July 11, 2026

Penetration Testing

Senior • Hybrid

1,100 - 1,360 PLN

Krakow, Poland

Project

We are looking for a skilled Security Researcher to join a Cybersecurity Assurance Center, part of a product security team responsible for penetration testing across a wide range of products.

In this role, you will work on cutting-edge cybersecurity challenges, ensuring that products are secure before they reach the market.

 

Key Responsibilities

  • Perform penetration testing across hardware, software, cloud, mobile and OT environments

  • Identify, analyze and exploit vulnerabilities to prevent security issues before release

  • Collaborate closely with engineering teams to support a security-by-design approach

  • Use and develop advanced security tools, including custom cryptographic and reverse engineering solutions

  • Conduct research on emerging technologies, protocols and potential attack vectors

  • Prepare detailed technical reports and documentation

  • Participate in knowledge-sharing sessions and technical discussions

Required Skills & Experience

  • Strong understanding of TCP/IP networking and application protocols

  • Solid knowledge of software exploitation techniques and common vulnerabilities

  • Hands-on experience with port scanning, fuzzing, and vulnerability assessment tools

  • Knowledge of web technologies and related security risks

  • Familiarity with OWASP Top 10 and SANS Top 25

  • Experience with mobile application security and APIs

  • Proficiency in at least one scripting language (e.g. Python)

  • Good knowledge of cryptographic and security protocols

  • Experience using tools like Metasploit and writing custom exploits

  • Strong English communication skills (written and spoken)

Nice to Have

  • Experience with reverse engineering and binary analysis

  • Knowledge of hardware exploitation (UART, JTAG, I2C, firmware extraction)

  • Understanding of wireless technologies (RF, Bluetooth, NFC)

 

Responsibilities

  • Perform penetration testing on various systems, including hardware, software, cloud, mobile, and OT environmentsIdentify, analyze, and exploit vulnerabilities to improve product security before release

  • Collaborate with engineering teams to support secure development practices

  • Conduct vulnerability assessments, fuzz testing, and port scanning

  • Research new technologies, communication protocols, and associated security risks

  • Prepare detailed technical reports and internal documentation

  • Participate in knowledge-sharing and technical discussions

  • Use and develop advanced security tools, including custom-built solutions

 

Client – why choose this particular client from the Jit portfolio?

Our Client is an established global technology leader driving the digital transformation and innovation required to accelerate the transition toward a carbon-neutral future. Serving customers across the utility, industry, and infrastructure sectors, they provide cutting-edge solutions and services across the entire energy value chain. The organization is actively evolving the worlds energy systems to make them more sustainable, flexible, and secure, while precisely balancing social, environmental, and economic value.

With a proven track record and an unparalleled installed technological base spanning well over 100 countries, the company operates on a massive global scale.

Similar jobs you might like

Technology

TechTree

Software Engineer

Mid

Remote

Warsaw, Poland

47,300 - 64,500 EUR

🏢 Summary: Software Engineer role on the Client team building secure browser extensions, desktop applications, CLI tools and SDKs for a global cybersecurity product. The position focuses on client-side engineering in a zero-trust, end-to-end encrypted environment with strong ownership across the full development lifecycle. Ideal for engineers who enjoy solving complex product and security challenges while contributing to open-source and high-quality software at scale. 🗂️ Requirements: 3+ years of experience building JavaScript applications in production, Strong client-side engineering experience with React or similar framework, Ability to design simple, robust solutions to complex problems, Experience writing and maintaining unit, integration and end-to-end tests, Ability to implement secure client-side business logic and data handling, Comfort collaborating across product, design and engineering, Interest in security, privacy or trustworthy software systems 📃 Skills: JavaScript, React, HTML, CSS, Storybook, Jest, WebdriverIO, OpenPGP, Git, Docker, Windows, macOS, Linux 🏢 Description: THE CLIENT Our client is a fast-growing cybersecurity product company rethinking how teams manage and share sensitive access. Their platform is trusted by 40,000+ organisations across 50+ countries - and growing fast. This is an engineering-led business: modern architecture, real technical challenges, and a strong focus on open source, privacy, and security. They’re building a fully remote, collaborative team and looking for engineers who take ownership and enjoy solving meaningful problems. If you want to work on a product with real impact at global scale - this is worth a conversation. THE ROLE: Our client is looking for a software engineer to join its Client team and help build the applications through which users experience the product, including browser extensions, desktop applications, command-line tools and SDKs. This is not a typical frontend role. Because their product is built around end-to-end encryption and a zero-trust model, their client applications carry significant responsibility for security, data handling and product behaviour. The role sits at the intersection of client engineering, product thinking, usability and security-sensitive application design. You would work on features used by a large open-source community, contributing across the full lifecycle: understanding the problem, shaping the approach, implementing the solution, testing it thoroughly and improving it over time. This role will suit someone who enjoys solving complex product problems, keeping solutions simple, and working in an environment where quality, openness and collaboration matter. RESPONSIBILITIES: Build and improve client applications across browser, desktop and adjacent client surfaces Translate product and user needs into secure, usable client-side solutions Implement and maintain business logic, local data handling and security-sensitive workflows on the client side Contribute to testing strategy across unit, integration and end-to-end levels Work closely with product, design and engineering peers to refine solutions before implementation Help improve code quality, performance, maintainability and documentation Contribute to open-source collaboration with the community where relevant CORE REQUIREMENTS 3+ years of experience building JavaScript applications in production Strong client-side engineering fundamentals with React or a similar framework Ability to break down complex problems and design simple, robust solutions Good testing habits and attention to quality Comfort working across product, engineering and implementation questions - not just coding tickets Strong collaboration skills, openness to feedback, and a low-ego working style Interest in security, privacy, or building trustworthy software systems NICE TO HAVE Experience building browser extensions, desktop applications or other multi-platform clients Experience with security-sensitive applications, client-side cryptography or zero-trust architectures Experience with design systems, Storybook or usability-focused product development Open-source contribution experience Experience maintaining long-lived software products Familiarity with other languages such as Go, Swift, C#, PHP, Python or Rust Tools and technologies you’ll work with: JavaScript, React, HTML/CSS, Storybook, Jest, WebdriverIO, OpenPGP-related tooling, Git and Docker across Windows, macOS and Linux environments. (We do not expect candidates to bring experience with every tool listed here) How you work You take ownership of problems, not just tasks You value simplicity and avoid over-engineering You work well in an environment where feedback is frequent and constructive

