May 28, 2026
Penetrationstester
Senior • On-site
Copenhagen, Denmark
For en af vores kunder søger vi en dygtig Penetrationstester med erfaring inden for det statslige område til at udføre penetrationstests af diverse løsninger.
1.2 Beskrivelse af opgaven
Formålet med gennemførelsen af pentests er at lave dybdegående afprøvning af sårbarheder, hvilke sammenholdes med de sårbarhedsscanninger, som kunden selv udfører løbende. Målet er at forsøge at bryde ind i en given applikation eller netværk, bl.a. gennem udnyttelsen af kendte sårbarheder og usikkert konfigurerede systemer.
Der efterspørges en række pentests af applikationer, herunder flere højtprioriterede og gentests. Tests skal gennemføres i 2026 (Q2-Q4) efter en prioriteret rækkefølge aftalt mellem konsulenten og kunden. Opgavens omfang er i omegnen af 25 tests, og applikationerne spænder over både ældre og nyere teknologier. konsulenten skal derfor besidde en bred teknologisk viden og forståelse.
Primære ansvarsområder
Udførelse af pentests af høj kvalitet.
Indsamling og analyse af sårbarheder.
Dokumentation af fundne sårbarheder og deres alvorlighed.
Udarbejdelse af teknisk, elektronisk rapport på dansk.
Udførelse af mundtlig gennemgang af rapportens resultater.
Gennemførelse af gentests af applikationer.
Nøglekrav
Solid erfaring med penetrationstests i det statslige område.
Omfattende viden om sikkerhedsforskning og sårbarhedsanalyse.
Evne til at kommunikere teknisk information klart og præcist.
Erfaring med at udarbejde detaljerede tekniske rapporter.
Færdigheder i at analysere komplekse systemer og netværk.
Nice to Have
Certificeringer inden for IT-sikkerhed (f.eks. OSCP, CEH).
Kendskab til moderne programmeringssprog.
Erfaring med automatiserede sikkerhedsscannere.
Andre detaljer
Testene er planlagt til 2026 og vil være delt over Q2 til Q4. Konsulenten vil modtage den nødvendige dokumentation og testbrugere for at udføre pentests effektivt.
Similar jobs you might like
Technology
emagine Polska
Penetration Tester (m/w/d)
Senior
Remote
Berlin, Germany
🏢 Summary: Experienced Penetration Tester responsible for planning, executing, and reporting comprehensive penetration tests across network, web, wireless, Active Directory, and physical environments. The role includes realistic attack simulations, compliance assessments, and deriving concrete security improvement measures within a large public IT environment. Engagement is long-term and primarily remote within Germany. 🗂️ Requirements: Completed degree in Computer Science or recognized technical IT training, Minimum 3 years experience in IT security, At least 2 years hands-on experience in penetration testing or red teaming, Experience in at least 2 large-scale projects (>250 users), Proven experience in web, network or cloud penetration testing, Ability to conduct independent security assessments and exploit development, Good German language skills (written and spoken) 📃 Skills: PenetrationTesting, RedTeaming, NetworkSecurity, WebSecurity, WLAN, ActiveDirectory, CloudSecurity, BurpSuite, Nmap, Metasploit, CobaltStrike, Nessus, OpenVAS, sqlmap, Python, PowerShell, Jira, Confluence, SharePoint, OSCP, GPEN, CEH, eJPT, CREST, CISSP, CISM 🏢 Description: Für das Projekt wird ein erfahrener Penetration Tester (m/w/d) gesucht, der umfassende Penetration Tests plant, vorbereitet, durchführt und nachbereitet. Die Rolle umfasst sowohl technische Sicherheitsanalysen als auch die Ableitung konkreter Maßnahmen zur Erhöhung der IT-Sicherheit. Der Einsatz findet im Umfeld eines großen öffentlichen IT-Dienstleisters statt. Deine Aufgaben: Vor- und Nachbereitung sowie Durchführung abgestimmter Penetration Tests, u. a.: Network Penetration Testing WLAN Penetration Testing Web Application Penetration Testing Active Directory Penetration Testing Physical Penetration Testing Ermittlung bekannter und unbekannter Sicherheitslücken in IT-Systemen und Anwendungen Analyse der Sicherheitslage der IT-Infrastruktur sowie Prüfung der Compliance-Vorgaben (z. B. DSGVO, BSI-Grundschutz, NIS-Richtlinie) Durchführung realitätsnaher Angriffssimulationen zur Risikobewertung Ableitung von Maßnahmen zur Verbesserung der IT-Sicherheit und Präsentation der Ergebnisse Sicherstellung, dass alle Aktivitäten transparent, nachvollziehbar und rechtskonform erfolgen Dein Profil: Abgeschlossenes Informatik-Studium oder eine