June 30, 2026

Global Penetration Testing Manager

Senior • Hybrid

Kraków, Poland

Global Service Lead – Pentest Coordination

We are seeking a senior cybersecurity leader to take ownership of our global penetration testing operations. In this role, you will define the strategic direction, oversee regional execution, ensure regulatory compliance, and manage relationships with high-level stakeholders and C-suite executives across a global banking environment.

Key Responsibilities

  • Global Governance & Compliance: Safeguard the quality and compliance of global penetration testing services. Ensure all activities align with bank internal policies and global regulatory requirements, collaborating closely with regional leads in AMER, APAC, and EMEA.

  • Team Leadership & Strategy: Directly manage the EMEA Pentest Coordination Team Lead. Provide strategic guidance to ensure flawless execution, technical review accuracy, and timely delivery across the EMEA region.

  • Strategic Planning (Book of Work): Lead the creation, formalization, and stakeholder validation of the annual global pentest Book of Work.

  • Risk-Based Prioritization: Align testing schedules and priorities with threat modeling and risk-based assessment methodologies.

  • Vendor & Budget Management: Consolidate and oversee the global pentest budget, ensuring cost-effectiveness. Conduct regular performance reviews of both internal and external testing providers to drive continuous service improvement.

  • Metrics, KPIs & Audit Readiness: Maintain data integrity within reporting platforms. Define and track KPIs/KRIs, deliver regular executive reporting, and support both internal and external regulatory audits.

Requirements

Leadership & Experience:

  • 8–10 years of experience in a similar penetration testing service delivery or coordination role.

  • Proven track record of managing technical service delivery and cross-border teams within large, multinational organizations.

  • Strong executive presence with the ability to facilitate steering committees and confidently present complex security topics to C-suite executives and regulatory bodies.

  • Exceptional cross-cultural collaboration and communication skills, with complete fluency in English.

Technical Expertise & Qualifications:

  • Deep domain knowledge in penetration testing and broader cybersecurity practices.

  • Solid experience in international process implementation and data-driven, risk-based decision-making.

  • Education: Bachelor’s degree in Computer Science, Cybersecurity, or equivalent practical experience.

  • Certifications (Must hold at least one): OSCP, OSCE, CREST-CRT, CREST CCT, CISSP, CISM, or GIAC GPEN.

Nice to Have

  • Professional experience within the banking or financial services sector (ideally a global investment bank).

  • Prior experience serving as an advisor to a CISO or participating in risk-steering committees.

  • Hands-on technical background in Red Teaming / Purple Teaming, advanced threat modeling, or exploit development.

Similar jobs you might like

Technology

New offer

Experis Manpower Group

API Pentester

Senior

Remote

Wroclaw, Poland

170 - 180 PLN

🏢 Summary: Hands-on senior offensive security role leading penetration testing engagements across web, network, mobile, cloud, and Active Directory environments. The position combines technical delivery, client interaction, reporting, and mentoring responsibilities within consulting-style engagements. Candidates are expected to have advanced penetration testing experience, scripting skills, and recognized offensive security certifications. 🗂️ Requirements: 5+ years of hands-on penetration testing or offensive security experience, Experience in consulting or client-facing security engagements, Expertise in at least three areas: web, network, mobile, or Active Directory security testing, Experience with offensive security and penetration testing tools, Scripting skills in Python, PowerShell, or Bash, Strong communication and technical reporting skills, At least one certification: OSCP, CREST CRT/CPSA, CRTP, or CRTO 📃 Skills: BurpSuite, Nmap, Metasploit, BloodHound, Impacket, CobaltStrike, Nessus, OpenVAS, Frida, MobSF, Python, PowerShell, Bash, AWS, Azure, GCP, Kubernetes 🏢 Description: Join our Offensive Security team and lead penetration testing engagements for clients across financial services, technology, healthcare, government, and critical infrastructure sectors. This is a hands-on role for an experienced security professional who wants to remain highly technical while taking ownership of project delivery, client relationships, and mentoring junior consultants. Key Responsibilities: Lead and perform penetration tests across web applications, APIs, internal/external networks, mobile applications, cloud environments, and Active Directory. Conduct advanced Active Directory security assessments and infrastructure testing. Develop custom scripts, tooling, and proof-of-concept exploits. Manage engagements from scoping to reporting and remediation validation. Present findings to technical and business stakeholders. Support proposal development, effort estimation, and pre-sales activities. Mentor junior team members and contribute to internal methodologies and best practices. Required Experience: 5+ years of hands-on penetration testing or offensive security experience, ideally within a consulting environment. Strong expertise in at least three of the following: web, network, mobile, or Active Directory security testing. Experience with tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Cobalt Strike (or similar), Nessus/OpenVAS, Frida, and MobSF. Scripting skills in Python, PowerShell, or Bash. Strong communication, reporting, and client-facing skills. Certifications: At least one of: OSCP CREST CRT/CPSA CRTP or CRTO Nice to Have: Big 4 or cybersecurity consultancy experience. Cloud security testing (AWS, Azure, GCP). Kubernetes/container security knowledge. Security research, CVEs, conference talks, or CTF achievements. Offer: Multisport Card Life insurance Private healthcare PowerYou platform

Technology

Antal Sp. z o.o.