Technology

TechTree

Software Engineer

Mid

Remote

Warsaw, Poland

47,300 - 64,500 EUR

🏢 Summary: Software Engineer role focused on building and improving secure client applications including browser extensions, desktop apps, CLI tools and SDKs within a zero-trust, end-to-end encrypted product. The position combines client-side engineering, security-sensitive design and product thinking, contributing across the full development lifecycle. You will deliver secure, high-quality solutions used by a large global and open-source community. 🗂️ Requirements: 3+ years of production experience with JavaScript, Strong experience with React or similar framework, Solid client-side engineering fundamentals, Experience designing simple, robust solutions for complex problems, Hands-on experience with unit, integration and end-to-end testing, Ability to implement secure client-side data handling and business logic, Experience collaborating across product, design and engineering teams, Interest in security, privacy or secure software systems 📃 Skills: JavaScript, React, HTML, CSS, Storybook, Jest, WebdriverIO, OpenPGP, Git, Docker, Windows, macOS, Linux 🏢 Description: THE CLIENT Our client is a fast-growing cybersecurity product company rethinking how teams manage and share sensitive access. Their platform is trusted by 40,000+ organisations across 50+ countries - and growing fast. This is an engineering-led business: modern architecture, real technical challenges, and a strong focus on open source, privacy, and security. They’re building a fully remote, collaborative team and looking for engineers who take ownership and enjoy solving meaningful problems. If you want to work on a product with real impact at global scale - this is worth a conversation. THE ROLE: Our client is looking for a software engineer to join its Client team and help build the applications through which users experience the product, including browser extensions, desktop applications, command-line tools and SDKs. This is not a typical frontend role. Because their product is built around end-to-end encryption and a zero-trust model, their client applications carry significant responsibility for security, data handling and product behaviour. The role sits at the intersection of client engineering, product thinking, usability and security-sensitive application design. You would work on features used by a large open-source community, contributing across the full lifecycle: understanding the problem, shaping the approach, implementing the solution, testing it thoroughly and improving it over time. This role will suit someone who enjoys solving complex product problems, keeping solutions simple, and working in an environment where quality, openness and collaboration matter. RESPONSIBILITIES: Build and improve client applications across browser, desktop and adjacent client surfaces Translate product and user needs into secure, usable client-side solutions Implement and maintain business logic, local data handling and security-sensitive workflows on the client side Contribute to testing strategy across unit, integration and end-to-end levels Work closely with product, design and engineering peers to refine solutions before implementation Help improve code quality, performance, maintainability and documentation Contribute to open-source collaboration with the community where relevant CORE REQUIREMENTS 3+ years of experience building JavaScript applications in production Strong client-side engineering fundamentals with React or a similar framework Ability to break down complex problems and design simple, robust solutions Good testing habits and attention to quality Comfort working across product, engineering and implementation questions - not just coding tickets Strong collaboration skills, openness to feedback, and a low-ego working style Interest in security, privacy, or building trustworthy software systems NICE TO HAVE Experience building browser extensions, desktop applications or other multi-platform clients Experience with security-sensitive applications, client-side cryptography or zero-trust architectures Experience with design systems, Storybook or usability-focused product development Open-source contribution experience Experience maintaining long-lived software products Familiarity with other languages such as Go, Swift, C#, PHP, Python or Rust Tools and technologies you’ll work with: JavaScript, React, HTML/CSS, Storybook, Jest, WebdriverIO, OpenPGP-related tooling, Git and Docker across Windows, macOS and Linux environments. (We do not expect candidates to bring experience with every tool listed here) How you work You take ownership of problems, not just tasks You value simplicity and avoid over-engineering You work well in an environment where feedback is frequent and constructive