anerkannte technische Berufsausbildung (z. B. Fachinformatiker) Mindestens 3 Jahre praktische Erfahrung im Bereich IT-Sicherheit, davon mindestens 2 Jahre in Penetration Tests bzw. Red-Team-Übungen Beteiligung an mindestens 2 größeren Projekten (Unternehmen / Behörde mit >250 Mitarbeitenden), z. B. Web-App-Pentests, Netzwerk-Pentests, Cloud-Pentests Gute Deutschkenntnisse in Wort und Schrift Zuschlagskriterien: Umfangreiche Erfahrung in Pen-Tests / Red-Team Mehrere Referenzprojekte Zertifizierungen wie OSCP, GPEN, CEH, eJPT, CREST, CISSP/CISM Erfahrung mit Werkzeugen wie Burp Suite, Nmap, Metasploit, Cobalt Strike, Nessus/OpenVAS, sqlmap, etc. Fähig, eigene Exploits / PoCs zu entwickeln (Python, PowerShell) Erfahrung mit Jira, Confluence, SharePoint Andere Details: Zeitraum: Rahmenvereinbarung bis 2030 Arbeitsort: Remote/Deutschland Bei Interesse freue ich mich auf Deine Bewerbungsunterlagen , Verfügbarkeit und Stundensätze an tamara.petrovic.turkovic@emagine.de
Technology
emagine Polska
Penetration Tester (m/w/d)
Senior
Remote
Berlin, BE, Germany
🏢 Summary: Experienced Penetration Tester responsible for planning, executing, and reporting comprehensive penetration tests across network, web, wireless, Active Directory, and physical environments for a public sector IT project. The role includes identifying vulnerabilities, performing realistic attack simulations, assessing compliance, and deriving concrete security improvements. Engagement is long-term and primarily remote within Germany. 🗂️ Requirements: Degree in ComputerScience or completed technical IT training, Minimum 3 years experience in ITSecurity, At least 2 years hands-on PenetrationTesting or RedTeam, Experience in minimum 2 large-scale projects over 250 users, Proven experience in WebApp Pentests Network Pentests or Cloud Pentests, Ability to develop own exploits or PoCs, Knowledge of compliance standards DSGVO BSI NIS, Fluent German language skills 📃 Skills: PenetrationTesting, RedTeam, NetworkSecurity, WLAN, WebSecurity, ActiveDirectory, Python, PowerShell, BurpSuite, Nmap, Metasploit, CobaltStrike, Nessus, OpenVAS, sqlmap, OSCP, GPEN, CEH, eJPT, CREST, CISSP, CISM, Jira, Confluence, SharePoint 🏢 Description: Für das Projekt wird ein erfahrener Penetration Tester (m/w/d) gesucht, der umfassende Penetration Tests plant, vorbereitet, durchführt und nachbereitet. Die Rolle umfasst sowohl technische Sicherheitsanalysen als auch die Ableitung konkreter Maßnahmen zur Erhöhung der IT-Sicherheit. Der Einsatz findet im Umfeld eines großen öffentlichen IT-Dienstleisters statt. Deine Aufgaben: Vor- und Nachbereitung sowie Durchführung abgestimmter Penetration Tests, u. a.: Network Penetration Testing WLAN Penetration Testing Web Application Penetration Testing Active Directory Penetration Testing Physical Penetration Testing Ermittlung bekannter und unbekannter Sicherheitslücken in IT-Systemen und Anwendungen Analyse der Sicherheitslage der IT-Infrastruktur sowie Prüfung der Compliance-Vorgaben (z. B. DSGVO, BSI-Grundschutz, NIS-Richtlinie) Durchführung realitätsnaher Angriffssimulationen zur Risikobewertung Ableitung von Maßnahmen zur Verbesserung der IT-Sicherheit und Präsentation der Ergebnisse Sicherstellung, dass alle Aktivitäten transparent, nachvollziehbar und rechtskonform erfolgen Dein Profil: Abgeschlossenes Informatik-Studium oder eine anerkannte technische Berufsausbildung (z. B. Fachinformatiker) Mindestens 3 Jahre praktische Erfahrung im Bereich IT-Sicherheit, davon mindestens 2 Jahre in Penetration Tests bzw. Red-Team-Übungen Beteiligung an mindestens 2 größeren Projekten (Unternehmen / Behörde mit >250 Mitarbeitenden), z. B. Web-App-Pentests, Netzwerk-Pentests, Cloud-Pentests Gute Deutschkenntnisse in Wort und Schrift Zuschlagskriterien: Umfangreiche Erfahrung in Pen-Tests / Red-Team Mehrere Referenzprojekte Zertifizierungen wie OSCP, GPEN, CEH, eJPT, CREST, CISSP/CISM Erfahrung mit Werkzeugen wie Burp Suite, Nmap, Metasploit, Cobalt Strike, Nessus/OpenVAS, sqlmap, etc. Fähig, eigene Exploits / PoCs zu entwickeln (Python, PowerShell) Erfahrung mit Jira, Confluence, SharePoint Andere Details: Zeitraum: Rahmenvereinbarung bis 2030 Arbeitsort: Remote/Deutschland Bei Interesse freue ich mich auf Deine Bewerbungsunterlagen , Verfügbarkeit und Stundensätze an tamara.petrovic.turkovic@emagine.de
Technology
Exatel S.A.