HSBCJP00057046 (Cybersecurity) Penetration Testing Lead

Senior

Hybrid

Krakow, Poland

180 - 220 PLN/hr

🏢 Summary: Leadership role combining hands-on penetration testing with team management, responsible for delivering complex security assessments across applications, infrastructure, and mobile platforms. The position owns the full testing lifecycle, defines methodologies, and ensures high-quality reporting and remediation guidance. It involves close collaboration with global stakeholders to strengthen overall security posture. 🗂️ Requirements: Minimum 5 years of hands-on penetration testing experience, Experience leading or mentoring penetration testing teams, Expertise in at least two areas: web applications, infrastructure, mobile security, Strong knowledge of common vulnerabilities and attack techniques, Strong understanding of TCP/IP and network security, Strong understanding of application security principles, Experience with manual and automated testing, Ability to communicate technical findings to non-technical stakeholders, Experience with scripting or programming 📃 Skills: PenetrationTesting, WebSecurity, InfrastructureSecurity, MobileSecurity, TCP/IP, NetworkSecurity, ApplicationSecurity, Scripting, OWASP, SAST, DAST, IAST, OAuth2, JWT, iOS, Android, Java, Kotlin, Swift, Objective-C, Microservices, APIs, Cloud 🏢 Description: Penetration Testing Team Lead 📍 Location: Kraków (preferable) / Warszawa ( 6 days per month) Area: Cybersecurity – Research & Offensive Security Level: Senior / Leadership Model: B2B Rate: 180-220PLN netto About the role We are looking for a Penetration Testing Team Lead to join a global cybersecurity organization and lead a team responsible for identifying and exploiting vulnerabilities across applications, infrastructure, and mobile platforms. This role combines hands-on penetration testing expertise with team leadership and delivery ownership . You will lead complex security assessments, shape testing methodologies, and work closely with stakeholders to strengthen the overall security posture in a rapidly evolving threat landscape. Key responsibilities Lead and manage a team of penetration testers delivering security assessments across multiple domains Oversee end-to-end penetration testing lifecycle: scoping, planning, execution, and reporting Ensure high-quality, actionable deliverables, including clear risk articulation and remediation guidance Act as the main escalation point for complex technical challenges and stakeholder concerns Collaborate with global penetration testing leads to: align methodologies and standards share knowledge and insights ensure consistency across regions Contribute to the development and continuous improvement of testing frameworks, tools, and best practices Build and maintain internal knowledge base (findings, trends, lessons learned) Support vulnerability management lifecycle (tracking, remediation, risk acceptance) Participate in incident response and security investigations when needed Evaluate new tools, techniques, and emerging attack vectors Leadership & collaboration Mentor, coach, and develop team members (technical and career growth) Foster a collaborative, knowledge-sharing culture within the team Work closely with stakeholders across technology, security, and business teams Translate technical findings into business-relevant insights Support cross-regional collaboration and alignment Requirements Minimum 5 years of hands-on experience in penetration testing Proven experience leading or mentoring penetration testing teams Strong expertise in at least two domains: web applications infrastructure mobile security Solid understanding of: common vulnerabilities and attack techniques TCP/IP and network security application security principles Strong experience with manual and automated testing techniques Ability to clearly communicate complex technical findings to non-technical stakeholders Strong analytical thinking and problem-solving skills Experience with scripting/programming Nice to have Experience with mobile security (iOS, Android) and related risks Knowledge of OWASP standards (e.g., MASVS, MSTG) Experience with SAST, DAST, IAST tools Understanding of modern architectures (microservices, APIs, cloud environments) Experience with code reviews (Java, Kotlin, Swift, Objective-C) Knowledge of authentication and security mechanisms (OAuth2, JWT, biometrics, SSL pinning) Background in software development or secure SDLC Experience in financial services or other regulated environments What we offer Opportunity to lead and shape a high-performing penetration testing team Work in a global, collaborative cybersecurity environment Exposure to complex and large-scale security challenges Real impact on improving security posture across the organization Competitive compensation and benefits _ Luxmed and Multisport Why apply for an Antal job offer? When your application is successful, you will be supported by a dedicated Consultant who will stay in regular contact with you (via email or phone), help you prepare for interviews with your future employer, and ensure a smooth and professional recruitment process. About Antal Antal is a leading recruitment and HR advisory company, present in Poland since 1996 and later expanded to the Czech Republic and Hungary. Across the CEE region, we employ around 150 professionals who deliver a full range of services – from specialist and executive recruitment, employee outsourcing and HR consulting, to employer branding and market research. Our division-based structure combines deep industry expertise with functional specialisation, enabling us to provide tailored solutions for companies in every sector. We act as a trusted partner for both employers and candidates, sharing our knowledge and guiding them through every stage of the talent journey. We connect exceptional people with the right opportunities and help organisations build successful teams.