Technology

Experis Manpower Group

API Pentester

Senior

Remote

Wroclaw, Poland

170 - 180 PLN

🏢 Summary: Hands-on senior offensive security role leading penetration testing engagements across web, network, mobile, cloud, and Active Directory environments. The position combines technical delivery, client interaction, reporting, and mentoring responsibilities within consulting-style engagements. Candidates are expected to have advanced penetration testing experience, scripting skills, and recognized offensive security certifications. 🗂️ Requirements: 5+ years of hands-on penetration testing or offensive security experience, Experience in consulting or client-facing security engagements, Expertise in at least three areas: web, network, mobile, or Active Directory security testing, Experience with offensive security and penetration testing tools, Scripting skills in Python, PowerShell, or Bash, Strong communication and technical reporting skills, At least one certification: OSCP, CREST CRT/CPSA, CRTP, or CRTO 📃 Skills: BurpSuite, Nmap, Metasploit, BloodHound, Impacket, CobaltStrike, Nessus, OpenVAS, Frida, MobSF, Python, PowerShell, Bash, AWS, Azure, GCP, Kubernetes 🏢 Description: Join our Offensive Security team and lead penetration testing engagements for clients across financial services, technology, healthcare, government, and critical infrastructure sectors. This is a hands-on role for an experienced security professional who wants to remain highly technical while taking ownership of project delivery, client relationships, and mentoring junior consultants. Key Responsibilities: Lead and perform penetration tests across web applications, APIs, internal/external networks, mobile applications, cloud environments, and Active Directory. Conduct advanced Active Directory security assessments and infrastructure testing. Develop custom scripts, tooling, and proof-of-concept exploits. Manage engagements from scoping to reporting and remediation validation. Present findings to technical and business stakeholders. Support proposal development, effort estimation, and pre-sales activities. Mentor junior team members and contribute to internal methodologies and best practices. Required Experience: 5+ years of hands-on penetration testing or offensive security experience, ideally within a consulting environment. Strong expertise in at least three of the following: web, network, mobile, or Active Directory security testing. Experience with tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Cobalt Strike (or similar), Nessus/OpenVAS, Frida, and MobSF. Scripting skills in Python, PowerShell, or Bash. Strong communication, reporting, and client-facing skills. Certifications: At least one of: OSCP CREST CRT/CPSA CRTP or CRTO Nice to Have: Big 4 or cybersecurity consultancy experience. Cloud security testing (AWS, Azure, GCP). Kubernetes/container security knowledge. Security research, CVEs, conference talks, or CTF achievements. Offer: Multisport Card Life insurance Private healthcare PowerYou platform

Technology

DataArt

Penetration Tester

Mid

Remote

Wroclaw, Poland

12,000 - 15,000 PLN

🏢 Summary: The offer is for a Middle Penetration Tester responsible for conducting network and application-level security assessments using automated and manual techniques. The role involves identifying and validating vulnerabilities, preparing detailed reports, collaborating with clients, and contributing to internal security tools and processes. The position focuses on strengthening security posture through structured testing methodologies and technical research. 🗂️ Requirements: Minimum 1 year of experience in vulnerability assessments and penetration testing, Minimum 3 years of experience in IT industry, Experience with Linux, Windows, Active Directory, JavaScript, .NET, SQL, Experience applying structured penetration testing methodologies, Understanding of web application vulnerabilities, Ability to document vulnerabilities and remediation steps, Experience with Burp Suite, Nessus, Metasploit, Nmap, sqlmap, Knowledge of programming or scripting for security tools development 📃 Skills: Burp, Nessus, Metasploit, Nmap, sqlmap, Linux, Windows, ActiveDirectory, JavaScript, .NET, SQL, Scripting 🏢 Description: Project overview A security-focused initiative aimed at performing vulnerability assessments and penetration tests for a variety of digital systems. The project supports continuous improvement of security practices and contributes to the development of internal tools and methodologies. The work includes research activities, process enhancement, and collaboration with technical teams to strengthen the overall security posture. Team You will join a security-oriented team that consists of penetration testers, security analysts, and engineers. The team collaborates closely, shares knowledge, and supports research and internal tool development. Position overview We are looking for a Middle Penetration Tester who will be involved in network and application-level security assessments. You will use automated tools and manual techniques to identify and verify security vulnerabilities. This role includes preparing assessment reports, interacting with clients to clarify scope and gather information, and contributing to the improvement of security processes and tools. Technology stack Burp Suite, Nessus, Metasploit, Nmap, sqlmap, Linux, Windows, Active Directory, JavaScript, .NET, SQL, scripting languages Responsibilities Conduct network and application-level security assessments Use automated tools and manual techniques to identify and validate vulnerabilities Prepare clear and comprehensive assessment reports with root cause details and remediation steps Communicate with clients to gather information, clarify scope, and discuss security controls Support internal security competence development through research, tool creation, and process improvement Collaborate with other team members across security and engineering domains Requirements One year of experience performing vulnerability assessments and penetration tests Three years of experience in the IT industry with familiarity across technologies such as Linux, Windows, Active Directory, JavaScript, .NET, SQL Experience applying structured methodology for vulnerability assessments and penetration tests Understanding of web application vulnerabilities Ability to describe and report vulnerabilities along with typical remediation activities Experience with open source and commercial security tools, including Burp Suite, Nessus, Metasploit, Nmap, and sqlmap Knowledge of programming or scripting for creating auxiliary security tools Ability to work effectively with customers and self-manage in challenging situations Nice to have Security certifications, including OSCP, CRTO, CPTS, eWPT, BSCP Strong programming experience in a modern language Experience with mobile application penetration testing Experience with reverse engineering and binary analysis Experience publishing technical content or speaking at industry events Familiarity with security standards, including PCI DSS and ISO 27000

Technology

BLUE energy Sp. z o.o.