Pentesterka/ Pentester
Senior
Hybrid
Warsaw, Poland
🏢 Summary: Role focused on conducting advanced penetration tests for applications, systems, network devices, and IT/OT infrastructure within strategic cybersecurity projects. The position involves both manual and automated testing, tool development, and reporting, with participation in R&D and telecom-related security initiatives. It offers specialization paths in areas such as operator-class networks, OT, and mobile security. 🗂️ Requirements: Minimum 3 years of commercial penetration testing experience, Experience in manual and automated penetration testing, Ability to develop security testing tools, Knowledge of penetration testing methodologies, Practical experience in IT security, OSCP certification, Eligibility for security clearance or willingness to undergo clearance procedure 📃 Skills: Pentesting, IT, OT, OSCP, OSCE, OSWE, CEH, LPT, Android, iOS, SDN, 5G, CVE 🏢 Description: Wewnątrz EXATEL – operatora sieci strategicznych, powstał kilkudziesięcioosobowy zespół zajmujący się zapewnianiem cyberbezpieczeństwa. Realizujemy szereg projektów dotyczących m.in. różnych newralgicznych obszarów funkcjonowania Państwa. Monitorujemy bezpieczeństwo 24x7, identyfikujemy luki i dajemy rekomendacje jak je zamknąć, wdrażamy sensowne zabezpieczenia. A jak trzeba – jeździmy do klientów pomagać im w przypadku aktywnych incydentów. Do pracy wykorzystujemy najlepsze światowe technologie ale także sami tworzymy potrzebne nam rozwiązania, jeżeli nie ma ich na rynku. U nas będziesz miał/a możliwość realizować projekty dużo ciekawsze niż gdzie indziej. Testy urządzeń sieciowych klasy operatorskiej, OT, udział w projektach R&D (np. TAMA, SDNbox, SDNcore, #Polskie5G, Satelitarny System Obserwacji Ziemi). To tylko część zadań realizowanych przez zespół. Oczywiście nie jest nam też obcy codzienny chleb pentesterski w postaci testów realizowanych dla branży finansowej, energetycznej czy zbrojeniowej. Pentesterka/ Pentester Zakres obowiązków: Wykonywanie manualnych i automatycznych testów penetracyjnych aplikacji, systemów, urządzeń sieciowych i infrastruktury IT/OT - w zależności od przyjętej specjalizacji będziesz rozwijał się w ustalonej wspólnie ścieżce Przygotowywanie szczegółowych raportów z wykonanych testów penetracyjnych. Nasze wymagania: Odpowiedni mindset. Dopasowanie zespołu jest dla nas bardzo ważne Minimum 3 lata udokumentowanego komercyjnego doświadczenia w wykonywaniu testów penetracyjnych W związku z unikatowością niektórych projektów potrzebne będzie konstruktywne podejście oraz umiejętność nieszablonowego i logicznego myślenia Umiejętność tworzenia narzędzi wspomagających testowanie bezpieczeństwa systemów i aplikacji Znajomość metodyk stosowanych w testach penetracyjnych Praktyczne doświadczenie z zakresu bezpieczeństwa informatycznego Certyfikat OSCP Poświadczenia bezpieczeństwa lub gotowość do poddania się procedurze. Mile widziane: Podstawowa wiedza z zakresu elektroniki Praktyczne doświadczenia w testach operatorskiej infrastruktury telekomunikacyjnej Praktyczne doświadczenie w testach OT Praktyczne doświadczenie w testach aplikacji mobilnych (Android, iOS) Certyfikaty takie jak: OSCE, OSWE, CEH, LPT, inne Własne CVE – jeśli posiadasz opublikowane, prześlij je wraz z aplikacją Oferujemy: Zatrudnienie na podstawie umowy o pracę Premie półroczne uzależnione od poziomu realizacji celów Praca w modelu hybrydowym Możliwość zdobycia doświadczenia zawodowego poprzez realizację ciekawych zadań w branży telekomunikacyjnej Pakiet świadczeń socjalnych (opieka medyczna w tym pakiet stomatologiczny i swoboda leczenia, karnet sportowy) Benefity socjalne i oferty pracownicze Elastyczne godziny rozpoczęcia pracy Parking dla pracowników JAK WYGLĄDA PROCES REKRUTACYJNY? Przeanalizujemy Twoją aplikację Jeśli Twoje kompetencje wpiszą się w nasze oczekiwania spodziewaj się telefonu od Marty z zespołu HR Jeśli pozytywnie przejdziesz rozmowę czeka Cię spotkanie online na platformie ZOOM z przełożonym - Markiem- Dział Architektury i Zaawansowanych Usług Bezpieczeństwa oraz Martą - HR Business Partner Informację zwrotną otrzymasz niezależnie od decyzji Wyślij swoje CV i dołącz do #teamEXATEL 🛰!