Technology

Orange Polska

Senior Pentester

Senior

Hybrid

Warsaw, Poland

🏢 Summary: Senior Pentester role in an international Zero Trust Security project, responsible for end-to-end penetration testing, technical audits, and Red/Purple Team activities. The position involves exploiting complex vulnerabilities across network, cloud, and application environments, reporting risk with business impact, and mentoring junior testers. The role also includes tooling development, framework alignment, and close collaboration with stakeholders. 🗂️ Requirements: 5+ years of hands-on penetration testing experience, 2+ years of project leadership and mentoring experience, Strong knowledge of TCP/IP, DNS, routing, Strong knowledge of Linux, Strong knowledge of HTTP, TLS, REST, GraphQL, Understanding of Kerberos, NTLM, OAuth2, OIDC, SAML, JWT, Experience with AD and Entra ID, Advanced exploitation skills including privilege escalation and lateral movement, Experience in cloud and container security including IAM and Kubernetes, Proficiency with Burp Suite Pro, Nmap, Wireshark, Metasploit, Experience with C2 frameworks, Programming or scripting in Python, Programming or scripting in PowerShell or Bash or Go, Experience with Git, Knowledge of PTES, OWASP Testing Guide, NIST SP 800-115, Ability to map findings to MITRE ATT&CK, Fluent Polish and English (minimum B2) 📃 Skills: TCP/IP, DNS, Linux, HTTP, TLS, REST, GraphQL, Kerberos, NTLM, OAuth2, OIDC, SAML, JWT, ActiveDirectory, EntraID, IAM, Kubernetes, CI/CD, BurpSuite, Nmap, Wireshark, Metasploit, CobaltStrike, Sliver, Python, PowerShell, Bash, Go, Git, PTES, OWASP, NIST, MITRE, CVSS 🏢 Description: Jako Senior Pentester dołączysz do naszego rosnącego zespołu Cybersecurity, będąc kluczowym członkiem projektu międzynarodowego (klient francuski) i pracując w modelu Zero Trust Security. Liczymy nie tylko na Twoją wiedzę techniczną, ale także na Twoje umiejętności współpracy z innymi, ze szczególnym naciskiem na dzielenie się wiedzą i mentoring młodszych członków zespołu. Współpraca opiera się na umowie o pracę i zdalnym (tylko z terytorium Polski) lub hybrydowym (dowolne biuro Orange Polska) modelu pracy. Senior Pentester Planowanie i prowadzenie testów od początku do końca: zakres, Statement of Work, zasady współpracy, sprawdzanie legalności i ryzyka Przeprowadzanie audytów technicznych (w tym PenTesting i audytów konfiguracji) na różnych zakresach i poziomach złożoności Identyfikowanie i łączenie słabości, aby pokazać realny wpływ, zawsze w bezpieczny sposób i w ramach zakresu Prowadzenie warsztatów w celu rozwoju filozofii Red Team i wspieranie promowania Purple Team, z uwzględnieniem dojrzałości Blue Team Tworzenie jasnych raportów z dowodami, ocenami ryzyka (np. CVSS), wpływem na biznes i praktycznymi rozwiązaniami; prezentowanie wyników zarówno technicznym, jak i nietechnicznym odbiorcom Uzgadnianie priorytetów z właścicielami, doradzanie w zakresie napraw i kontroli rekompensujących, planowanie i wykonywanie retestów Udoskonalanie metod i narzędzi: aktualizacja playbooków, pisanie skryptów/PoC, utrzymanie środowisk laboratoryjnych, dzielenie się badaniami Nauczanie i wspieranie młodszych testerów: spotkania 1:1, testy w parach, warsztaty, szkolenia wewnętrzne; przegląd ich pracy; wsparcie w rekrutacji i onboardingu Dzielenie się wiedzą z zespołem i społecznością: tech talks, artykuły, lessons learned; publikowanie blogów lub prezentacji; udział w open source Współpraca z interesariuszami: prowadzenie briefingów i warsztatów, tłumaczenie ryzyk technicznych na język biznesu Wsparcie działań presales: przygotowywanie zakresów, szacowanie wysiłku, pisanie SoW, udział w spotkaniach z klientami Przestrzeganie etyki i standardów (PTES, OWASP, NIST, ISO, PCI DSS) oraz ochrona poufnych danych Wymagane: Ponad 5 lat praktycznego doświadczenia w penetration testing w różnych obszarach; doświadczenie w prowadzeniu projektów i mentoringu (2+ lat) Dobra znajomość sieci (TCP/IP, DNS, routing), Linux i technologii webowych (HTTP(S), TLS, REST/GraphQL) Dobre zrozumienie tożsamości i uwierzytelniania: Kerberos/NTLM, OAuth2/OIDC, SAML, JWT; AD/Entra ID i popularnych IdP (np. Okta/Azure AD) Zaawansowane umiejętności w zakresie exploitacji: weryfikacja ustaleń, tworzenie prostych PoC, chainowanie problemów, eskalacja uprawnień, lateral movement, OPSEC Solidne doświadczenie w bezpieczeństwie Cloud i kontenerów: IAM, segmentation, serverless, secrets, supply chain, Kubernetes (RBAC/admission), CI/CD attack paths Znajomość narzędzi: Burp Suite Pro, Nmap, Wireshark, Metasploit, CLI chmur, frameworków C2 (np. Cobalt Strike, Sliver) Umiejętność scriptingu/programowania: Python i co najmniej jeden z: PowerShell/Bash/Go; Git; automatyzacja i tworzenie własnych narzędzi Umiejętność dostosowania metod i frameworków: PTES, OWASP Testing Guide, NIST SP 800-115; mapowanie do MITRE ATT&CK; podstawowe modelowanie zagrożeń Jasna komunikacja: zwięzłe pisanie, skuteczne prezentacje, priorytetyzacja ryzyk w kontekście biznesu Biegła znajomość języka polskiego i angielskiego (minimum B2) Mile widziane: Certyfikaty: CEH, CISSP, OSCP, GPEN/GXPN/GMOB, CRTO, CCSK/CCSP Głębsze doświadczenie w Red Teamingu, detection engineering i tuning telemetry Reverse engineering i development exploitów (np. Ghidra/IDA) lub fuzzing Zaawansowane testy mobilne (np. Frida/Objection, instrumentation) Udział w open source, badania/CVEs, konferencje, silne osiągnięcia w bug bounty Doświadczenie w ramach frameworków zgodności i ryzyka (PCI DSS, ISO 27001/SOC 2, NIST CSF) i metrykach (KPIs/OKRs) Znajomość języka francuskiego Benefity: Stabilne zatrudnienie w oparciu o umowę o pracę Praca w modelu hybrydowym (2 dni z biura / 3 dni z domu) Program emerytalny – po 6 miesiącach pracy, Orange co miesiąc dołoży 7% Twojej pensji brutto na Twoje konto emerytalne Prywatna opieka medyczna w PZU Zdrowie Pożyczki bez oprocentowania na cele mieszkaniowe, zdrowotne i inne Dofinansowanie do wypoczynku Karta sportowa FitProfit Wydarzenia integracyjne i wyjazdy współfinansowane z funduszu socjalnego Możliwość dołączenia do ubezpieczenia grupowego na preferencyjnych warunkach Smartfon z nielimitowanym Internetem – również do użytku prywatnego Preferencyjna oferta na usługi Orange Zróżnicowane i dopasowane do potrzeb możliwości rozwoju – szkolenia, dostęp do platform edukacyjnych (w tym platformy do nauki języków obcych), program staży wewnętrznych i inspirujące wydarzenia edukacyjne „Zdrowie na TAK” - program dla osób z niepełnosprawnościami „Jestem w grze” – wsparcie dla rodziców powracających do pracy po urlopach rodzicielskich Programy wellbeingowe Wolontariat we współpracy z Fundacją Orange

