May 3, 2026

Penetration Tester

Mid • Remote

12,000 - 15,000 PLN

Wroclaw, Poland

Project overview

A security-focused initiative aimed at performing vulnerability assessments and penetration tests for a variety of digital systems. The project supports continuous improvement of security practices and contributes to the development of internal tools and methodologies. The work includes research activities, process enhancement, and collaboration with technical teams to strengthen the overall security posture.

Team

You will join a security-oriented team that consists of penetration testers, security analysts, and engineers. The team collaborates closely, shares knowledge, and supports research and internal tool development.

Position overview

We are looking for a Middle Penetration Tester who will be involved in network and application-level security assessments. You will use automated tools and manual techniques to identify and verify security vulnerabilities. This role includes preparing assessment reports, interacting with clients to clarify scope and gather information, and contributing to the improvement of security processes and tools.

Technology stack

Burp Suite, Nessus, Metasploit, Nmap, sqlmap, Linux, Windows, Active Directory, JavaScript, .NET, SQL, scripting languages

Responsibilities

  • Conduct network and application-level security assessments

  • Use automated tools and manual techniques to identify and validate vulnerabilities

  • Prepare clear and comprehensive assessment reports with root cause details and remediation steps

  • Communicate with clients to gather information, clarify scope, and discuss security controls

  • Support internal security competence development through research, tool creation, and process improvement

  • Collaborate with other team members across security and engineering domains

Requirements

  • One year of experience performing vulnerability assessments and penetration tests

  • Three years of experience in the IT industry with familiarity across technologies such as Linux, Windows, Active Directory, JavaScript, .NET, SQL

  • Experience applying structured methodology for vulnerability assessments and penetration tests

  • Understanding of web application vulnerabilities

  • Ability to describe and report vulnerabilities along with typical remediation activities

  • Experience with open source and commercial security tools, including Burp Suite, Nessus, Metasploit, Nmap, and sqlmap

  • Knowledge of programming or scripting for creating auxiliary security tools

  • Ability to work effectively with customers and self-manage in challenging situations

Nice to have

  • Security certifications, including OSCP, CRTO, CPTS, eWPT, BSCP

  • Strong programming experience in a modern language

  • Experience with mobile application penetration testing

  • Experience with reverse engineering and binary analysis

  • Experience publishing technical content or speaking at industry events

  • Familiarity with security standards, including PCI DSS and ISO 27000

 

Similar jobs you might like

Technology

BLUE energy Sp. z o.o.

Tester Penetracyjny Aplikacji Web

Mid

Hybrid

Poznan, Poland

10,000 - 14,000 PLN

🏢 Summary: Offer for a Web Application Penetration Tester responsible for conducting manual and automated security testing of web applications for external clients. The role focuses on identifying and exploiting vulnerabilities, preparing detailed security reports, and advising on remediation. It involves working with recognized security tools and methodologies to ensure high application security standards. 🗂️ Requirements: Experience in web application penetration testing, Knowledge of web security vulnerabilities (XSS, SQL Injection, CSRF, RCE), Ability to use penetration testing tools (Burp Suite, OWASP ZAP, Nmap, Metasploit), Ability to analyze application code for security flaws, Understanding of web application architecture, Knowledge of OWASP and PTES methodologies, Ability to prepare technical security reports, Relevant security certifications (e.g. CEH, OSCP, CISSP, GWAPT) 📃 Skills: BurpSuite, OWASPZAP, Nmap, Metasploit, XSS, SQLInjection, CSRF, RCE, JavaScript, PHP, Python, OWASP, PTES, CEH, OSCP, CISSP, GWAPT 🏢 Description: Jako firma konsultingowa specjalizująca się w bezpieczeństwie IT, poszukujemy Testera Penetracyjnego Aplikacji Web , który dołączy do naszego zespołu. Osoba na tym stanowisku będzie odpowiedzialna za realizację testów penetracyjnych aplikacji webowych w ramach projektów dla naszych zewnętrznych klientów. Będziesz pracować nad identyfikowaniem luk w zabezpieczeniach aplikacji, wspierając naszych klientów w zapewnianiu najwyższego poziomu bezpieczeństwa ich systemów. Zakres obowiązków: Realizacja testów penetracyjnych aplikacji webowych dla różnych klientów, w tym identyfikowanie i eksploatowanie luk w zabezpieczeniach Audytowanie aplikacji pod kątem zagrożeń takich jak XSS, SQL Injection, CSRF, RCE i innych typowych wektorów ataków Przeprowadzanie testów manualnych oraz automatycznych przy użyciu narzędzi takich jak Burp Suite, OWASP ZAP, Metasploit, itp. Przygotowywanie szczegółowych raportów z przeprowadzonych testów, w tym rekomendacji dotyczących poprawy zabezpieczeń Współpraca z zespołami deweloperskimi klientów, doradztwo w zakresie implementacji poprawek bezpieczeństwa Udział w analizach ryzyka i opracowywanie zaleceń dla klientów w zakresie bezpieczeństwa aplikacji webowych Wymagania: Doświadczenie w przeprowadzaniu testów penetracyjnych aplikacji webowych, w tym znajomość narzędzi i metod wykorzystywanych w tej dziedzinie (Burp Suite, OWASP ZAP, Nmap, Metasploit, itp.) Doskonała znajomość zagrożeń związanych z bezpieczeństwem aplikacji webowych (XSS, SQL Injection, CSRF, RCE, itp.) Umiejętność analizowania kodu aplikacji i identyfikowania potencjalnych luk w zabezpieczeniach Dobre rozumienie architektury aplikacji webowych i technologii wykorzystywanych w aplikacjach (JavaScript, PHP, Python, itp.) Umiejętności raportowania i przedstawiania wyników testów w sposób zrozumiały dla osób nietechnicznych (np. menedżerowie projektów, klienci) Certyfikaty z zakresu bezpieczeństwa (np. CEH, OSCP, CISSP, GWAPT) będą dodatkowym atutem Praktyczna znajomość metodologii testowania oraz standardów bezpieczeństwa (np. OWASP, PTES) Umiejętność pracy w zespole, komunikatywność oraz umiejętność pracy z klientami Oferujemy: Pracę nad interesującymi projektami z zakresu bezpieczeństwa aplikacji webowych dla klientów z różnych branż Atrakcyjne wynagrodzenie oraz pakiet benefitów (m. in. Multisport, ubezpieczenie i pakiet medyczny) Możliwość rozwoju zawodowego i certyfikacji w zakresie bezpieczeństwa IT Współpracę z zespołem ekspertów oraz wsparcie w realizacji wyzwań technicznych Elastyczne godziny pracy oraz możliwość pracy zdalnej lub hybrydowej Jeśli jesteś pasjonatem bezpieczeństwa aplikacji webowych i chcesz dołączyć do naszego zespołu, zapraszamy do aplikowania!