Technology
emagine Polska
Pentester
Senior
Remote
Warsaw, Poland
🏢 Summary: The offer is for an experienced Penetration Tester to conduct comprehensive security assessments across web, mobile, cloud, infrastructure, and API environments. The role focuses on identifying vulnerabilities, validating security controls, and ensuring compliance with DORA and PCI-DSS through primarily manual testing. The candidate will deliver structured, actionable reports based on recognized security standards and methodologies. 🗂️ Requirements: Minimum 5 years of penetration testing experience, Proven delivery of enterprise-level pentests, Experience with web, mobile, cloud, API, and infrastructure testing, Strong manual exploitation skills, Knowledge of OWASP Top 10, PTES, OSSTMM, Ability to perform grey-box testing, Experience with AWS, Azure, or GCP environments, Ability to produce detailed technical reports, Relevant security certifications (OSCP, OSCE, OSWE, GPEN, GWAPT, CISSP) 📃 Skills: Pentesting, OWASP, PTES, OSSTMM, DORA, PCI-DSS, AWS, Azure, GCP, Android, iOS, React, REST, Swagger, API, ActiveDirectory, Firewalls, VPN, CIS, OSCP, OSCE, OSWE, GPEN, GWAPT, CISSP 🏢 Description: Role Objective The primary objectives of the role are to: Identify security vulnerabilities in external and internal infrastructure/applications. Validate the effectiveness of existing security controls. Ensure compliance with DORA and PCI-DSS regulations. Provide actionable remediation guidance. Scope of Work The Penetration Tester will be responsible for conducting comprehensive penetration tests across the following areas: Asset Type Environment Notes Web applications Staging/Prod Main customer portal, admin panels, complex business-oriented apps Mobile applications Staging/Prod Android/iOS native apps, React Native Cloud environment Production AWS/Azure/GCP, CIS benchmark Thick client apps Production Desktop agents, use of API External infra Production Firewalls, VPN gateways Internal infra Production AD environment, database servers APIs and microservices Staging/Prod REST API provided with Swagger Testing Methodology Manual vs Automated: Emphasis on manual exploitation. Automated scanning should not exceed 20% of effort. Standards: Testing must adhere to OWASP Top 10 for web/mobile apps, PTES, or OSSTMM. Credentials: For grey-box testing, accounts will be provided (e.g., admin, user, viewer) for privilege escalation testing. Key Requirements Proven experience in delivering high-quality pentest services to enterprise clients (at least 5 years of experience delivering pentests) and client references. Team members with relevant certifications (e.g., OSCP, OSCE, OSWE, GPEN, GWAPT, CISSP). High communication quality: clear verbal communication and reporting. Ability to deliver detailed, structured, and actionable reports. Use of industry-standard tools and methodologies.
Technology
Ness Solution
Tester Penetracyjny
Mid
Remote
Warsaw, Poland
90 - 100 PLN
🏢 Summary: Oferta dotyczy prowadzenia manualnych i automatycznych testów penetracyjnych aplikacji webowych, mobilnych, API oraz infrastruktury IT wraz z analizą podatności i raportowaniem rekomendacji bezpieczeństwa. Rola obejmuje także analizę kodu, testowanie środowisk kontenerowych oraz pracę z systemami IAM i rozwiązaniami chmurowymi. 🗂️ Requirements: Minimum 3 lata doświadczenia w testach penetracyjnych lub bezpieczeństwie ofensywnym, Znajomość OWASP, Znajomość OWASP WSTG, Znajomość OWASP MASVS, Znajomość CVSS, Znajomość MITRE ATT&CK, Znajomość systemów operacyjnych, Znajomość sieci komputerowych i protokołów sieciowych, Doświadczenie w testach bezpieczeństwa aplikacji webowych, Doświadczenie w testach bezpieczeństwa aplikacji mobilnych, Doświadczenie w testach bezpieczeństwa API, Doświadczenie z Active Directory, Doświadczenie z Exchange, Doświadczenie z rozwiązaniami chmurowymi, Doświadczenie z systemami IAM, Znajomość relacyjnych i nierelacyjnych baz danych, Podstawy kryptografii, Znajomość Docker, Znajomość Kubernetes, Umiejętność analizy i deobfuskacji kodu, Umiejętność obchodzenia SSL Pinning 📃 Skills: OWASP, WSTG, MASVS, CVSS, MITRE, ActiveDirectory, Exchange, Keycloak, Docker, Kubernetes, API, IAM, SQL, NoSQL, Cryptography, SSLPinning 🏢 Description: Zakres obowiązków Prowadzenie manualnych i automatycznych testów penetracyjnych aplikacji webowych, mobilnych, infrastruktury oraz systemów IT. Wykonywanie analiz bezpieczeństwa, skanów podatności oraz statycznej analizy kodu. Testowanie bezpieczeństwa interfejsów API, aplikacji mobilnych oraz środowisk kontenerowych. Opracowywanie raportów z testów wraz z rekomendacjami usunięcia wykrytych podatności. Wymagania Minimum 3 lata doświadczenia w obszarze testów penetracyjnych lub bezpieczeństwa ofensywnego. Znajomość technik ataków i standardów bezpieczeństwa, w szczególności OWASP, OWASP WSTG, OWASP MASVS, CVSS oraz MITRE ATT&CK. Praktyczna znajomość systemów operacyjnych, sieci komputerowych, protokołów sieciowych oraz narzędzi do analizy ruchu i testów penetracyjnych. Doświadczenie w testowaniu bezpieczeństwa aplikacji webowych, mobilnych, API oraz infrastruktury opartej o Active Directory, Exchange, rozwiązania chmurowe i systemy IAM (np. Keycloak). Znajomość relacyjnych i nierelacyjnych baz danych, podstaw kryptografii oraz technologii konteneryzacji (Docker, Kubernetes). Umiejętność analizy i deobfuskacji kodu, w tym obchodzenia mechanizmów SSL Pinning.