Technology

Euroclear

Tribe Test Engineer (Test Manager)

Senior

Hybrid

Krakow, Poland

🏢 Summary: Senior-level testing role responsible for defining and leading test and deployment strategies for complex or large-scale projects, ensuring software quality, risk control, and successful releases. The position involves managing test planning, execution, reporting, and deployment activities while overseeing teams and vendors. The role ensures delivery within quality, time, and budget targets in mission-critical environments. 🗂️ Requirements: Proven experience in software testing and quality assurance, Experience leading test strategy and deployment for complex or large projects, Ability to create and manage test plans, test cases, and test data, Experience with system testing, UAT, alpha and beta testing, Experience managing deployments to Pre-Production and Production environments, Ability to analyze and manage testing risks, Experience validating requirements and design documentation for testability, Experience leading and monitoring test execution and reporting, Project management experience in testing environments, Experience supervising or mentoring test teams 📃 Skills: Testing, QA, UAT, Alpha, Beta, Deployment, Pre-Production, Production, TestPlanning, TestCases, TestData, RiskManagement, Reporting, ProjectManagement 🏢 Description: Key Responsibilities Conducts a wide range of quality control tests and analyses to ensure that software meets or exceeds specified standards and end‑user requirements: Drafts, revises, and approves test plans and scripts to ensure alignment with standards and IT strategy. Creates test data files with valid and invalid records to thoroughly test program logic and verify system flow. Coordinates with users to plan user acceptance testing, alpha, and beta testing. Ensures that system tests are successfully completed and documented, and that all problems are resolved. Contributes to or manages deployment preparation and execution for both Pre‑Production and Production until the end of the warranty period. Role Overview Leads testing in a complex environment or for one or more standard to larger projects. Manages the preparation of systems and/or applications deployment. May manage the deployment itself. Is responsible for formulating the test and deployment strategy for their area and plans and leads work to ensure the delivery of the product within quality standards. May lead a team, project, or resources. Acts as the main reference point for problem escalation and is expected to plan and monitor the work of the team as well as external vendors. Has recognized expertise and authority in testing. Detailed Role Description Typically requires project management, organizational, and people‑leadership skills, as well as recognized expertise in testing. Uses these competencies: To formulate the test strategy, including the deployment approach, for one or more standard to larger projects. To specify and plan the corresponding activities and lead their execution, acting as the main reference point for problem escalation. To ensure that testing is carried out within budget and established procedures, meeting project testing objectives within quality, time, and budget targets. To analyze and monitor risks in the area of testing, identifying potential consequences and taking appropriate actions to prevent issues from materializing. Validates product design documentation to ensure that stated requirements are suitable for testing, unambiguous, and verifiable. Leads, guides, and monitors the analysis, design, implementation, and execution of test cases, test procedures, and/or test suites. Schedules tests for execution and monitors, measures, controls, and reports on test progress, product quality status, and test results, adapting the test plan as needed to adjust to evolving conditions. Produces a summary test report at the end of the project. May manage deployment activities (consolidating release scenarios, collecting authorizations, coordinating change delivery, and supporting operations after deployment). Work requires considering future implications beyond immediate problems and may involve creating new approaches and procedures to structurally address them. Provides feedback and development input into quality assurance methodologies and risk management strategy. Works with a high level of autonomy, with performance and outcomes subject to managerial review. Requires highly developed skills to motivate, influence, and persuade in the context of frequent interactions with a large and diverse set of stakeholders. Has a direct impact on the quality and stability of non‑stop applications and systems, helping avoid disruptions to mission‑critical services and supporting the company’s competitive advantage. Works and communicates with other stakeholders and vendors to ensure an effective quality assurance process is maintained and developed within the organization. May coach other testers stepping into this role. May supervise, develop, and assess the performance of Test Analysts. ​We welcome applicants from all backgrounds and experiences. If you meet most of the requirements and are excited about the role, we encourage you to apply.​