Technology

Experis Manpower Group

API Pentester

Senior

Remote

Wroclaw, Poland

170 - 180 PLN

🏢 Summary: Hands-on senior offensive security role leading penetration testing engagements across web, network, mobile, cloud, and Active Directory environments. The position combines technical delivery, client interaction, reporting, and mentoring responsibilities within consulting-style engagements. Candidates are expected to have advanced penetration testing experience, scripting skills, and recognized offensive security certifications. 🗂️ Requirements: 5+ years of hands-on penetration testing or offensive security experience, Experience in consulting or client-facing security engagements, Expertise in at least three areas: web, network, mobile, or Active Directory security testing, Experience with offensive security and penetration testing tools, Scripting skills in Python, PowerShell, or Bash, Strong communication and technical reporting skills, At least one certification: OSCP, CREST CRT/CPSA, CRTP, or CRTO 📃 Skills: BurpSuite, Nmap, Metasploit, BloodHound, Impacket, CobaltStrike, Nessus, OpenVAS, Frida, MobSF, Python, PowerShell, Bash, AWS, Azure, GCP, Kubernetes 🏢 Description: Join our Offensive Security team and lead penetration testing engagements for clients across financial services, technology, healthcare, government, and critical infrastructure sectors. This is a hands-on role for an experienced security professional who wants to remain highly technical while taking ownership of project delivery, client relationships, and mentoring junior consultants. Key Responsibilities: Lead and perform penetration tests across web applications, APIs, internal/external networks, mobile applications, cloud environments, and Active Directory. Conduct advanced Active Directory security assessments and infrastructure testing. Develop custom scripts, tooling, and proof-of-concept exploits. Manage engagements from scoping to reporting and remediation validation. Present findings to technical and business stakeholders. Support proposal development, effort estimation, and pre-sales activities. Mentor junior team members and contribute to internal methodologies and best practices. Required Experience: 5+ years of hands-on penetration testing or offensive security experience, ideally within a consulting environment. Strong expertise in at least three of the following: web, network, mobile, or Active Directory security testing. Experience with tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Cobalt Strike (or similar), Nessus/OpenVAS, Frida, and MobSF. Scripting skills in Python, PowerShell, or Bash. Strong communication, reporting, and client-facing skills. Certifications: At least one of: OSCP CREST CRT/CPSA CRTP or CRTO Nice to Have: Big 4 or cybersecurity consultancy experience. Cloud security testing (AWS, Azure, GCP). Kubernetes/container security knowledge. Security research, CVEs, conference talks, or CTF achievements. Offer: Multisport Card Life insurance Private healthcare PowerYou platform

Technology

emagine Polska

Penetration Tester (m/w/d)