Technology
BLUE energy Sp. z o.o.
Tester Penetracyjny Aplikacji Web
Mid
Hybrid
Poznan, Poland
10,000 - 14,000 PLN
🏢 Summary: Offer for a Web Application Penetration Tester responsible for conducting manual and automated security testing of web applications for external clients. The role focuses on identifying and exploiting vulnerabilities, preparing detailed security reports, and advising on remediation. It involves working with recognized security tools and methodologies to ensure high application security standards. 🗂️ Requirements: Experience in web application penetration testing, Knowledge of web security vulnerabilities (XSS, SQL Injection, CSRF, RCE), Ability to use penetration testing tools (Burp Suite, OWASP ZAP, Nmap, Metasploit), Ability to analyze application code for security flaws, Understanding of web application architecture, Knowledge of OWASP and PTES methodologies, Ability to prepare technical security reports, Relevant security certifications (e.g. CEH, OSCP, CISSP, GWAPT) 📃 Skills: BurpSuite, OWASPZAP, Nmap, Metasploit, XSS, SQLInjection, CSRF, RCE, JavaScript, PHP, Python, OWASP, PTES, CEH, OSCP, CISSP, GWAPT 🏢 Description: Jako firma konsultingowa specjalizująca się w bezpieczeństwie IT, poszukujemy Testera Penetracyjnego Aplikacji Web , który dołączy do naszego zespołu. Osoba na tym stanowisku będzie odpowiedzialna za realizację testów penetracyjnych aplikacji webowych w ramach projektów dla naszych zewnętrznych klientów. Będziesz pracować nad identyfikowaniem luk w zabezpieczeniach aplikacji, wspierając naszych klientów w zapewnianiu najwyższego poziomu bezpieczeństwa ich systemów. Zakres obowiązków: Realizacja testów penetracyjnych aplikacji webowych dla różnych klientów, w tym identyfikowanie i eksploatowanie luk w zabezpieczeniach Audytowanie aplikacji pod kątem zagrożeń takich jak XSS, SQL Injection, CSRF, RCE i innych typowych wektorów ataków Przeprowadzanie testów manualnych oraz automatycznych przy użyciu narzędzi takich jak Burp Suite, OWASP ZAP, Metasploit, itp. Przygotowywanie szczegółowych raportów z przeprowadzonych testów, w tym rekomendacji dotyczących poprawy zabezpieczeń Współpraca z zespołami deweloperskimi klientów, doradztwo w zakresie implementacji poprawek bezpieczeństwa Udział w analizach ryzyka i opracowywanie zaleceń dla klientów w zakresie bezpieczeństwa aplikacji webowych Wymagania: Doświadczenie w przeprowadzaniu testów penetracyjnych aplikacji webowych, w tym znajomość narzędzi i metod wykorzystywanych w tej dziedzinie (Burp Suite, OWASP ZAP, Nmap, Metasploit, itp.) Doskonała znajomość zagrożeń związanych z bezpieczeństwem aplikacji webowych (XSS, SQL Injection, CSRF, RCE, itp.) Umiejętność analizowania kodu aplikacji i identyfikowania potencjalnych luk w zabezpieczeniach Dobre rozumienie architektury aplikacji webowych i technologii wykorzystywanych w aplikacjach (JavaScript, PHP, Python, itp.) Umiejętności raportowania i przedstawiania wyników testów w sposób zrozumiały dla osób nietechnicznych (np. menedżerowie projektów, klienci) Certyfikaty z zakresu bezpieczeństwa (np. CEH, OSCP, CISSP, GWAPT) będą dodatkowym atutem Praktyczna znajomość metodologii testowania oraz standardów bezpieczeństwa (np. OWASP, PTES) Umiejętność pracy w zespole, komunikatywność oraz umiejętność pracy z klientami Oferujemy: Pracę nad interesującymi projektami z zakresu bezpieczeństwa aplikacji webowych dla klientów z różnych branż Atrakcyjne wynagrodzenie oraz pakiet benefitów (m. in. Multisport, ubezpieczenie i pakiet medyczny) Możliwość rozwoju zawodowego i certyfikacji w zakresie bezpieczeństwa IT Współpracę z zespołem ekspertów oraz wsparcie w realizacji wyzwań technicznych Elastyczne godziny pracy oraz możliwość pracy zdalnej lub hybrydowej Jeśli jesteś pasjonatem bezpieczeństwa aplikacji webowych i chcesz dołączyć do naszego zespołu, zapraszamy do aplikowania!