Technology

B2Bnetwork

Testing Strategy Lead

Senior

Hybrid

Warsaw, Poland

🏢 Summary: The role involves leading the design and implementation of a comprehensive testing strategy for operational and cyber resilience, ensuring effective recovery from major incidents. It focuses on disaster recovery, business continuity, and large-scale resilience testing within a regulated financial environment. The position requires close collaboration with cross-functional teams to validate and strengthen organizational recovery capabilities. 🗂️ Requirements: Extensive experience in senior testing leadership role, Experience in financial services or banking sector, Strong knowledge of Business Continuity Management, Strong knowledge of Crisis Management, Strong knowledge of Cyber Resilience, Experience designing Disaster Recovery testing programs, Experience managing large-scale testing programs, Ability to coordinate cross-functional technical teams, Experience conducting risk assessments, Ability to design and implement testing strategies 📃 Skills: BCM, Cybersecurity, DisasterRecovery, RiskManagement, DORA, EBA, PRA, Basel, Testing, Resilience 🏢 Description: Testing Strategy Lead – Operational & Cyber Resilience Location: Warsaw or Gdańsk (Hybrid – 3 days onsite) Language: English About the Role An experienced Testing Strategy Lead is sought to support a large-scale program focused on operational resilience and cyber recovery capabilities . The role will focus on designing and implementing a comprehensive testing strategy for Minimum Viable Business (MVB) capabilities , ensuring the organization can effectively respond to and recover from major operational or cyber incidents. This position works closely with senior stakeholders across technology, cyber resilience, risk, business continuity, and business teams , contributing to a strategic resilience program with high regulatory and organizational impact. Key Responsibilities Design and implement a comprehensive testing strategy for operational and cyber resilience capabilities. Develop recovery testing plans and execution schedules for critical systems and business processes. Coordinate large-scale resilience and disaster recovery testing exercises involving multiple technical and business teams. Define and manage dependencies between business processes, applications, and infrastructure to ensure realistic recovery scenarios. Conduct risk assessments and design realistic disaster scenarios to validate organizational resilience. Develop and execute different types of resilience tests, including tabletop, integrated, and technology-level testing. Support the setup and configuration of testing environments for resilience and recovery exercises. Continuously improve the testing strategy based on test results, feedback, and evolving regulatory requirements . Communicate testing strategy and results to senior stakeholders and ensure alignment between business and technology teams. Requirements Extensive experience as a Testing Manager, Test Strategy Lead, or similar senior testing leadership role within large organizations. Strong background in the financial services or banking sector , including familiarity with banking products and regulatory environments. Deep understanding of Business Continuity Management (BCM), Crisis Management, and Cyber/Operational Resilience . Proven experience designing and executing Disaster Recovery and recovery testing programs in complex environments. Experience managing large testing programs and coordinating cross-functional teams during resilience or recovery exercises. Ability to collaborate effectively with stakeholders across technology, security, risk, compliance, and business domains . Excellent communication skills and ability to translate strategic objectives into practical testing frameworks. Nice to Have Familiarity with regulatory frameworks such as DORA, EBA, PRA, or Basel . Experience working on enterprise resilience or regulatory transformation programs . What the Role Offers Participation in a strategic cyber resilience and operational resilience program . Opportunity to shape the long-term testing framework for recovery and resilience capabilities. Collaboration with senior stakeholders across risk, cyber security, technology, and business domains . High impact role contributing to the organizational resilience of a large financial institution .

Technology

emagine Polska

Penetration Tester (m/w/d)

Senior

Remote

Berlin, Germany

🏢 Summary: Experienced Penetration Tester responsible for planning, executing, and reporting comprehensive penetration tests across network, web, wireless, Active Directory, and physical environments. The role includes realistic attack simulations, compliance assessments, and deriving concrete security improvement measures within a large public IT environment. Engagement is long-term and primarily remote within Germany. 🗂️ Requirements: Completed degree in Computer Science or recognized technical IT training, Minimum 3 years experience in IT security, At least 2 years hands-on experience in penetration testing or red teaming, Experience in at least 2 large-scale projects (>250 users), Proven experience in web, network or cloud penetration testing, Ability to conduct independent security assessments and exploit development, Good German language skills (written and spoken) 📃 Skills: PenetrationTesting, RedTeaming, NetworkSecurity, WebSecurity, WLAN, ActiveDirectory, CloudSecurity, BurpSuite, Nmap, Metasploit, CobaltStrike, Nessus, OpenVAS, sqlmap, Python, PowerShell, Jira, Confluence, SharePoint, OSCP, GPEN, CEH, eJPT, CREST, CISSP, CISM 🏢 Description: Für das Projekt wird ein erfahrener Penetration Tester (m/w/d) gesucht, der umfassende Penetration Tests plant, vorbereitet, durchführt und nachbereitet. Die Rolle umfasst sowohl technische Sicherheitsanalysen als auch die Ableitung konkreter Maßnahmen zur Erhöhung der IT-Sicherheit. Der Einsatz findet im Umfeld eines großen öffentlichen IT-Dienstleisters statt. Deine Aufgaben: Vor- und Nachbereitung sowie Durchführung abgestimmter Penetration Tests, u. a.: Network Penetration Testing WLAN Penetration Testing Web Application Penetration Testing Active Directory Penetration Testing Physical Penetration Testing Ermittlung bekannter und unbekannter Sicherheitslücken in IT-Systemen und Anwendungen Analyse der Sicherheitslage der IT-Infrastruktur sowie Prüfung der Compliance-Vorgaben (z. B. DSGVO, BSI-Grundschutz, NIS-Richtlinie) Durchführung realitätsnaher Angriffssimulationen zur Risikobewertung Ableitung von Maßnahmen zur Verbesserung der IT-Sicherheit und Präsentation der Ergebnisse Sicherstellung, dass alle Aktivitäten transparent, nachvollziehbar und rechtskonform erfolgen Dein Profil: Abgeschlossenes Informatik-Studium oder eine anerkannte technische Berufsausbildung (z. B. Fachinformatiker) Mindestens 3 Jahre praktische Erfahrung im Bereich IT-Sicherheit, davon mindestens 2 Jahre in Penetration Tests bzw. Red-Team-Übungen Beteiligung an mindestens 2 größeren Projekten (Unternehmen / Behörde mit >250 Mitarbeitenden), z. B. Web-App-Pentests, Netzwerk-Pentests, Cloud-Pentests Gute Deutschkenntnisse in Wort und Schrift Zuschlagskriterien: Umfangreiche Erfahrung in Pen-Tests / Red-Team Mehrere Referenzprojekte Zertifizierungen wie OSCP, GPEN, CEH, eJPT, CREST, CISSP/CISM Erfahrung mit Werkzeugen wie Burp Suite, Nmap, Metasploit, Cobalt Strike, Nessus/OpenVAS, sqlmap, etc. Fähig, eigene Exploits / PoCs zu entwickeln (Python, PowerShell) Erfahrung mit Jira, Confluence, SharePoint Andere Details: Zeitraum: Rahmenvereinbarung bis 2030 Arbeitsort: Remote/Deutschland Bei Interesse freue ich mich auf Deine Bewerbungsunterlagen , Verfügbarkeit und Stundensätze an tamara.petrovic.turkovic@emagine.de