Senior

Remote

Berlin, Germany

🏢 Summary: Experienced Penetration Tester responsible for planning, executing, and reporting comprehensive penetration tests across network, web, wireless, Active Directory, and physical environments. The role includes realistic attack simulations, compliance assessments, and deriving concrete security improvement measures within a large public IT environment. Engagement is long-term and primarily remote within Germany. 🗂️ Requirements: Completed degree in Computer Science or recognized technical IT training, Minimum 3 years experience in IT security, At least 2 years hands-on experience in penetration testing or red teaming, Experience in at least 2 large-scale projects (>250 users), Proven experience in web, network or cloud penetration testing, Ability to conduct independent security assessments and exploit development, Good German language skills (written and spoken) 📃 Skills: PenetrationTesting, RedTeaming, NetworkSecurity, WebSecurity, WLAN, ActiveDirectory, CloudSecurity, BurpSuite, Nmap, Metasploit, CobaltStrike, Nessus, OpenVAS, sqlmap, Python, PowerShell, Jira, Confluence, SharePoint, OSCP, GPEN, CEH, eJPT, CREST, CISSP, CISM 🏢 Description: Für das Projekt wird ein erfahrener Penetration Tester (m/w/d) gesucht, der umfassende Penetration Tests plant, vorbereitet, durchführt und nachbereitet. Die Rolle umfasst sowohl technische Sicherheitsanalysen als auch die Ableitung konkreter Maßnahmen zur Erhöhung der IT-Sicherheit. Der Einsatz findet im Umfeld eines großen öffentlichen IT-Dienstleisters statt. Deine Aufgaben: Vor- und Nachbereitung sowie Durchführung abgestimmter Penetration Tests, u. a.: Network Penetration Testing WLAN Penetration Testing Web Application Penetration Testing Active Directory Penetration Testing Physical Penetration Testing Ermittlung bekannter und unbekannter Sicherheitslücken in IT-Systemen und Anwendungen Analyse der Sicherheitslage der IT-Infrastruktur sowie Prüfung der Compliance-Vorgaben (z. B. DSGVO, BSI-Grundschutz, NIS-Richtlinie) Durchführung realitätsnaher Angriffssimulationen zur Risikobewertung Ableitung von Maßnahmen zur Verbesserung der IT-Sicherheit und Präsentation der Ergebnisse Sicherstellung, dass alle Aktivitäten transparent, nachvollziehbar und rechtskonform erfolgen Dein Profil: Abgeschlossenes Informatik-Studium oder eine anerkannte technische Berufsausbildung (z. B. Fachinformatiker) Mindestens 3 Jahre praktische Erfahrung im Bereich IT-Sicherheit, davon mindestens 2 Jahre in Penetration Tests bzw. Red-Team-Übungen Beteiligung an mindestens 2 größeren Projekten (Unternehmen / Behörde mit >250 Mitarbeitenden), z. B. Web-App-Pentests, Netzwerk-Pentests, Cloud-Pentests Gute Deutschkenntnisse in Wort und Schrift Zuschlagskriterien: Umfangreiche Erfahrung in Pen-Tests / Red-Team Mehrere Referenzprojekte Zertifizierungen wie OSCP, GPEN, CEH, eJPT, CREST, CISSP/CISM Erfahrung mit Werkzeugen wie Burp Suite, Nmap, Metasploit, Cobalt Strike, Nessus/OpenVAS, sqlmap, etc. Fähig, eigene Exploits / PoCs zu entwickeln (Python, PowerShell) Erfahrung mit Jira, Confluence, SharePoint Andere Details: Zeitraum: Rahmenvereinbarung bis 2030 Arbeitsort: Remote/Deutschland Bei Interesse freue ich mich auf Deine Bewerbungsunterlagen , Verfügbarkeit und Stundensätze an tamara.petrovic.turkovic@emagine.de

Technology

emagine Polska

Penetration Tester (m/w/d)