Tester Penetracyjny Aplikacji Web

Mid

Hybrid

Poznan, Poland

10,000 - 14,000 PLN

🏢 Summary: Offer for a Web Application Penetration Tester responsible for conducting manual and automated security testing of web applications for external clients. The role focuses on identifying and exploiting vulnerabilities, preparing detailed security reports, and advising on remediation. It involves working with recognized security tools and methodologies to ensure high application security standards. 🗂️ Requirements: Experience in web application penetration testing, Knowledge of web security vulnerabilities (XSS, SQL Injection, CSRF, RCE), Ability to use penetration testing tools (Burp Suite, OWASP ZAP, Nmap, Metasploit), Ability to analyze application code for security flaws, Understanding of web application architecture, Knowledge of OWASP and PTES methodologies, Ability to prepare technical security reports, Relevant security certifications (e.g. CEH, OSCP, CISSP, GWAPT) 📃 Skills: BurpSuite, OWASPZAP, Nmap, Metasploit, XSS, SQLInjection, CSRF, RCE, JavaScript, PHP, Python, OWASP, PTES, CEH, OSCP, CISSP, GWAPT 🏢 Description: Jako firma konsultingowa specjalizująca się w bezpieczeństwie IT, poszukujemy Testera Penetracyjnego Aplikacji Web , który dołączy do naszego zespołu. Osoba na tym stanowisku będzie odpowiedzialna za realizację testów penetracyjnych aplikacji webowych w ramach projektów dla naszych zewnętrznych klientów. Będziesz pracować nad identyfikowaniem luk w zabezpieczeniach aplikacji, wspierając naszych klientów w zapewnianiu najwyższego poziomu bezpieczeństwa ich systemów. Zakres obowiązków: Realizacja testów penetracyjnych aplikacji webowych dla różnych klientów, w tym identyfikowanie i eksploatowanie luk w zabezpieczeniach Audytowanie aplikacji pod kątem zagrożeń takich jak XSS, SQL Injection, CSRF, RCE i innych typowych wektorów ataków Przeprowadzanie testów manualnych oraz automatycznych przy użyciu narzędzi takich jak Burp Suite, OWASP ZAP, Metasploit, itp. Przygotowywanie szczegółowych raportów z przeprowadzonych testów, w tym rekomendacji dotyczących poprawy zabezpieczeń Współpraca z zespołami deweloperskimi klientów, doradztwo w zakresie implementacji poprawek bezpieczeństwa Udział w analizach ryzyka i opracowywanie zaleceń dla klientów w zakresie bezpieczeństwa aplikacji webowych Wymagania: Doświadczenie w przeprowadzaniu testów penetracyjnych aplikacji webowych, w tym znajomość narzędzi i metod wykorzystywanych w tej dziedzinie (Burp Suite, OWASP ZAP, Nmap, Metasploit, itp.) Doskonała znajomość zagrożeń związanych z bezpieczeństwem aplikacji webowych (XSS, SQL Injection, CSRF, RCE, itp.) Umiejętność analizowania kodu aplikacji i identyfikowania potencjalnych luk w zabezpieczeniach Dobre rozumienie architektury aplikacji webowych i technologii wykorzystywanych w aplikacjach (JavaScript, PHP, Python, itp.) Umiejętności raportowania i przedstawiania wyników testów w sposób zrozumiały dla osób nietechnicznych (np. menedżerowie projektów, klienci) Certyfikaty z zakresu bezpieczeństwa (np. CEH, OSCP, CISSP, GWAPT) będą dodatkowym atutem Praktyczna znajomość metodologii testowania oraz standardów bezpieczeństwa (np. OWASP, PTES) Umiejętność pracy w zespole, komunikatywność oraz umiejętność pracy z klientami Oferujemy: Pracę nad interesującymi projektami z zakresu bezpieczeństwa aplikacji webowych dla klientów z różnych branż Atrakcyjne wynagrodzenie oraz pakiet benefitów (m. in. Multisport, ubezpieczenie i pakiet medyczny) Możliwość rozwoju zawodowego i certyfikacji w zakresie bezpieczeństwa IT Współpracę z zespołem ekspertów oraz wsparcie w realizacji wyzwań technicznych Elastyczne godziny pracy oraz możliwość pracy zdalnej lub hybrydowej Jeśli jesteś pasjonatem bezpieczeństwa aplikacji webowych i chcesz dołączyć do naszego zespołu, zapraszamy do aplikowania!