Technology

emagine Polska

Penetration Tester (m/w/d)

Senior

Remote

Berlin, BE, Germany

🏢 Summary: Experienced Penetration Tester responsible for planning, executing, and reporting comprehensive penetration tests across network, web, wireless, Active Directory, and physical environments for a public sector IT project. The role includes identifying vulnerabilities, performing realistic attack simulations, assessing compliance, and deriving concrete security improvements. Engagement is long-term and primarily remote within Germany. 🗂️ Requirements: Degree in ComputerScience or completed technical IT training, Minimum 3 years experience in ITSecurity, At least 2 years hands-on PenetrationTesting or RedTeam, Experience in minimum 2 large-scale projects over 250 users, Proven experience in WebApp Pentests Network Pentests or Cloud Pentests, Ability to develop own exploits or PoCs, Knowledge of compliance standards DSGVO BSI NIS, Fluent German language skills 📃 Skills: PenetrationTesting, RedTeam, NetworkSecurity, WLAN, WebSecurity, ActiveDirectory, Python, PowerShell, BurpSuite, Nmap, Metasploit, CobaltStrike, Nessus, OpenVAS, sqlmap, OSCP, GPEN, CEH, eJPT, CREST, CISSP, CISM, Jira, Confluence, SharePoint 🏢 Description: Für das Projekt wird ein erfahrener Penetration Tester (m/w/d) gesucht, der umfassende Penetration Tests plant, vorbereitet, durchführt und nachbereitet. Die Rolle umfasst sowohl technische Sicherheitsanalysen als auch die Ableitung konkreter Maßnahmen zur Erhöhung der IT-Sicherheit. Der Einsatz findet im Umfeld eines großen öffentlichen IT-Dienstleisters statt. Deine Aufgaben: Vor- und Nachbereitung sowie Durchführung abgestimmter Penetration Tests, u. a.: Network Penetration Testing WLAN Penetration Testing Web Application Penetration Testing Active Directory Penetration Testing Physical Penetration Testing Ermittlung bekannter und unbekannter Sicherheitslücken in IT-Systemen und Anwendungen Analyse der Sicherheitslage der IT-Infrastruktur sowie Prüfung der Compliance-Vorgaben (z. B. DSGVO, BSI-Grundschutz, NIS-Richtlinie) Durchführung realitätsnaher Angriffssimulationen zur Risikobewertung Ableitung von Maßnahmen zur Verbesserung der IT-Sicherheit und Präsentation der Ergebnisse Sicherstellung, dass alle Aktivitäten transparent, nachvollziehbar und rechtskonform erfolgen Dein Profil: Abgeschlossenes Informatik-Studium oder eine anerkannte technische Berufsausbildung (z. B. Fachinformatiker) Mindestens 3 Jahre praktische Erfahrung im Bereich IT-Sicherheit, davon mindestens 2 Jahre in Penetration Tests bzw. Red-Team-Übungen Beteiligung an mindestens 2 größeren Projekten (Unternehmen / Behörde mit >250 Mitarbeitenden), z. B. Web-App-Pentests, Netzwerk-Pentests, Cloud-Pentests Gute Deutschkenntnisse in Wort und Schrift Zuschlagskriterien: Umfangreiche Erfahrung in Pen-Tests / Red-Team Mehrere Referenzprojekte Zertifizierungen wie OSCP, GPEN, CEH, eJPT, CREST, CISSP/CISM Erfahrung mit Werkzeugen wie Burp Suite, Nmap, Metasploit, Cobalt Strike, Nessus/OpenVAS, sqlmap, etc. Fähig, eigene Exploits / PoCs zu entwickeln (Python, PowerShell) Erfahrung mit Jira, Confluence, SharePoint Andere Details: Zeitraum: Rahmenvereinbarung bis 2030 Arbeitsort: Remote/Deutschland Bei Interesse freue ich mich auf Deine Bewerbungsunterlagen , Verfügbarkeit und Stundensätze an tamara.petrovic.turkovic@emagine.de