Senior

Remote

Berlin, BE, Germany

🏢 Summary: Experienced Penetration Tester responsible for planning, executing, and reporting comprehensive penetration tests across network, web, wireless, Active Directory, and physical environments for a public sector IT project. The role includes identifying vulnerabilities, performing realistic attack simulations, assessing compliance, and deriving concrete security improvements. Engagement is long-term and primarily remote within Germany. 🗂️ Requirements: Degree in ComputerScience or completed technical IT training, Minimum 3 years experience in ITSecurity, At least 2 years hands-on PenetrationTesting or RedTeam, Experience in minimum 2 large-scale projects over 250 users, Proven experience in WebApp Pentests Network Pentests or Cloud Pentests, Ability to develop own exploits or PoCs, Knowledge of compliance standards DSGVO BSI NIS, Fluent German language skills 📃 Skills: PenetrationTesting, RedTeam, NetworkSecurity, WLAN, WebSecurity, ActiveDirectory, Python, PowerShell, BurpSuite, Nmap, Metasploit, CobaltStrike, Nessus, OpenVAS, sqlmap, OSCP, GPEN, CEH, eJPT, CREST, CISSP, CISM, Jira, Confluence, SharePoint 🏢 Description: Für das Projekt wird ein erfahrener Penetration Tester (m/w/d) gesucht, der umfassende Penetration Tests plant, vorbereitet, durchführt und nachbereitet. Die Rolle umfasst sowohl technische Sicherheitsanalysen als auch die Ableitung konkreter Maßnahmen zur Erhöhung der IT-Sicherheit. Der Einsatz findet im Umfeld eines großen öffentlichen IT-Dienstleisters statt. Deine Aufgaben: Vor- und Nachbereitung sowie Durchführung abgestimmter Penetration Tests, u. a.: Network Penetration Testing WLAN Penetration Testing Web Application Penetration Testing Active Directory Penetration Testing Physical Penetration Testing Ermittlung bekannter und unbekannter Sicherheitslücken in IT-Systemen und Anwendungen Analyse der Sicherheitslage der IT-Infrastruktur sowie Prüfung der Compliance-Vorgaben (z. B. DSGVO, BSI-Grundschutz, NIS-Richtlinie) Durchführung realitätsnaher Angriffssimulationen zur Risikobewertung Ableitung von Maßnahmen zur Verbesserung der IT-Sicherheit und Präsentation der Ergebnisse Sicherstellung, dass alle Aktivitäten transparent, nachvollziehbar und rechtskonform erfolgen Dein Profil: Abgeschlossenes Informatik-Studium oder eine anerkannte technische Berufsausbildung (z. B. Fachinformatiker) Mindestens 3 Jahre praktische Erfahrung im Bereich IT-Sicherheit, davon mindestens 2 Jahre in Penetration Tests bzw. Red-Team-Übungen Beteiligung an mindestens 2 größeren Projekten (Unternehmen / Behörde mit >250 Mitarbeitenden), z. B. Web-App-Pentests, Netzwerk-Pentests, Cloud-Pentests Gute Deutschkenntnisse in Wort und Schrift Zuschlagskriterien: Umfangreiche Erfahrung in Pen-Tests / Red-Team Mehrere Referenzprojekte Zertifizierungen wie OSCP, GPEN, CEH, eJPT, CREST, CISSP/CISM Erfahrung mit Werkzeugen wie Burp Suite, Nmap, Metasploit, Cobalt Strike, Nessus/OpenVAS, sqlmap, etc. Fähig, eigene Exploits / PoCs zu entwickeln (Python, PowerShell) Erfahrung mit Jira, Confluence, SharePoint Andere Details: Zeitraum: Rahmenvereinbarung bis 2030 Arbeitsort: Remote/Deutschland Bei Interesse freue ich mich auf Deine Bewerbungsunterlagen , Verfügbarkeit und Stundensätze an tamara.petrovic.turkovic@emagine.de

Technology

Ness Solution

Tester Penetracyjny

Mid

Remote

Warsaw, Poland

90 - 100 PLN

🏢 Summary: Oferta dotyczy prowadzenia manualnych i automatycznych testów penetracyjnych aplikacji webowych, mobilnych, API oraz infrastruktury IT wraz z analizą podatności i raportowaniem rekomendacji bezpieczeństwa. Rola obejmuje także analizę kodu, testowanie środowisk kontenerowych oraz pracę z systemami IAM i rozwiązaniami chmurowymi. 🗂️ Requirements: Minimum 3 lata doświadczenia w testach penetracyjnych lub bezpieczeństwie ofensywnym, Znajomość OWASP, Znajomość OWASP WSTG, Znajomość OWASP MASVS, Znajomość CVSS, Znajomość MITRE ATT&CK, Znajomość systemów operacyjnych, Znajomość sieci komputerowych i protokołów sieciowych, Doświadczenie w testach bezpieczeństwa aplikacji webowych, Doświadczenie w testach bezpieczeństwa aplikacji mobilnych, Doświadczenie w testach bezpieczeństwa API, Doświadczenie z Active Directory, Doświadczenie z Exchange, Doświadczenie z rozwiązaniami chmurowymi, Doświadczenie z systemami IAM, Znajomość relacyjnych i nierelacyjnych baz danych, Podstawy kryptografii, Znajomość Docker, Znajomość Kubernetes, Umiejętność analizy i deobfuskacji kodu, Umiejętność obchodzenia SSL Pinning 📃 Skills: OWASP, WSTG, MASVS, CVSS, MITRE, ActiveDirectory, Exchange, Keycloak, Docker, Kubernetes, API, IAM, SQL, NoSQL, Cryptography, SSLPinning 🏢 Description: Zakres obowiązków Prowadzenie manualnych i automatycznych testów penetracyjnych aplikacji webowych, mobilnych, infrastruktury oraz systemów IT. Wykonywanie analiz bezpieczeństwa, skanów podatności oraz statycznej analizy kodu. Testowanie bezpieczeństwa interfejsów API, aplikacji mobilnych oraz środowisk kontenerowych. Opracowywanie raportów z testów wraz z rekomendacjami usunięcia wykrytych podatności. Wymagania Minimum 3 lata doświadczenia w obszarze testów penetracyjnych lub bezpieczeństwa ofensywnego. Znajomość technik ataków i standardów bezpieczeństwa, w szczególności OWASP, OWASP WSTG, OWASP MASVS, CVSS oraz MITRE ATT&CK. Praktyczna znajomość systemów operacyjnych, sieci komputerowych, protokołów sieciowych oraz narzędzi do analizy ruchu i testów penetracyjnych. Doświadczenie w testowaniu bezpieczeństwa aplikacji webowych, mobilnych, API oraz infrastruktury opartej o Active Directory, Exchange, rozwiązania chmurowe i systemy IAM (np. Keycloak). Znajomość relacyjnych i nierelacyjnych baz danych, podstaw kryptografii oraz technologii konteneryzacji (Docker, Kubernetes). Umiejętność analizy i deobfuskacji kodu, w tym obchodzenia mechanizmów SSL Pinning.

