emagine Polska

Penetration Tester (m/w/d)

Senior

Remote

Berlin, Germany

🏢 Summary: Experienced Penetration Tester responsible for planning, executing, and reporting comprehensive penetration tests across network, web, wireless, Active Directory, and physical environments. The role includes realistic attack simulations, compliance assessments, and deriving concrete security improvement measures within a large public IT environment. Engagement is long-term and primarily remote within Germany. 🗂️ Requirements: Completed degree in Computer Science or recognized technical IT training, Minimum 3 years experience in IT security, At least 2 years hands-on experience in penetration testing or red teaming, Experience in at least 2 large-scale projects (>250 users), Proven experience in web, network or cloud penetration testing, Ability to conduct independent security assessments and exploit development, Good German language skills (written and spoken) 📃 Skills: PenetrationTesting, RedTeaming, NetworkSecurity, WebSecurity, WLAN, ActiveDirectory, CloudSecurity, BurpSuite, Nmap, Metasploit, CobaltStrike, Nessus, OpenVAS, sqlmap, Python, PowerShell, Jira, Confluence, SharePoint, OSCP, GPEN, CEH, eJPT, CREST, CISSP, CISM 🏢 Description: Für das Projekt wird ein erfahrener Penetration Tester (m/w/d) gesucht, der umfassende Penetration Tests plant, vorbereitet, durchführt und nachbereitet. Die Rolle umfasst sowohl technische Sicherheitsanalysen als auch die Ableitung konkreter Maßnahmen zur Erhöhung der IT-Sicherheit. Der Einsatz findet im Umfeld eines großen öffentlichen IT-Dienstleisters statt. Deine Aufgaben: Vor- und Nachbereitung sowie Durchführung abgestimmter Penetration Tests, u. a.: Network Penetration Testing WLAN Penetration Testing Web Application Penetration Testing Active Directory Penetration Testing Physical Penetration Testing Ermittlung bekannter und unbekannter Sicherheitslücken in IT-Systemen und Anwendungen Analyse der Sicherheitslage der IT-Infrastruktur sowie Prüfung der Compliance-Vorgaben (z. B. DSGVO, BSI-Grundschutz, NIS-Richtlinie) Durchführung realitätsnaher Angriffssimulationen zur Risikobewertung Ableitung von Maßnahmen zur Verbesserung der IT-Sicherheit und Präsentation der Ergebnisse Sicherstellung, dass alle Aktivitäten transparent, nachvollziehbar und rechtskonform erfolgen Dein Profil: Abgeschlossenes Informatik-Studium oder eine anerkannte technische Berufsausbildung (z. B. Fachinformatiker) Mindestens 3 Jahre praktische Erfahrung im Bereich IT-Sicherheit, davon mindestens 2 Jahre in Penetration Tests bzw. Red-Team-Übungen Beteiligung an mindestens 2 größeren Projekten (Unternehmen / Behörde mit >250 Mitarbeitenden), z. B. Web-App-Pentests, Netzwerk-Pentests, Cloud-Pentests Gute Deutschkenntnisse in Wort und Schrift Zuschlagskriterien: Umfangreiche Erfahrung in Pen-Tests / Red-Team Mehrere Referenzprojekte Zertifizierungen wie OSCP, GPEN, CEH, eJPT, CREST, CISSP/CISM Erfahrung mit Werkzeugen wie Burp Suite, Nmap, Metasploit, Cobalt Strike, Nessus/OpenVAS, sqlmap, etc. Fähig, eigene Exploits / PoCs zu entwickeln (Python, PowerShell) Erfahrung mit Jira, Confluence, SharePoint Andere Details: Zeitraum: Rahmenvereinbarung bis 2030 Arbeitsort: Remote/Deutschland Bei Interesse freue ich mich auf Deine Bewerbungsunterlagen , Verfügbarkeit und Stundensätze an tamara.petrovic.turkovic@emagine.de

Technology

emagine Polska

Penetration Tester (m/w/d)