Technology
DataArt
Penetration Tester
Mid
Remote
Wroclaw, Poland
12,000 - 15,000 PLN
🏢 Summary: The offer is for a Middle Penetration Tester responsible for conducting network and application-level security assessments using automated and manual techniques. The role involves identifying and validating vulnerabilities, preparing detailed reports, collaborating with clients, and contributing to internal security tools and processes. The position focuses on strengthening security posture through structured testing methodologies and technical research. 🗂️ Requirements: Minimum 1 year of experience in vulnerability assessments and penetration testing, Minimum 3 years of experience in IT industry, Experience with Linux, Windows, Active Directory, JavaScript, .NET, SQL, Experience applying structured penetration testing methodologies, Understanding of web application vulnerabilities, Ability to document vulnerabilities and remediation steps, Experience with Burp Suite, Nessus, Metasploit, Nmap, sqlmap, Knowledge of programming or scripting for security tools development 📃 Skills: Burp, Nessus, Metasploit, Nmap, sqlmap, Linux, Windows, ActiveDirectory, JavaScript, .NET, SQL, Scripting 🏢 Description: Project overview A security-focused initiative aimed at performing vulnerability assessments and penetration tests for a variety of digital systems. The project supports continuous improvement of security practices and contributes to the development of internal tools and methodologies. The work includes research activities, process enhancement, and collaboration with technical teams to strengthen the overall security posture. Team You will join a security-oriented team that consists of penetration testers, security analysts, and engineers. The team collaborates closely, shares knowledge, and supports research and internal tool development. Position overview We are looking for a Middle Penetration Tester who will be involved in network and application-level security assessments. You will use automated tools and manual techniques to identify and verify security vulnerabilities. This role includes preparing assessment reports, interacting with clients to clarify scope and gather information, and contributing to the improvement of security processes and tools. Technology stack Burp Suite, Nessus, Metasploit, Nmap, sqlmap, Linux, Windows, Active Directory, JavaScript, .NET, SQL, scripting languages Responsibilities Conduct network and application-level security assessments Use automated tools and manual techniques to identify and validate vulnerabilities Prepare clear and comprehensive assessment reports with root cause details and remediation steps Communicate with clients to gather information, clarify scope, and discuss security controls Support internal security competence development through research, tool creation, and process improvement Collaborate with other team members across security and engineering domains Requirements One year of experience performing vulnerability assessments and penetration tests Three years of experience in the IT industry with familiarity across technologies such as Linux, Windows, Active Directory, JavaScript, .NET, SQL Experience applying structured methodology for vulnerability assessments and penetration tests Understanding of web application vulnerabilities Ability to describe and report vulnerabilities along with typical remediation activities Experience with open source and commercial security tools, including Burp Suite, Nessus, Metasploit, Nmap, and sqlmap Knowledge of programming or scripting for creating auxiliary security tools Ability to work effectively with customers and self-manage in challenging situations Nice to have Security certifications, including OSCP, CRTO, CPTS, eWPT, BSCP Strong programming experience in a modern language Experience with mobile application penetration testing Experience with reverse engineering and binary analysis Experience publishing technical content or speaking at industry events Familiarity with security standards, including PCI DSS and ISO 27000
Technology
UNIQA
Młodsza/y Specjalistka/a ds. testów penetracyjnych
Junior
Hybrid
Warsaw, Poland
🏢 Summary: Role focused on supporting security testing and vulnerability assessments in live environments, with hands-on use of pentesting tools and techniques. The position involves analyzing scan results, identifying vulnerabilities, and contributing to pentest reports. It offers practical development in manual testing, attack techniques, and cybersecurity best practices. 🗂️ Requirements: 1–2 years experience in cybersecurity, pentesting or vulnerability analysis, Knowledge of OWASP Top 10, Understanding of pentesting phases, Experience with Burp Suite, Nmap, Wireshark, Knowledge of XSS, SQLi, CSRF vulnerabilities, Ability to work with Linux and Windows, Knowledge of HTTP, DNS, TCP/IP protocols, Basic knowledge of cryptography and TLS, English level min. B1 📃 Skills: BurpSuite, Nmap, Wireshark, Linux, Windows, OWASP, XSS, SQLi, CSRF, HTTP, DNS, TCPIP, TLS, HTTPS, Metasploit, Nessus, Kali, CEH, eJPT, SecurityPlus, PNPT, OSCP, GDPR, DORA, ISO27001 🏢 Description: Opis firmy Od 30 lat działamy w Polsce i tworzymy miejsce, w którym ludzie naprawdę lubią pracować. Jesteśmy jedną z największych grup ubezpieczeniowych w kraju – zajmujemy 6. miejsce na rynku! Naszym celem? Pomagać ludziom żyć lepiej – bez stresu o zdrowie, życie czy majątek. Ubezpieczamy, wspieramy i inspirujemy do tego, żeby żyć dłużej, zdrowiej i bezpieczniej. Z taką samą troską podchodzimy do naszych pracowników – bo wiemy, że fajna praca to nie tylko obowiązki, ale też atmosfera, rozwój i poczucie, że to, co robisz, ma znaczenie. Jeśli chcesz pracować w miejscu, gdzie możesz się rozwijać, mieć realny wpływ i być częścią czegoś większego – dołącz do nas! Opis stanowiska Chcesz realnie wpływać na bezpieczeństwo naszych systemów i pracować z narzędziami, które wykorzystują pentesterzy? W tej roli uczysz się w praktyce, działasz na żywych środowiskach i rozwijasz swoje umiejętności każdego dnia. Tu działasz konkretnie — testujesz, analizujesz i wyłapujesz podatności, zanim zrobią to cyberprzestępcy. Na co dzień: wspierasz testy bezpieczeństwa i pomagasz wykrywać podstawowe luki, analizujesz wyniki skanów podatności i weryfikujesz false positives, tworzysz część raportów z pentestów: dowody, opisy podatności, podstawowe rekomendacje, dokumentujesz przebieg testów i dbasz o kompletne