Technology

TSS

Tester Bezpieczeństwa

Mid

Remote

Warsaw, Poland

80 - 95 PLN

🏢 Summary: Role focused on conducting comprehensive security testing of web applications, APIs, and IT infrastructure, including penetration testing and vulnerability assessments. The position involves identifying security risks, simulating real-world attacks, and providing remediation recommendations in close collaboration with development teams. It requires hands-on use of professional security tools and active participation in code reviews and technical consultations. 🗂️ Requirements: Minimum 3 years of commercial experience in security testing, Experience in penetration testing and vulnerability scanning, Practical experience in manual web application security testing, Experience in API security testing, Experience in network infrastructure security assessment, Proficiency with Burp Suite, OWASP ZAP, Wireshark, SQLMap, Ability to identify vulnerabilities and assess security risks, Experience collaborating with development teams and participating in code reviews, Fluent Polish, Working knowledge of English for technical documentation 📃 Skills: BurpSuite, OWASPZAP, Wireshark, SQLMap, PenetrationTesting, VulnerabilityScanning, WebSecurity, APITesting, Networking, Cybersecurity, OWASP, Cloud, Agile, Scrum 🏢 Description: W TSS napędzamy cyfrową rewolucję. Tworzymy zaawansowane systemy i innowacyjne rozwiązania z zakresu Software Development, FinTech, AI oraz Cybersecurity. Zakres odpowiedzialności: Testy bezpieczeństwa aplikacji webowych: Planowanie, przygotowywanie i realizacja manualnych testów bezpieczeństwa aplikacji webowych, identyfikacja podatności oraz analiza ryzyk bezpieczeństwa. Testowanie API: Przeprowadzanie testów bezpieczeństwa interfejsów API, weryfikacja mechanizmów uwierzytelniania, autoryzacji oraz odporności na najczęściej występujące zagrożenia. Testy infrastruktury sieciowej: Ocena bezpieczeństwa infrastruktury IT, usług sieciowych oraz konfiguracji systemów pod kątem potencjalnych podatności. Testy penetracyjne: Realizacja testów penetracyjnych systemów i aplikacji, symulowanie rzeczywistych scenariuszy ataków oraz analiza skuteczności wdrożonych zabezpieczeń. Skanowanie podatności: Wykorzystywanie specjalistycznych narzędzi do wykrywania luk bezpieczeństwa, analiza wyników oraz przygotowywanie rekomendacji naprawczych. Wykorzystanie narzędzi bezpieczeństwa: Codzienna praca z narzędziami takimi jak Burp Suite, OWASP ZAP, Wireshark, SQLMap oraz innymi rozwiązaniami wspierającymi proces testów bezpieczeństwa. Współpraca z zespołem deweloperskim: Aktywna współpraca z programistami, architektami i analitykami w zakresie identyfikacji oraz eliminacji zagrożeń bezpieczeństwa, udział w code review i konsultacjach technicznych. Raportowanie i rekomendacje: Przygotowywanie raportów z przeprowadzonych testów, dokumentowanie wykrytych podatności oraz rekomendowanie działań naprawczych i usprawnień. Wymagania: Doświadczenie komercyjne: Minimum 3 lata doświadczenia w obszarze testów bezpieczeństwa obejmujących testy penetracyjne, skanowanie podatności oraz symulacje ataków. Testy bezpieczeństwa aplikacji: Praktyczne doświadczenie w manualnym testowaniu bezpieczeństwa aplikacji webowych, API oraz infrastruktury sieciowej. Narzędzia bezpieczeństwa: Bardzo dobra znajomość narzędzi takich jak Burp Suite , OWASP ZAP, Wireshark, SQLMap oraz innych rozwiązań wykorzystywanych w testach bezpieczeństwa. Znajomość zagadnień cyberbezpieczeństwa: Umiejętność identyfikowania podatności, analizowania ryzyk bezpieczeństwa oraz proponowania skutecznych działań naprawczych. Komunikacja i współpraca: Wysoko rozwinięte umiejętności komunikacyjne oraz doświadczenie we współpracy z zespołami deweloperskimi, w tym udział w code review i konsultacjach technicznych. Znajomość języków: Biegłe posługiwanie się językiem polskim w mowie i piśmie oraz znajomość języka angielskiego umożliwiająca efektywną pracę z dokumentacją techniczną. Dodatkowym atutem będzie: Znajomość standardów i metodyk bezpieczeństwa, w szczególności OWASP Top 10. Doświadczenie w testowaniu środowisk chmurowych oraz nowoczesnych architektur aplikacyjnych. Posiadanie certyfikatów branżowych związanych z bezpieczeństwem, np. eJPT, PNPT, OSCP, CEH lub pokrewnych. Doświadczenie w pracy w środowiskach Agile/Scrum. Otwartość na dzielenie się wiedzą oraz aktywne wspieranie rozwoju zespołu. Co zyskujesz, dołączając do teamu? Stabilność i elastyczność: Długofalową współpracę w oparciu o kontrakt B2B. Realny wpływ: Pracę nad kluczowymi projektami, gdzie Twoje rekomendacje i działania realnie wpływają na poziom bezpieczeństwa tworzonych rozwiązań. Zdrowie pod kontrolą: Dofinansowanie do prywatnej opieki medycznej w PZU. Stały rozwój: Dostęp do wewnętrznych, specjalistycznych szkoleń z zakresu m.in . cyberbezpieczeństwa. Środowisko entuzjastów: Pracę w zespole, gdzie pasja łączy się z profesjonalizmem, a dobra atmosfera to standard, nie benefit.