Senior

Remote

Berlin, BE, Germany

🏢 Summary: Experienced Penetration Tester responsible for planning, executing, and reporting comprehensive penetration tests across network, web, wireless, Active Directory, and physical environments for a public sector IT project. The role includes identifying vulnerabilities, performing realistic attack simulations, assessing compliance, and deriving concrete security improvements. Engagement is long-term and primarily remote within Germany. 🗂️ Requirements: Degree in ComputerScience or completed technical IT training, Minimum 3 years experience in ITSecurity, At least 2 years hands-on PenetrationTesting or RedTeam, Experience in minimum 2 large-scale projects over 250 users, Proven experience in WebApp Pentests Network Pentests or Cloud Pentests, Ability to develop own exploits or PoCs, Knowledge of compliance standards DSGVO BSI NIS, Fluent German language skills 📃 Skills: PenetrationTesting, RedTeam, NetworkSecurity, WLAN, WebSecurity, ActiveDirectory, Python, PowerShell, BurpSuite, Nmap, Metasploit, CobaltStrike, Nessus, OpenVAS, sqlmap, OSCP, GPEN, CEH, eJPT, CREST, CISSP, CISM, Jira, Confluence, SharePoint 🏢 Description: Für das Projekt wird ein erfahrener Penetration Tester (m/w/d) gesucht, der umfassende Penetration Tests plant, vorbereitet, durchführt und nachbereitet. Die Rolle umfasst sowohl technische Sicherheitsanalysen als auch die Ableitung konkreter Maßnahmen zur Erhöhung der IT-Sicherheit. Der Einsatz findet im Umfeld eines großen öffentlichen IT-Dienstleisters statt. Deine Aufgaben: Vor- und Nachbereitung sowie Durchführung abgestimmter Penetration Tests, u. a.: Network Penetration Testing WLAN Penetration Testing Web Application Penetration Testing Active Directory Penetration Testing Physical Penetration Testing Ermittlung bekannter und unbekannter Sicherheitslücken in IT-Systemen und Anwendungen Analyse der Sicherheitslage der IT-Infrastruktur sowie Prüfung der Compliance-Vorgaben (z. B. DSGVO, BSI-Grundschutz, NIS-Richtlinie) Durchführung realitätsnaher Angriffssimulationen zur Risikobewertung Ableitung von Maßnahmen zur Verbesserung der IT-Sicherheit und Präsentation der Ergebnisse Sicherstellung, dass alle Aktivitäten transparent, nachvollziehbar und rechtskonform erfolgen Dein Profil: Abgeschlossenes Informatik-Studium oder eine anerkannte technische Berufsausbildung (z. B. Fachinformatiker) Mindestens 3 Jahre praktische Erfahrung im Bereich IT-Sicherheit, davon mindestens 2 Jahre in Penetration Tests bzw. Red-Team-Übungen Beteiligung an mindestens 2 größeren Projekten (Unternehmen / Behörde mit >250 Mitarbeitenden), z. B. Web-App-Pentests, Netzwerk-Pentests, Cloud-Pentests Gute Deutschkenntnisse in Wort und Schrift Zuschlagskriterien: Umfangreiche Erfahrung in Pen-Tests / Red-Team Mehrere Referenzprojekte Zertifizierungen wie OSCP, GPEN, CEH, eJPT, CREST, CISSP/CISM Erfahrung mit Werkzeugen wie Burp Suite, Nmap, Metasploit, Cobalt Strike, Nessus/OpenVAS, sqlmap, etc. Fähig, eigene Exploits / PoCs zu entwickeln (Python, PowerShell) Erfahrung mit Jira, Confluence, SharePoint Andere Details: Zeitraum: Rahmenvereinbarung bis 2030 Arbeitsort: Remote/Deutschland Bei Interesse freue ich mich auf Deine Bewerbungsunterlagen , Verfügbarkeit und Stundensätze an tamara.petrovic.turkovic@emagine.de