Technology

The Nuclear Company

Staff Application Security Engineer

Senior

On-site

Washington, DC

150,000 - 173,004 USD/yr

🏢 Summary: The role focuses on securing modern applications, APIs, cloud workloads, and developer workflows within a nuclear energy environment. You will embed security into the SDLC, perform threat modeling and code reviews, harden CI/CD pipelines, and collaborate across engineering teams to manage vulnerabilities and protect sensitive data. This position combines hands-on application security, DevSecOps, and cloud security responsibilities in a regulated, mission-critical context. 🗂️ Requirements: 4+ years experience in application, product, or software security, Hands-on experience securing web applications, APIs, distributed systems, or cloud-native services, Strong knowledge of application security risks (authentication, authorization, injection, SSRF, insecure deserialization, secrets exposure, API security), Experience with secure SDLC tools (SAST, SCA, secret scanning, CI/CD security), Ability to read code in at least one language: Python, TypeScript, Go, Java, C#, or C++, Familiarity with AWS security concepts (IAM, encryption, logging, networking, secrets management, infrastructure-as-code), Experience performing threat modeling and security reviews, Understanding of offensive security principles 📃 Skills: Python, TypeScript, Go, Java, C#, C++, AWS, IAM, CodeQL, Dependabot, SAST, SCA, CI/CD, GitHub, OWASP, NIST, SOC2, IEC62443, NERCCIP 🏢 Description: About the role The Nuclear Company is searching for an Application Security Engineer to help secure the software, data systems, and developer workflows that power our Nuclear Operating System, internal platforms, and mission-critical applications. This is a high-ownership role for a builder who is equally comfortable reviewing application architecture, threat modeling APIs, improving GitHub security controls, and partnering directly with engineers to ship secure software quickly. You will work across product engineering, platform engineering, data science, infrastructure, and operations to embed security into the way we design, build, test, and deploy software. You will help define secure development standards, review high-impact product designs, harden CI/CD workflows, and guide teams through vulnerability remediation in a practical, risk-based way. This role reports to the Senior Manager for Application and Product Security. Responsibilities Application & Product Security - Perform security reviews and threat models for NOS modules, internal tools, APIs, data workflows, AI-enabled features, and cloud-connected applications. - Identify and remediate risks across authentication, authorization, tenant isolation, input validation, secrets handling, encryption, logging, and data access. - Review application designs and code changes for security issues before production. - Define reusable security patterns for web applications, APIs, mobile workflows, internal platforms, and data-heavy systems. - Establish secure-by-default approaches for applications supporting regulated, high-consequence infrastructure. Secure SDLC & Developer Enablement - Build and improve DevSecOps practices across the GitHub-based SDLC, including code scanning, dependency review, secret scanning, branch protections, CI/CD hardening, and secure workflows. - Create secure templates, checklists, automation, documentation, and lightweight review processes. - Triage and prioritize findings from SAST, SCA, secret scanning, penetration tests, code reviews, and internal assessments. - Develop vulnerability management workflows, remediation guidance, and engineering metrics. - Support secure coding education through design reviews, documentation, and developer partnership. Platform, Cloud & Data Security - Secure AWS workloads, infrastructure-as-code, service integrations, data pipelines, and deployment workflows. - Review integrations involving Palantir Foundry, partner APIs, internal data platforms, and AI-assisted engineering workflows. - Secure sensitive data flows across application, platform, and operational environments. - Ensure application events, audit logs, and security signals support investigation and response. - Navigate cybersecurity expectations within a regulated nuclear energy environment. Cross-Functional Partnership - Partner with software engineers, product managers, data engineers, infrastructure teams, and stakeholders. - Communicate risk clearly while balancing security and delivery speed. - Contribute to the application and product security roadmap as systems scale. - Help build a culture of ownership, velocity, and technical rigor. Experience - 4+ years in application security, product security, software security, or software engineering with strong security focus. - Experience securing modern software systems including web applications, APIs, distributed systems, or cloud-native services. - Strong understanding of authentication, authorization, access control, injection, insecure deserialization, SSRF, secrets exposure, dependency risk, and API security. - Experience with GitHub Advanced Security, CodeQL, Dependabot, SAST, SCA, secret scanning, and CI/CD security. - Ability to read at least one modern programming language (Python, TypeScript, Go, Java, C#, or C++). - Familiarity with AWS security concepts including IAM, logging, encryption, networking, secrets management, and infrastructure-as-code. - Strong communication skills and offensive security mindset. Preferred Qualifications - Experience securing software in regulated or mission-critical environments. - Familiarity with AI-assisted development tools, LLM-enabled applications, prompt injection risks, and AI supply chain concerns. - Experience with vulnerability management, penetration testing, DAST tools, or incident response. - Familiarity with OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, NIST CSF, NIST 800-53, SOC 2, IEC 62443, or NERC CIP. - Security certifications such as AWS Certified Security – Specialty or OSWE. - Interest in nuclear energy and critical infrastructure. Benefits - Competitive compensation packages - 401k with company match - Medical, dental, vision plans - Generous vacation policy plus holidays Estimated Starting Salary Range The estimated starting salary range for this role is $150,000 - $173,000 annually, less applicable withholdings and deductions, paid on a bi-weekly basis. The actual salary offered may vary based on experience, qualifications, tenure, skill set, availability of qualified candidates, geographic location, certifications, and other relevant factors. EEO Statement The Nuclear Company is an equal opportunity employer committed to fostering an inclusive workplace. Equal employment opportunities are provided without regard to protected characteristics. Discrimination in any aspect of employment is prohibited. Export Control Certain positions may involve access to information and technology subject to U.S. export controls. Compliance requirements may limit consideration of some applicants.