Technology

Jit Team

Penetration Testing

Senior

Hybrid

Krakow, Poland

1,100 - 1,360 PLN

🏢 Summary: Security Researcher role focused on penetration testing across hardware, software, cloud, mobile, and OT environments within a product security team. The position involves vulnerability research, exploitation, security assessments, and collaboration with engineering teams to ensure secure product development. Candidates will work with advanced security tools, conduct technical research, and prepare detailed security documentation. 🗂️ Requirements: Strong understanding of TCP/IP networking, Knowledge of application protocols, Knowledge of software exploitation techniques, Experience with common vulnerabilities, Hands-on experience with port scanning, Hands-on experience with fuzzing, Experience with vulnerability assessment tools, Knowledge of web technologies, Knowledge of web security risks, Familiarity with OWASP Top 10, Familiarity with SANS Top 25, Experience with mobile application security, Experience with APIs, Proficiency in Python or another scripting language, Knowledge of cryptographic protocols, Knowledge of security protocols, Experience with Metasploit, Experience writing custom exploits, Strong English communication skills 📃 Skills: TCP/IP, OWASP, SANS, Python, Metasploit, Fuzzing, APIs, Cryptography, Portscanning, Exploitation, Networking, Bluetooth, NFC, UART, JTAG, I2C, Firmware, Reverseengineering 🏢 Description: Project We are looking for a skilled Security Researcher to join a Cybersecurity Assurance Center, part of a product security team responsible for penetration testing across a wide range of products . In this role, you will work on cutting-edge cybersecurity challenges , ensuring that products are secure before they reach the market. Key Responsibilities Perform penetration testing across hardware, software, cloud, mobile and OT environments Identify, analyze and exploit vulnerabilities to prevent security issues before release Collaborate closely with engineering teams to support a security-by-design approach Use and develop advanced security tools, including custom cryptographic and reverse engineering solutions Conduct research on emerging technologies, protocols and potential attack vectors Prepare detailed technical reports and documentation Participate in knowledge-sharing sessions and technical discussions Required Skills & Experience Strong understanding of TCP/IP networking and application protocols Solid knowledge of software exploitation techniques and common vulnerabilities Hands-on experience with port scanning, fuzzing, and vulnerability assessment tools Knowledge of web technologies and related security risks Familiarity with OWASP Top 10 and SANS Top 25 Experience with mobile application security and APIs Proficiency in at least one scripting language (e.g. Python ) Good knowledge of cryptographic and security protocols Experience using tools like Metasploit and writing custom exploits Strong English communication skills (written and spoken) Nice to Have Experience with reverse engineering and binary analysis Knowledge of hardware exploitation (UART, JTAG, I2C, firmware extraction) Understanding of wireless technologies (RF, Bluetooth, NFC) Responsibilities Perform penetration testing on various systems, including hardware, software, cloud, mobile, and OT environmentsIdentify, analyze, and exploit vulnerabilities to improve product security before release Collaborate with engineering teams to support secure development practices Conduct vulnerability assessments, fuzz testing, and port scanning Research new technologies, communication protocols, and associated security risks Prepare detailed technical reports and internal documentation Participate in knowledge-sharing and technical discussions Use and develop advanced security tools, including custom-built solutions Client – why choose this particular client from the Jit portfolio? Our Client is an established global technology leader driving the digital transformation and innovation required to accelerate the transition toward a carbon-neutral future . Serving customers across the utility, industry, and infrastructure sectors, they provide cutting-edge solutions and services across the entire energy value chain. The organization is actively evolving the worlds energy systems to make them more sustainable, flexible, and secure, while precisely balancing social, environmental, and economic value. With a proven track record and an unparalleled installed technological base spanning well over 100 countries, the company operates on a massive global scale.