Technology

emagine Polska

Penetrationstester

Senior

On-site

Copenhagen, Denmark

🏢 Summary: Penetration tester role focused on conducting approximately 25 in-depth penetration tests of applications and networks within the public sector during 2026 (Q2–Q4). The assignment includes vulnerability analysis, retesting, and delivery of detailed technical reports in Danish. The consultant will test both legacy and modern technologies and present findings to stakeholders. 🗂️ Requirements: Proven experience with penetration testing in public sector environments, Strong knowledge of security research and vulnerability analysis, Experience performing application and network penetration tests, Ability to analyze complex systems and networks, Experience writing detailed technical security reports in Danish, Ability to communicate technical findings clearly, Experience with retesting and validation of vulnerabilities 📃 Skills: Penetrationtesting, Vulnerabilityanalysis, Securityresearch, Networksecurity, Applicationsecurity, OSCP, CEH, Scripting, Securityscanners, Reporting 🏢 Description: For en af vores kunder søger vi en dygtig Penetrationstester med erfaring inden for det statslige område til at udføre penetrationstests af diverse løsninger. 1.2 Beskrivelse af opgaven Formålet med gennemførelsen af pentests er at lave dybdegående afprøvning af sårbarheder, hvilke sammenholdes med de sårbarhedsscanninger, som kunden selv udfører løbende. Målet er at forsøge at bryde ind i en given applikation eller netværk, bl.a. gennem udnyttelsen af kendte sårbarheder og usikkert konfigurerede systemer. Der efterspørges en række pentests af applikationer, herunder flere højtprioriterede og gentests. Tests skal gennemføres i 2026 (Q2-Q4) efter en prioriteret rækkefølge aftalt mellem konsulenten og kunden. Opgavens omfang er i omegnen af 25 tests, og applikationerne spænder over både ældre og nyere teknologier. konsulenten skal derfor besidde en bred teknologisk viden og forståelse. Primære ansvarsområder Udførelse af pentests af høj kvalitet. Indsamling og analyse af sårbarheder. Dokumentation af fundne sårbarheder og deres alvorlighed. Udarbejdelse af teknisk, elektronisk rapport på dansk. Udførelse af mundtlig gennemgang af rapportens resultater. Gennemførelse af gentests af applikationer. Nøglekrav Solid erfaring med penetrationstests i det statslige område. Omfattende viden om sikkerhedsforskning og sårbarhedsanalyse. Evne til at kommunikere teknisk information klart og præcist. Erfaring med at udarbejde detaljerede tekniske rapporter. Færdigheder i at analysere komplekse systemer og netværk. Nice to Have Certificeringer inden for IT-sikkerhed (f.eks. OSCP, CEH). Kendskab til moderne programmeringssprog. Erfaring med automatiserede sikkerhedsscannere. Andre detaljer Testene er planlagt til 2026 og vil være delt over Q2 til Q4. Konsulenten vil modtage den nødvendige dokumentation og testbrugere for at udføre pentests effektivt.

Technology

Exatel S.A.

Pentesterka/ Pentester

Senior

Hybrid

Warsaw, Poland

🏢 Summary: Role focused on conducting advanced penetration tests for applications, systems, network devices, and IT/OT infrastructure within strategic cybersecurity projects. The position involves both manual and automated testing, tool development, and reporting, with participation in R&D and telecom-related security initiatives. It offers specialization paths in areas such as operator-class networks, OT, and mobile security. 🗂️ Requirements: Minimum 3 years of commercial penetration testing experience, Experience in manual and automated penetration testing, Ability to develop security testing tools, Knowledge of penetration testing methodologies, Practical experience in IT security, OSCP certification, Eligibility for security clearance or willingness to undergo clearance procedure 📃 Skills: Pentesting, IT, OT, OSCP, OSCE, OSWE, CEH, LPT, Android, iOS, SDN, 5G, CVE 🏢 Description: Wewnątrz EXATEL – operatora sieci strategicznych, powstał kilkudziesięcioosobowy zespół zajmujący się zapewnianiem cyberbezpieczeństwa. Realizujemy szereg projektów dotyczących m.in. różnych newralgicznych obszarów funkcjonowania Państwa. Monitorujemy bezpieczeństwo 24x7, identyfikujemy luki i dajemy rekomendacje jak je zamknąć, wdrażamy sensowne zabezpieczenia. A jak trzeba – jeździmy do klientów pomagać im w przypadku aktywnych incydentów. Do pracy wykorzystujemy najlepsze światowe technologie ale także sami tworzymy potrzebne nam rozwiązania, jeżeli nie ma ich na rynku. U nas będziesz miał/a możliwość realizować projekty dużo ciekawsze niż gdzie indziej. Testy urządzeń sieciowych klasy operatorskiej, OT, udział w projektach R&D (np. TAMA, SDNbox, SDNcore, #Polskie5G, Satelitarny System Obserwacji Ziemi). To tylko część zadań realizowanych przez zespół. Oczywiście nie jest nam też obcy codzienny chleb pentesterski w postaci testów realizowanych dla branży finansowej, energetycznej czy zbrojeniowej. Pentesterka/ Pentester Zakres obowiązków: Wykonywanie manualnych i automatycznych testów penetracyjnych aplikacji, systemów, urządzeń sieciowych i infrastruktury IT/OT - w zależności od przyjętej specjalizacji będziesz rozwijał się w ustalonej wspólnie ścieżce Przygotowywanie szczegółowych raportów z wykonanych testów penetracyjnych. Nasze wymagania: Odpowiedni mindset. Dopasowanie zespołu jest dla nas bardzo ważne Minimum 3 lata udokumentowanego komercyjnego doświadczenia w wykonywaniu testów penetracyjnych W związku z unikatowością niektórych projektów potrzebne będzie konstruktywne podejście oraz umiejętność nieszablonowego i logicznego myślenia Umiejętność tworzenia narzędzi wspomagających testowanie bezpieczeństwa systemów i aplikacji Znajomość metodyk stosowanych w testach penetracyjnych Praktyczne doświadczenie z zakresu bezpieczeństwa informatycznego Certyfikat OSCP Poświadczenia bezpieczeństwa lub gotowość do poddania się procedurze. Mile widziane: Podstawowa wiedza z zakresu elektroniki Praktyczne doświadczenia w testach operatorskiej infrastruktury telekomunikacyjnej Praktyczne doświadczenie w testach OT Praktyczne doświadczenie w testach aplikacji mobilnych (Android, iOS) Certyfikaty takie jak: OSCE, OSWE, CEH, LPT, inne Własne CVE – jeśli posiadasz opublikowane, prześlij je wraz z aplikacją Oferujemy: Zatrudnienie na podstawie umowy o pracę Premie półroczne uzależnione od poziomu realizacji celów Praca w modelu hybrydowym Możliwość zdobycia doświadczenia zawodowego poprzez realizację ciekawych zadań w branży telekomunikacyjnej Pakiet świadczeń socjalnych (opieka medyczna w tym pakiet stomatologiczny i swoboda leczenia, karnet sportowy) Benefity socjalne i oferty pracownicze Elastyczne godziny rozpoczęcia pracy Parking dla pracowników JAK WYGLĄDA PROCES REKRUTACYJNY? Przeanalizujemy Twoją aplikację Jeśli Twoje kompetencje wpiszą się w nasze oczekiwania spodziewaj się telefonu od Marty z zespołu HR Jeśli pozytywnie przejdziesz rozmowę czeka Cię spotkanie online na platformie ZOOM z przełożonym - Markiem- Dział Architektury i Zaawansowanych Usług Bezpieczeństwa​ oraz Martą - HR Business Partner Informację zwrotną otrzymasz niezależnie od decyzji Wyślij swoje CV i dołącz do #teamEXATEL 🛰!