Technology

drEryk

Cybersecurity Engineer (F/M)

Senior

Hybrid

Krakow, Poland

18,200 - 23,520 PLN

🏢 Summary: Technical SOC role combining operational cybersecurity with compliance and security standards management. The position focuses on SIEM/SOAR development, incident handling (L2/L3), vulnerability management, and ensuring compliance with ISO 27001, NIS2, and related regulations. It also includes internal audits, risk assessment, documentation, and cooperation with external institutions such as CSIRT. 🗂️ Requirements: Minimum 3 years experience in cybersecurity (SOC or security management), Valid cybersecurity certification (CISSP, GSEC, GCIH, SSCP), Practical experience with SIEM systems, Experience with vulnerability scanning tools, Experience in implementing or auditing ISO27001 or NIS2, Knowledge of network protocols, Knowledge of Windows and Linux systems, Experience in log analysis, Ability to create security procedures and documentation, Experience in conducting security trainings 📃 Skills: SIEM, SOAR, ISO27001, ISO22301, NIS2, RODO, CISSP, GSEC, GCIH, SSCP, Windows, Linux, VulnerabilityScanning, LogAnalysis, RiskAssessment, Auditing, CSIRT 🏢 Description: Poszukujemy specjalistki/y, która/który połączy kompetencje techniczne z zakresu Security Operations Center (SOC) z wiedzą o standardach bezpieczeństwa. Na tym stanowisku będziesz odpowiedzialna/y za wdrażanie i utrzymanie procedur bezpieczeństwa oraz zapewnianie zgodności z kluczowymi regulacjami. Twoje obowiązki: Konfiguracja i rozwój systemów np. SIEM/SOAR, analiza incydentów (L2/L3), aktywne poszukiwanie ukrytych cyberzagrożeń, zarządzanie podatnościami; Udział w projektach wdrażania usług SOC oraz w audytach zgodności (ISO 27001/22301, NIS 2, RODO); Tworzenie i aktualizacja dokumentacji polityk, procedur bezpieczeństwa oraz raportów z audytów i testów; Tworzenie i aktualizacja dokumentacji polityk, procedur reakcji na incydenty oraz raportów zgodności; Zarządzanie działaniami związanymi ze zdarzeniami dotyczącymi bezpieczeństwa informacji, procedowanie incydentów bezpieczeństwa informacji; Analizowanie informacji dotyczących przebiegu kluczowych projektów pod kątem zagrożeń dla systemu bezpieczeństwa informacji; Opracowywanie, prowadzenie i rozliczanie programu audytów wewnętrznych; Inicjowanie i koordynowanie działań mających na celu podnoszenie poziomu bezpieczeństwa informacji w Organizacji; Przeprowadzanie wewnętrznych szkoleń z zakresu cyberbezpieczeństwa; Udział w procesach związanych z szacowaniem ryzyka, w tym analizowanie jego wyników i udział w opracowywaniu planów postępowania z ryzykiem; Kontakt z instytucjami np. CSIRT. Nasze wymagania: Min. 3 lata doświadczenia w obszarze cyberbezpieczeństwa (SOC/zarządzanie bezpieczeństwem); Posiadanie globalnie respektowanych certyfikatów, np. CISSP, GSEC, GCIH, (ISC)² SSCP; Praktyczna znajomość systemów SIEM, narzędzi do skanowania podatności; Doświadczenie we wdrażaniu lub audycie norm (ISO 27001, NIS2); Podstawowa znajomość protokołów sieciowych, systemów operacyjnych (Windows, Linux) i analizy logów; Umiejętność tworzenia procedur i dokumentacji; Doświadczenie w prowadzeniu niezbędnych szkoleń / instrukcji w zakresie bezpieczeństwa; Samodzielność w realizacji zadań i inicjatywa w szukaniu rozwiązań; Komunikatywność, otwartość i umiejętność pracy zespołowej. Mile widziane: Znajomość i doświadczenie w pracy w metodykach zwinnych; Dodatkowy atut znajomość branży medycznej. Oferujemy: Zatrudnienie w oparciu o umowę o pracę lub umowa b2b; Możliwość rozwoju zawodowego – szkolenia, konferencje; Elastyczne godziny pracy oraz możliwość pracy zdalnej; Niezbędne narzędzia pracy; Naukę języka angielskiego; Opiekę medyczną LuxMed; Karnet Benefit Multisport; Możliwość przystąpienia do ubezpieczenia grupowego; Program rekomendacji pracowników; Nowoczesne biuro, spotkania integracyjne.