Technology

emagine Polska

Penetrationstester

Senior

On-site

Copenhagen, Denmark

🏢 Summary: Penetration tester role focused on conducting approximately 25 in-depth penetration tests of applications and networks within the public sector during 2026 (Q2–Q4). The assignment includes vulnerability analysis, retesting, and delivery of detailed technical reports in Danish. The consultant will test both legacy and modern technologies and present findings to stakeholders. 🗂️ Requirements: Proven experience with penetration testing in public sector environments, Strong knowledge of security research and vulnerability analysis, Experience performing application and network penetration tests, Ability to analyze complex systems and networks, Experience writing detailed technical security reports in Danish, Ability to communicate technical findings clearly, Experience with retesting and validation of vulnerabilities 📃 Skills: Penetrationtesting, Vulnerabilityanalysis, Securityresearch, Networksecurity, Applicationsecurity, OSCP, CEH, Scripting, Securityscanners, Reporting 🏢 Description: For en af vores kunder søger vi en dygtig Penetrationstester med erfaring inden for det statslige område til at udføre penetrationstests af diverse løsninger. 1.2 Beskrivelse af opgaven Formålet med gennemførelsen af pentests er at lave dybdegående afprøvning af sårbarheder, hvilke sammenholdes med de sårbarhedsscanninger, som kunden selv udfører løbende. Målet er at forsøge at bryde ind i en given applikation eller netværk, bl.a. gennem udnyttelsen af kendte sårbarheder og usikkert konfigurerede systemer. Der efterspørges en række pentests af applikationer, herunder flere højtprioriterede og gentests. Tests skal gennemføres i 2026 (Q2-Q4) efter en prioriteret rækkefølge aftalt mellem konsulenten og kunden. Opgavens omfang er i omegnen af 25 tests, og applikationerne spænder over både ældre og nyere teknologier. konsulenten skal derfor besidde en bred teknologisk viden og forståelse. Primære ansvarsområder Udførelse af pentests af høj kvalitet. Indsamling og analyse af sårbarheder. Dokumentation af fundne sårbarheder og deres alvorlighed. Udarbejdelse af teknisk, elektronisk rapport på dansk. Udførelse af mundtlig gennemgang af rapportens resultater. Gennemførelse af gentests af applikationer. Nøglekrav Solid erfaring med penetrationstests i det statslige område. Omfattende viden om sikkerhedsforskning og sårbarhedsanalyse. Evne til at kommunikere teknisk information klart og præcist. Erfaring med at udarbejde detaljerede tekniske rapporter. Færdigheder i at analysere komplekse systemer og netværk. Nice to Have Certificeringer inden for IT-sikkerhed (f.eks. OSCP, CEH). Kendskab til moderne programmeringssprog. Erfaring med automatiserede sikkerhedsscannere. Andre detaljer Testene er planlagt til 2026 og vil være delt over Q2 til Q4. Konsulenten vil modtage den nødvendige dokumentation og testbrugere for at udføre pentests effektivt.