Technology

Jit Team

Penetration Testing

Senior

Hybrid

Krakow, Poland

1,100 - 1,360 PLN

🏢 Summary: Security Researcher role focused on penetration testing across hardware, software, cloud, mobile, and OT environments within a product security team. The position involves vulnerability research, exploitation, security assessments, and collaboration with engineering teams to ensure secure product development. Candidates will work with advanced security tools, conduct technical research, and prepare detailed security documentation. 🗂️ Requirements: Strong understanding of TCP/IP networking, Knowledge of application protocols, Knowledge of software exploitation techniques, Experience with common vulnerabilities, Hands-on experience with port scanning, Hands-on experience with fuzzing, Experience with vulnerability assessment tools, Knowledge of web technologies, Knowledge of web security risks, Familiarity with OWASP Top 10, Familiarity with SANS Top 25, Experience with mobile application security, Experience with APIs, Proficiency in Python or another scripting language, Knowledge of cryptographic protocols, Knowledge of security protocols, Experience with Metasploit, Experience writing custom exploits, Strong English communication skills 📃 Skills: TCP/IP, OWASP, SANS, Python, Metasploit, Fuzzing, APIs, Cryptography, Portscanning, Exploitation, Networking, Bluetooth, NFC, UART, JTAG, I2C, Firmware, Reverseengineering 🏢 Description: Project We are looking for a skilled Security Researcher to join a Cybersecurity Assurance Center, part of a product security team responsible for penetration testing across a wide range of products . In this role, you will work on cutting-edge cybersecurity challenges , ensuring that products are secure before they reach the market. Key Responsibilities Perform penetration testing across hardware, software, cloud, mobile and OT environments Identify, analyze and exploit vulnerabilities to prevent security issues before release Collaborate closely with engineering teams to support a security-by-design approach Use and develop advanced security tools, including custom cryptographic and reverse engineering solutions Conduct research on emerging technologies, protocols and potential attack vectors Prepare detailed technical reports and documentation Participate in knowledge-sharing sessions and technical discussions Required Skills & Experience Strong understanding of TCP/IP networking and application protocols Solid knowledge of software exploitation techniques and common vulnerabilities Hands-on experience with port scanning, fuzzing, and vulnerability assessment tools Knowledge of web technologies and related security risks Familiarity with OWASP Top 10 and SANS Top 25 Experience with mobile application security and APIs Proficiency in at least one scripting language (e.g. Python ) Good knowledge of cryptographic and security protocols Experience using tools like Metasploit and writing custom exploits Strong English communication skills (written and spoken) Nice to Have Experience with reverse engineering and binary analysis Knowledge of hardware exploitation (UART, JTAG, I2C, firmware extraction) Understanding of wireless technologies (RF, Bluetooth, NFC) Responsibilities Perform penetration testing on various systems, including hardware, software, cloud, mobile, and OT environmentsIdentify, analyze, and exploit vulnerabilities to improve product security before release Collaborate with engineering teams to support secure development practices Conduct vulnerability assessments, fuzz testing, and port scanning Research new technologies, communication protocols, and associated security risks Prepare detailed technical reports and internal documentation Participate in knowledge-sharing and technical discussions Use and develop advanced security tools, including custom-built solutions Client – why choose this particular client from the Jit portfolio? Our Client is an established global technology leader driving the digital transformation and innovation required to accelerate the transition toward a carbon-neutral future . Serving customers across the utility, industry, and infrastructure sectors, they provide cutting-edge solutions and services across the entire energy value chain. The organization is actively evolving the worlds energy systems to make them more sustainable, flexible, and secure, while precisely balancing social, environmental, and economic value. With a proven track record and an unparalleled installed technological base spanning well over 100 countries, the company operates on a massive global scale.