materiały techniczne, rozwijasz umiejętności w manualnych testach bezpieczeństwa, technikach ataków i narzędziach pentesterskich, śledzisz trendy w cyberatakach i regularnie uczysz się nowych technologii. Wymagania posiadasz 1–2 lata doświadczenia w cyberbezpieczeństwie, pentestach lub analizie podatności (również projekty własne, CTF, bug bounty), znasz podstawy OWASP Top 10 i etapy prowadzenia pentestów, pracowałaś/eś z Burp Suite, Nmap, Wireshark, znasz typowe podatności aplikacyjne (XSS, SQLi, CSRF), umiesz pracować z Linuxem i Windowsem oraz podstawowymi protokołami (HTTP/S, DNS, TCP/IP), znasz podstawy kryptografii (HTTPS/TLS, szyfrowanie danych), komunikatywnie mówisz w języku angielskim (min. B1), lubisz pracę zespołową, feedback i dbasz o dokładną dokumentację. Mile widziane: znasz Metasploit, Nessus lub narzędzia Kali Linux, posiadasz doświadczenie w testowaniu aplikacji mobilnych, API, infrastruktury, posiadasz certyfikaty: CEH, eJPT, Security+, PNPT, OSCP, znasz regulacje RODO/GDPR, DORA, ISO 27001. Oferujemy Pracujesz w firmie o jasnych wartościach: wspólnota, prostota, klient przede wszystkim, odpowiedzialność i wiarygodność. Premia roczna. Pracujesz w środowisku IT‑security, gdzie szybko rozwijasz umiejętności i pracujesz z nowoczesnymi narzędziami oraz innowacyjnymi rozwiązaniami. Możesz liczyć na wsparcie zespołu i uczenie się od osób z doświadczeniem pentesterskim. Dostęp do platform wellbeingowych, szkoleń online i nauki języków. Kafeteria, w której sam wybierasz benefity (sport, zdrowie, karty przedpłacone, rabaty, vouchery). Pracowniczy Program Inwestycyjny i Program Poleceń. Możliwość angażowania się w wolontariat i działania CSR. Kluby UNIQA — bieganie, planszówki, narty, turystyka górska, podróże, strzelectwo. Stabilna umowa o pracę i hybryda — do biura wpadasz tylko sporadycznie.
Technology
Jit Team
Penetration Testing
Senior
Hybrid
Krakow, Poland
1,100 - 1,360 PLN
🏢 Summary: Security Researcher role focused on penetration testing across hardware, software, cloud, mobile, and OT environments within a product security team. The position involves vulnerability research, exploitation, security assessments, and collaboration with engineering teams to ensure secure product development. Candidates will work with advanced security tools, conduct technical research, and prepare detailed security documentation. 🗂️ Requirements: Strong understanding of TCP/IP networking, Knowledge of application protocols, Knowledge of software exploitation techniques, Experience with common vulnerabilities, Hands-on experience with port scanning, Hands-on experience with fuzzing, Experience with vulnerability assessment tools, Knowledge of web technologies, Knowledge of web security risks, Familiarity with OWASP Top 10, Familiarity with SANS Top 25, Experience with mobile application security, Experience with APIs, Proficiency in Python or another scripting language, Knowledge of cryptographic protocols, Knowledge of security protocols, Experience with Metasploit, Experience writing custom exploits, Strong English communication skills 📃 Skills: TCP/IP, OWASP, SANS, Python, Metasploit, Fuzzing, APIs, Cryptography, Portscanning, Exploitation, Networking, Bluetooth, NFC, UART, JTAG, I2C, Firmware, Reverseengineering 🏢 Description: Project We are looking for a skilled Security Researcher to join a Cybersecurity Assurance Center, part of a product security team responsible for penetration testing across a wide range of products . In this role, you will work on cutting-edge cybersecurity challenges , ensuring that products are secure before they reach the market. Key Responsibilities Perform penetration testing across hardware, software, cloud, mobile and OT environments Identify, analyze and exploit vulnerabilities to prevent security issues before release Collaborate closely with engineering teams to support a security-by-design approach Use and develop advanced security tools, including custom cryptographic and reverse engineering solutions Conduct research on emerging technologies, protocols and potential attack vectors Prepare detailed technical reports and documentation Participate in knowledge-sharing sessions and technical discussions Required Skills & Experience Strong understanding of TCP/IP networking and application protocols Solid knowledge of software exploitation techniques and common vulnerabilities Hands-on experience with port scanning, fuzzing, and vulnerability assessment tools Knowledge of web technologies and related security risks Familiarity with OWASP Top 10 and SANS Top 25 Experience with mobile application security and APIs Proficiency in at least one scripting language (e.g. Python ) Good knowledge of cryptographic and security protocols Experience using tools like Metasploit and writing custom exploits Strong English communication skills (written and spoken) Nice to Have Experience with reverse engineering and binary analysis Knowledge of hardware exploitation (UART, JTAG, I2C, firmware extraction) Understanding of wireless technologies (RF, Bluetooth, NFC) Responsibilities Perform penetration testing on various systems, including hardware, software, cloud, mobile, and OT environmentsIdentify, analyze, and exploit vulnerabilities to improve product security before release Collaborate with engineering teams to support secure development practices Conduct vulnerability assessments, fuzz testing, and port scanning Research new technologies, communication protocols, and associated security risks Prepare detailed technical reports and internal documentation Participate in knowledge-sharing and technical discussions Use and develop advanced security tools, including custom-built solutions Client – why choose this particular client from the Jit portfolio? Our Client is an established global technology leader driving the digital transformation and innovation required to accelerate the transition toward a carbon-neutral future . Serving customers across the utility, industry, and infrastructure sectors, they provide cutting-edge solutions and services across the entire energy value chain. The organization is actively evolving the worlds energy systems to make them more sustainable, flexible, and secure, while precisely balancing social, environmental, and economic value. With a proven track record and an unparalleled installed technological base spanning well over 100 countries, the company operates on a massive global scale.