Technology

Experis Manpower Group

API Pentester

Senior

Remote

Wroclaw, Poland

170 - 180 PLN

🏢 Summary: Hands-on senior offensive security role leading penetration testing engagements across web, network, mobile, cloud, and Active Directory environments. The position combines technical delivery, client interaction, reporting, and mentoring responsibilities within consulting-style engagements. Candidates are expected to have advanced penetration testing experience, scripting skills, and recognized offensive security certifications. 🗂️ Requirements: 5+ years of hands-on penetration testing or offensive security experience, Experience in consulting or client-facing security engagements, Expertise in at least three areas: web, network, mobile, or Active Directory security testing, Experience with offensive security and penetration testing tools, Scripting skills in Python, PowerShell, or Bash, Strong communication and technical reporting skills, At least one certification: OSCP, CREST CRT/CPSA, CRTP, or CRTO 📃 Skills: BurpSuite, Nmap, Metasploit, BloodHound, Impacket, CobaltStrike, Nessus, OpenVAS, Frida, MobSF, Python, PowerShell, Bash, AWS, Azure, GCP, Kubernetes 🏢 Description: Join our Offensive Security team and lead penetration testing engagements for clients across financial services, technology, healthcare, government, and critical infrastructure sectors. This is a hands-on role for an experienced security professional who wants to remain highly technical while taking ownership of project delivery, client relationships, and mentoring junior consultants. Key Responsibilities: Lead and perform penetration tests across web applications, APIs, internal/external networks, mobile applications, cloud environments, and Active Directory. Conduct advanced Active Directory security assessments and infrastructure testing. Develop custom scripts, tooling, and proof-of-concept exploits. Manage engagements from scoping to reporting and remediation validation. Present findings to technical and business stakeholders. Support proposal development, effort estimation, and pre-sales activities. Mentor junior team members and contribute to internal methodologies and best practices. Required Experience: 5+ years of hands-on penetration testing or offensive security experience, ideally within a consulting environment. Strong expertise in at least three of the following: web, network, mobile, or Active Directory security testing. Experience with tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Cobalt Strike (or similar), Nessus/OpenVAS, Frida, and MobSF. Scripting skills in Python, PowerShell, or Bash. Strong communication, reporting, and client-facing skills. Certifications: At least one of: OSCP CREST CRT/CPSA CRTP or CRTO Nice to Have: Big 4 or cybersecurity consultancy experience. Cloud security testing (AWS, Azure, GCP). Kubernetes/container security knowledge. Security research, CVEs, conference talks, or CTF achievements. Offer: Multisport Card Life insurance Private healthcare PowerYou platform

Technology

emagine Polska

Tester AI

Mid

Remote

Warsaw, Poland

160 - 170 PLN/hr

🏢 Summary: Hybrid/remote B2B contract role for an AI Tester focused on automation and functional testing within CRM systems, primarily using TOSCA. The role centers on designing and maintaining automation frameworks, executing regression tests, and ensuring high-quality delivery through AI-driven testing methodologies in a global environment. 🗂️ Requirements: 4-6 years of hands-on experience with TOSCA or similar automation tools, Experience in automation testing of web and desktop applications, Experience in functional testing of CRM applications, Ability to design and implement automation frameworks, Experience creating and maintaining automated test cases with documentation, Experience with test management tools such as JIRA or Azure DevOps, Knowledge of regression testing, SIT, and UAT processes 📃 Skills: TOSCA, CRM, Automation, Testing, Regression, SIT, UAT, JIRA, Azure, DevOps, AI, Prompting 🏢 Description: Working mode : Hybrid or remote with occasional visits Contract: B2B Rate: 160-170PLN/h Summary: The Tester AI role focuses on automation testing with tools like TOSCA , alongside functional testing within CRM systems . The primary objective is to ensure high-quality software delivery through effective automation and collaborative efforts in a global team. Responsibilities: Design, develop, and maintain automation test cases using an automation tool such as TOSCA. Conduct functional regression testing and execute test cases. Utilize prompt engineering and AI testing methodologies . Create systems that support highly available and scalable automation test components. Implement solutions that meet both functional and non-functional requirements. Foster collaboration and professionalism within the team and adopt best practices. Communicate risks and issues to Program Management and proactively address impediments. Identify and innovate to eliminate process inefficiencies. Collaborate with global teams across regions. Manage defect control processes and ensure quality through System Integration Testing (SIT), User Acceptance Testing (UAT), and production delivery. Key Requirements: 4-6 years of hands-on experience with TOSCA or similar automation tools for web and desktop applications. Experience in both automation and functional testing of CRM applications. Proven ability to design and implement automation frameworks. Experience in creating and maintaining automated test cases with proper documentation. Familiarity with test management tools like JIRA or Azure DevOps. Nice to Have: Functional understanding of Investment Banking and Risk Management. Experience working in an agile/scrum environment. Ability to estimate testing efforts for new functionalities, including regression tests.