Technology

KUBO

Security Test Engineer

Mid

Hybrid

Katowice, SL, Poland

140 - 165 PLN/hr

🏢 Summary: Security Test Engineer role focused on validating and strengthening the security of industrial automation products and systems through comprehensive security testing and vulnerability analysis. The position involves white-box and black-box testing, firmware and protocol analysis, fuzzing, and development of automated security testing frameworks. It offers a hybrid B2B contract with competitive hourly rate and additional benefits. 🗂️ Requirements: Bachelor’s degree in Computer Science or related field, Hands-on experience with programming or scripting (preferably Python), Solid understanding of computer networking and troubleshooting, Knowledge of software security testing methodologies (white-box, black-box, fuzz testing, negative testing), English proficiency at minimum B2 level 📃 Skills: Python, Networking, Fuzzing, Reverseengineering, Wireshark, BurpSuite, IDAPro, Ghidra, Radare2, EthernetIP, CIP, Firmware, EmbeddedSystems 🏢 Description: Our client is a global technology leader specializing in industrial automation, digital transformation, and smart manufacturing solutions. We are looking for a Security Test Engineer to join a team responsible for strengthening the security of industrial automation products and systems. In this role, you will contribute to the development and execution of a comprehensive product security validation program, helping ensure the resilience of products against evolving cybersecurity threats. This position is ideal for a security-focused engineer who enjoys analyzing complex systems, uncovering vulnerabilities, and developing innovative testing approaches for embedded and industrial environments. Key responsibilities Execute white-box and black-box security testing as part of a structured product security validation program. Perform security assessments of industrial products and systems, including firmware, communication protocols, and device interfaces. Conduct protocol-level testing and validate industrial communication mechanisms. Analyze firmware and software binaries to identify security weaknesses, including reverse engineering activities when required. Design and execute fuzz testing and negative testing scenarios targeting device interfaces and communication protocols. Identify, validate, and document security vulnerabilities, including the creation of proof-of-concept (PoC) exploits when appropriate. Perform basic hardware-level security validation, including analysis of debug interfaces and physical access scenarios. Analyze test results, triage findings, and support root cause analysis together with development teams. Contribute to the development and maintenance of automated security testing frameworks and scripts, primarily in Python. Research emerging vulnerabilities, attack techniques, and threat trends relevant to industrial products and environments. Ideal candidate profile Bachelor’s degree in Computer Science or a related field. Hands-on experience with programming or scripting languages, preferably Python. Solid understanding of computer networking, including configuration and troubleshooting. Familiarity with software security testing methodologies, including fuzz testing, negative testing, and white-box/black-box testing. English communication skills min. B2 Nice to Have Experience with reverse engineering tools such as IDA Pro, Ghidra, or Radare2. Knowledge of industrial communication protocols, including Ethernet/IP and CIP. Experience testing embedded systems, firmware, or hardware devices. Knowledge of security testing tools such as Burp Suite and Wireshark. Conditions Contract type: B2B Rate: 140–165 PLN net/hour Work model: Hybrid (3 days per week from the office in Katowice) Benefits: private medical care, life insurance, Multisport card Recruitment steps Phone call with a Recruiter Client interview (may require 2 rounds) Feedback and decision

Technology

TSS

Tester Bezpieczeństwa

Mid

Remote

Warsaw, Poland

80 - 95 PLN

🏢 Summary: Role focused on conducting comprehensive security testing of web applications, APIs, and IT infrastructure, including penetration testing and vulnerability assessments. The position involves identifying security risks, simulating real-world attacks, and providing remediation recommendations in close collaboration with development teams. It requires hands-on use of professional security tools and active participation in code reviews and technical consultations. 🗂️ Requirements: Minimum 3 years of commercial experience in security testing, Experience in penetration testing and vulnerability scanning, Practical experience in manual web application security testing, Experience in API security testing, Experience in network infrastructure security assessment, Proficiency with Burp Suite, OWASP ZAP, Wireshark, SQLMap, Ability to identify vulnerabilities and assess security risks, Experience collaborating with development teams and participating in code reviews, Fluent Polish, Working knowledge of English for technical documentation 📃 Skills: BurpSuite, OWASPZAP, Wireshark, SQLMap, PenetrationTesting, VulnerabilityScanning, WebSecurity, APITesting, Networking, Cybersecurity, OWASP, Cloud, Agile, Scrum 🏢 Description: W TSS napędzamy cyfrową rewolucję. Tworzymy zaawansowane systemy i innowacyjne rozwiązania z zakresu Software Development, FinTech, AI oraz Cybersecurity. Zakres odpowiedzialności: Testy bezpieczeństwa aplikacji webowych: Planowanie, przygotowywanie i realizacja manualnych testów bezpieczeństwa aplikacji webowych, identyfikacja podatności oraz analiza ryzyk bezpieczeństwa. Testowanie API: Przeprowadzanie testów bezpieczeństwa interfejsów API, weryfikacja mechanizmów uwierzytelniania, autoryzacji oraz odporności na najczęściej występujące zagrożenia. Testy infrastruktury sieciowej: Ocena bezpieczeństwa infrastruktury IT, usług sieciowych oraz konfiguracji systemów pod kątem potencjalnych podatności. Testy penetracyjne: Realizacja testów penetracyjnych systemów i aplikacji, symulowanie rzeczywistych scenariuszy ataków oraz analiza skuteczności wdrożonych zabezpieczeń. Skanowanie podatności: Wykorzystywanie specjalistycznych narzędzi do wykrywania luk bezpieczeństwa, analiza wyników oraz przygotowywanie rekomendacji naprawczych. Wykorzystanie narzędzi bezpieczeństwa: Codzienna praca z narzędziami takimi jak Burp Suite, OWASP ZAP, Wireshark, SQLMap oraz innymi rozwiązaniami wspierającymi proces testów bezpieczeństwa. Współpraca z zespołem deweloperskim: Aktywna współpraca z programistami, architektami i analitykami w zakresie identyfikacji oraz eliminacji zagrożeń bezpieczeństwa, udział w code review i konsultacjach technicznych. Raportowanie i rekomendacje: Przygotowywanie raportów z przeprowadzonych testów, dokumentowanie wykrytych podatności oraz rekomendowanie działań naprawczych i usprawnień. Wymagania: Doświadczenie komercyjne: Minimum 3 lata doświadczenia w obszarze testów bezpieczeństwa obejmujących testy penetracyjne, skanowanie podatności oraz symulacje ataków. Testy bezpieczeństwa aplikacji: Praktyczne doświadczenie w manualnym testowaniu bezpieczeństwa aplikacji webowych, API oraz infrastruktury sieciowej. Narzędzia bezpieczeństwa: Bardzo dobra znajomość narzędzi takich jak Burp Suite , OWASP ZAP, Wireshark, SQLMap oraz innych rozwiązań wykorzystywanych w testach bezpieczeństwa. Znajomość zagadnień cyberbezpieczeństwa: Umiejętność identyfikowania podatności, analizowania ryzyk bezpieczeństwa oraz proponowania skutecznych działań naprawczych. Komunikacja i współpraca: Wysoko rozwinięte umiejętności komunikacyjne oraz doświadczenie we współpracy z zespołami deweloperskimi, w tym udział w code review i konsultacjach technicznych. Znajomość języków: Biegłe posługiwanie się językiem polskim w mowie i piśmie oraz znajomość języka angielskiego umożliwiająca efektywną pracę z dokumentacją techniczną. Dodatkowym atutem będzie: Znajomość standardów i metodyk bezpieczeństwa, w szczególności OWASP Top 10. Doświadczenie w testowaniu środowisk chmurowych oraz nowoczesnych architektur aplikacyjnych. Posiadanie certyfikatów branżowych związanych z bezpieczeństwem, np. eJPT, PNPT, OSCP, CEH lub pokrewnych. Doświadczenie w pracy w środowiskach Agile/Scrum. Otwartość na dzielenie się wiedzą oraz aktywne wspieranie rozwoju zespołu. Co zyskujesz, dołączając do teamu? Stabilność i elastyczność: Długofalową współpracę w oparciu o kontrakt B2B. Realny wpływ: Pracę nad kluczowymi projektami, gdzie Twoje rekomendacje i działania realnie wpływają na poziom bezpieczeństwa tworzonych rozwiązań. Zdrowie pod kontrolą: Dofinansowanie do prywatnej opieki medycznej w PZU. Stały rozwój: Dostęp do wewnętrznych, specjalistycznych szkoleń z zakresu m.in . cyberbezpieczeństwa. Środowisko entuzjastów: Pracę w zespole, gdzie pasja łączy się z profesjonalizmem, a dobra atmosfera to standard, nie benefit.