Technology

AgileEngine

Application Security Engineer

Mid

Remote

Krakow, Poland

3,600 - 5,600 USD

🏢 Summary: The offer is for a Middle Application Security Engineer to perform hands-on DevSecOps work within a large-scale financial services security program. The role focuses on integrating SAST, DAST, and SCA security gates into CI/CD pipelines, tuning vulnerability scanning tools, and deploying secure coding baselines. The engineer will automate security processes in Python and provide code-level remediation guidance to Java and Python development teams. 🗂️ Requirements: 3–5 years of commercial experience in software engineering and DevSecOps/AppSec, Proficiency in Python for automation and scripting, Ability to read and navigate Java source code, Experience with CI/CD orchestration tools, Experience with vulnerability scoring frameworks, Ability to independently execute complex scripting and integration tasks, Upper-intermediate English level 📃 Skills: Python, Java, DevSecOps, AppSec, SAST, DAST, SCA, CI/CD, CNAPP, ASPM 🏢 Description: ID71662 AgileEngine is an Inc. 5000 company that creates award-winning software for Fortune 500 brands and trailblazing startups across 17+ industries. We rank among the leaders in areas like application development and AI/ML, and our people-first culture has earned us multiple Best Place to Work awards. Why join us If you're looking for a place to grow, make an impact, and work with people who care, we'd love to meet you! :) About the role We are looking for a Middle Application Security Engineer to execute hands-on DevSecOps work across CI/CD pipeline security integration, vulnerability management tooling, and automated hardened baseline deployment within a large-scale financial services security program. You will write Python scripts to integrate SAST, DAST, and SCA gates into CI/CD pipelines, tune scanning tools to reduce false positives, and provide code-level remediation guidance to Java and Python development teams. The role requires 3–5 years of combined software engineering and AppSec experience. What you will do Write and maintain the scripts necessary to integrate security gates (SAST, DAST, SCA) seamlessly into the CI/CD pipeline; Continuously tune and configure existing security scanning tools to eliminate false positives and deliver high-confidence alerts; Assist in coding and deploying automated hardened baselines and secure coding patterns; Work directly with product development teams to provide actionable, code-level remediation guidance in Java and Python. Must haves 3–5 years of commercial experience in software engineering ; Solid coding proficiency in Python for automation and scripting; Working knowledge of modern CI/CD orchestration tools and practical experience interacting with vulnerability scoring frameworks; Ability to operate with minimal supervision on day-to-day execution, reliably completing complex scripting and integration tasks; Upper-intermediate English level. Nice to haves Experience in DevSecOps or Application Security ; Ability to comfortably read and navigate Java source code; Hands-on experience with CNAPP or ASPM platforms such as Wiz ; Basic understanding of application threat modeling. The benefits of joining us Professional growth Accelerate your professional journey with mentorship, TechTalks, and personalized growth roadmaps Competitive compensation We match your ever-growing skills, talent, and contributions with competitive USD-based compensation and budgets for education, fitness, and team activities A selection of exciting projects Join projects with modern solutions development and top-tier clients that include Fortune 500 enterprises and leading product brands Flextime Tailor your schedule for an optimal work-life balance, by having the options of working from home and going to the office – whatever makes you the happiest and most productive. Meet Our Recruitment Process Asynchronous stage – An automated, self-paced track that helps us move faster and give you quicker feedback: Short online form to confirm basic requirements 30–60 minute skills assessment via Codility – a platform founded in Poland that helps us provide quicker feedback and streamline this stage of the process. 5-minute introduction video Synchronous stage – Live interviews Technical interview with our engineering team (scheduled at your convenience) Final interview with your future teammates If it’s a match — you’ll get an offer!

Technology

emagine Polska

Senior System Integration & Test Engineer

Senior

Hybrid

Bucharest, Romania

🏢 Summary: Senior System Integration & Test Engineer role focused on defining and executing integration and validation strategies for complex software systems. The position involves building integration environments, implementing CI/CD practices, and ensuring full requirements traceability and high-quality deliverables. The project duration is 3 years with responsibility for end-to-end integration and testing activities. 🗂️ Requirements: Master’s degree in Computer Science or equivalent, Minimum 7 years of experience in software integration and qualification, Strong knowledge of software project lifecycle management, Advanced experience with application servers, Expertise in web services integration, Proficiency in CI/CD tools, Strong Linux knowledge, Knowledge of cybersecurity principles (PKI) 📃 Skills: JBoss, Tomcat, SOAP, REST, RPC, Jenkins, Ansible, Linux, PKI, CICD, DevOps 🏢 Description: Introduction & Summary: We are seeking a highly skilled Senior System Integration & Test Engineer with a solid minimum of 7 years in the integration and qualification of software. The ideal candidate will possess a comprehensive understanding of the software project lifecycle, advanced knowledge of DevOps practices, and expertise in integrating systems to ensure high-quality deliverables. Project duration : 3 years. Main Responsibilities: This role involves defining integration strategies and ensuring proper testing of software systems. Key responsibilities include: Defining integration and test strategies, test plans, and test scenarios. Ensuring requirements traceability and coverage. Utilizing DevOps and CI/CD best practices. Building integration environments and installing or upgrading solutions. Performing integration and validation tests (including load, performance, high availability, accuracy and security tests). Investigating issues by analyzing logs during tests execution, reports incidents through configuration management tool and monitors them until closure. Producing documents that will allow proper installation, testing, operations and administration. Preparing and providing training for customers, support and maintenance teams. Supporting pre-sales teams on specific technical requests on integration activities. Defining and implementing autonomously the entire integration and test strategy of a full simple project requiring advanced knowledge in OS, database and integration tools. Key Requirements: - Master's or equivalent degree in Computer Science (5+ years). - Minimum 7 years experience in software integration and qualification. - Proficient in software project lifecycle management. - Advanced skills in Application Servers (JBoss, Tomcat). - Expertise in web services (SOAP, REST, RPC). - Proficient in CI/CD tools (Jenkins, Ansible) and OS (Linux). - Knowledge of Cybersecurity principles (PKI) is important. - Professional English proficiency is essential. Nice to Have: - Familiarity with Maven Artifact repositories (Nexus). - Experience with scripting (Python, Bash, etc.). - Understanding of Queueing services (Rabbit MQ, Active MQ). - Familiarity with cloud environments (AWS, Azure, Google Cloud). - Knowledge of IT infrastructures (Windows, Linux, virtualization). - Experience with test tools (Jira, JMeter, etc.). Other Details: Work Arrangement & Mobility Requirements This position follows a hybrid work model , with 2 days remote and 3 days on-site per week. The selected candidate must also be available for occasional business travel within Europe . Eligibility & Export Control Due to Export Control regulations , the role is restricted to European nationals . Candidates must be eligible to work under these regulations and must not have a criminal record