Technology

B2Bnetwork

Senior Test Automation Engineer (.NET / Java)

Senior

Hybrid

Gdansk, Poland

100 - 120 PLN

🏢 Summary: Leadership role responsible for defining and implementing test automation strategy, designing scalable UI and API automation frameworks, and integrating automated tests into CI/CD pipelines. The position focuses on improving test coverage, reliability, and quality gates while mentoring the team and ensuring best practices in automation architecture. 🗂️ Requirements: 4–5 years experience in UI and API test automation (REST, SOAP), 4–5 years programming experience in .NET or Java, Hands-on experience with Playwright or Selenium, Experience designing and maintaining test automation frameworks, Experience with SQL and data validation for automated tests, Experience integrating automated tests with CI/CD pipelines, Experience with Git-based version control systems, Experience working with Jira in Agile environment, Very good English proficiency 📃 Skills: .NET, Java, Playwright, Selenium, REST, SOAP, SQL, CI/CD, Bamboo, Jenkins, Azure, Git, Bitbucket, GitHub, GitLab, Jira 🏢 Description: Główne obowiązki Prowadzenie, wspieranie i mentoring zespołu w zakresie najlepszych praktyk automatyzacji testów. Definiowanie oraz rozwijanie strategii automatyzacji testów dla zespołu, w tym roadmapy, narzędzi, architektury frameworków testowych oraz bramek jakościowych (quality gates). Projektowanie, implementacja, utrzymanie i ciągłe doskonalenie skalowalnych frameworków automatyzacji testów dla testów UI i API. Współpraca z ekspertami biznesowymi i funkcjonalnymi (SME) przy definiowaniu podejścia do jakości, kryteriów akceptacji oraz zakresu pokrycia testami opartego na analizie ryzyka. Integracja testów automatycznych z pipeline'ami CI/CD oraz ścisła współpraca z zespołami deweloperskimi i infrastrukturalnymi. Analiza możliwości automatyzacji oraz rekomendowanie odpowiedniego poziomu automatyzacji dla poszczególnych funkcjonalności. Zwiększanie pokrycia testami, poprawa szybkości wykonywania testów, niezawodności oraz diagnostyki błędów w duchu ciągłego doskonalenia. Zapewnienie prawidłowego zarządzania danymi testowymi, środowiskami testowymi oraz przepływami integracyjnymi pomiędzy systemami. Efektywna współpraca w międzynarodowym, rozproszonym środowisku oraz aktywny udział w społecznościach QA i automatyzacji testów. Wymagania obowiązkowe Minimum 4–5 lat praktycznego doświadczenia w automatyzacji testów (UI oraz API – REST/SOAP). Minimum 4–5 lat doświadczenia w programowaniu w .NET (preferowane) lub Java . Praktyczna znajomość narzędzi Playwright lub Selenium . Bardzo dobra znajomość projektowania frameworków automatyzacji testów oraz wzorców architektonicznych zapewniających łatwość utrzymania kodu. Doświadczenie w pracy z SQL oraz walidacją danych na potrzeby testów automatycznych. Doświadczenie w integracji testów z procesami CI/CD (np. Bamboo, Jenkins, Azure DevOps lub podobne). Doświadczenie w pracy z systemami kontroli wersji opartymi o Git (Bitbucket, GitHub, GitLab). Doświadczenie w pracy z Jira w środowisku Agile. Rozwinięte umiejętności liderskie, mentoringowe, komunikacyjne oraz analitycznego rozwiązywania problemów. Samodzielność, proaktywność i umiejętność efektywnej organizacji pracy. Bardzo dobra znajomość języka angielskiego w mowie i piśmie. Mile widziane Doświadczenie w branży bankowej lub finansowej. Znajomość systemu Temenos T24 . Doświadczenie w pracy w dużych, rozproszonych środowiskach korporacyjnych. Praktyczne doświadczenie w wykorzystaniu narzędzi wspieranych przez AI (GitHub Copilot, ChatGPT, Claude itp.) do generowania testów, refaktoryzacji kodu i tworzenia dokumentacji. Znajomość technik automatyzacji testów opartych o modele językowe (LLM), np. generowanie lokatorów, danych testowych czy asercji na podstawie wymagań.