Technology

emagine Polska

Penetrationstester

Senior

On-site

Copenhagen, Denmark

🏢 Summary: Penetration tester role focused on conducting approximately 25 in-depth penetration tests of applications and networks within the public sector during 2026 (Q2–Q4). The assignment includes vulnerability analysis, retesting, and delivery of detailed technical reports in Danish. The consultant will test both legacy and modern technologies and present findings to stakeholders. 🗂️ Requirements: Proven experience with penetration testing in public sector environments, Strong knowledge of security research and vulnerability analysis, Experience performing application and network penetration tests, Ability to analyze complex systems and networks, Experience writing detailed technical security reports in Danish, Ability to communicate technical findings clearly, Experience with retesting and validation of vulnerabilities 📃 Skills: Penetrationtesting, Vulnerabilityanalysis, Securityresearch, Networksecurity, Applicationsecurity, OSCP, CEH, Scripting, Securityscanners, Reporting 🏢 Description: For en af vores kunder søger vi en dygtig Penetrationstester med erfaring inden for det statslige område til at udføre penetrationstests af diverse løsninger. 1.2 Beskrivelse af opgaven Formålet med gennemførelsen af pentests er at lave dybdegående afprøvning af sårbarheder, hvilke sammenholdes med de sårbarhedsscanninger, som kunden selv udfører løbende. Målet er at forsøge at bryde ind i en given applikation eller netværk, bl.a. gennem udnyttelsen af kendte sårbarheder og usikkert konfigurerede systemer. Der efterspørges en række pentests af applikationer, herunder flere højtprioriterede og gentests. Tests skal gennemføres i 2026 (Q2-Q4) efter en prioriteret rækkefølge aftalt mellem konsulenten og kunden. Opgavens omfang er i omegnen af 25 tests, og applikationerne spænder over både ældre og nyere teknologier. konsulenten skal derfor besidde en bred teknologisk viden og forståelse. Primære ansvarsområder Udførelse af pentests af høj kvalitet. Indsamling og analyse af sårbarheder. Dokumentation af fundne sårbarheder og deres alvorlighed. Udarbejdelse af teknisk, elektronisk rapport på dansk. Udførelse af mundtlig gennemgang af rapportens resultater. Gennemførelse af gentests af applikationer. Nøglekrav Solid erfaring med penetrationstests i det statslige område. Omfattende viden om sikkerhedsforskning og sårbarhedsanalyse. Evne til at kommunikere teknisk information klart og præcist. Erfaring med at udarbejde detaljerede tekniske rapporter. Færdigheder i at analysere komplekse systemer og netværk. Nice to Have Certificeringer inden for IT-sikkerhed (f.eks. OSCP, CEH). Kendskab til moderne programmeringssprog. Erfaring med automatiserede sikkerhedsscannere. Andre detaljer Testene er planlagt til 2026 og vil være delt over Q2 til Q4. Konsulenten vil modtage den nødvendige dokumentation og testbrugere for at udføre pentests effektivt.