Technology
Link Group
Global Penetration Testing Manager
Senior
Hybrid
Kraków, Poland
🏢 Summary: Senior cybersecurity leadership role focused on managing global penetration testing operations within a banking environment, including governance, compliance, strategy, and stakeholder management. The position oversees regional execution, risk-based planning, vendor management, and executive reporting while ensuring regulatory alignment. Candidates are expected to combine deep penetration testing expertise with leadership experience in multinational organizations. 🗂️ Requirements: 8–10 years of experience in penetration testing service delivery or coordination, Experience managing technical service delivery and cross-border teams, Ability to present security topics to C-suite executives and regulatory bodies, Fluent English, Deep knowledge of penetration testing and cybersecurity, Experience with international process implementation, Experience with risk-based decision-making, Bachelor’s degree in Computer Science, Cybersecurity, or equivalent experience, At least one certification: OSCP, At least one certification: OSCE, At least one certification: CREST-CRT, At least one certification: CREST CCT, At least one certification: CISSP, At least one certification: CISM, At least one certification: GIAC GPEN 📃 Skills: Pentesting, Cybersecurity, OSCP, OSCE, CREST, CISSP, CISM, GIAC, GPEN, RedTeaming, PurpleTeaming, ThreatModeling, ExploitDevelopment, RiskAssessment, Compliance, KPIs, KRIs 🏢 Description: Global Service Lead – Pentest Coordination We are seeking a senior cybersecurity leader to take ownership of our global penetration testing operations. In this role, you will define the strategic direction, oversee regional execution, ensure regulatory compliance, and manage relationships with high-level stakeholders and C-suite executives across a global banking environment. Key Responsibilities Global Governance & Compliance: Safeguard the quality and compliance of global penetration testing services. Ensure all activities align with bank internal policies and global regulatory requirements, collaborating closely with regional leads in AMER, APAC, and EMEA. Team Leadership & Strategy: Directly manage the EMEA Pentest Coordination Team Lead. Provide strategic guidance to ensure flawless execution, technical review accuracy, and timely delivery across the EMEA region. Strategic Planning (Book of Work): Lead the creation, formalization, and stakeholder validation of the annual global pentest Book of Work. Risk-Based Prioritization: Align testing schedules and priorities with threat modeling and risk-based assessment methodologies. Vendor & Budget Management: Consolidate and oversee the global pentest budget, ensuring cost-effectiveness. Conduct regular performance reviews of both internal and external testing providers to drive continuous service improvement. Metrics, KPIs & Audit Readiness: Maintain data integrity within reporting platforms. Define and track KPIs/KRIs, deliver regular executive reporting, and support both internal and external regulatory audits. Requirements Leadership & Experience: 8–10 years of experience in a similar penetration testing service delivery or coordination role. Proven track record of managing technical service delivery and cross-border teams within large, multinational organizations . Strong executive presence with the ability to facilitate steering committees and confidently present complex security topics to C-suite executives and regulatory bodies . Exceptional cross-cultural collaboration and communication skills, with complete fluency in English . Technical Expertise & Qualifications: Deep domain knowledge in penetration testing and broader cybersecurity practices. Solid experience in international process implementation and data-driven, risk-based decision-making. Education: Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience. Certifications (Must hold at least one): OSCP, OSCE, CREST-CRT, CREST CCT, CISSP, CISM, or GIAC GPEN. Nice to Have Professional experience within the banking or financial services sector (ideally a global investment bank). Prior experience serving as an advisor to a CISO or participating in risk-steering committees. Hands-on technical background in Red Teaming / Purple Teaming , advanced threat modeling, or exploit development.