Unlock Full Resume Report

New offer - be the first one to apply!

September 2, 2026

Global Service Lead of Penetration Test

Senior • On-site

Kraków, MA, Poland

Within the EMEA IT Risk and Cybersecurity Office, part of the IT Directorate of Corporate and Investment Bank (CIB), you will be part of the CIB Ethical Hacking team.

You will play a key role in ensuring the seamless delivery of pentest campaigns for CIB across all pentest services: Applications, API, Infrastructure, and Mobile. You will contribute to the identification and remediation of vulnerabilities in CIB systems and to the overall security level of CIB, with support from regional relays.

Global Service Lead of Penetration Test

Responsibilities

  • Oversee and maintain the highest level of service quality and ensure coordination for CIB worldwide, while controlling pentest compliance with internal policies and regulatory requirements, with support from regional relays and AMER/APAC pentest coordination and delivery teams.
  • Provide strategic direction and directly manage the operations of the EMEA pentest coordination team, managed by the EMEA Pentest Coordination Team Lead, to ensure timely delivery, quality, technical reviews, and coordination of pentests delivered for EMEA.
  • Assure risk-based testing prioritization and threat-model alignment.
  • Lead the formalization of an annual pentest book of work and ensure its validation by relevant stakeholders for CIB worldwide, with support from regional relays.
  • Oversee CIB global pentest budget consolidation to ensure appropriate use of the budget in line with CIB needs and priorities.
  • Perform performance reviews of external and internal pentest suppliers to drive continuous improvement of the service.
  • Oversee and maintain data quality in reporting tools; ensure production of measures, KPIs, and KRIs; provide regular updates with support from regional relays; support internal and external audit reporting; and follow KPIs, KRIs, and controls required by CIB procedures.
  • Propose and implement improvements to processes and service-delivery KPIs/KRIs to advance the efficiency and governance of the global service.

Requirements

  • At least 8–10 years of experience in a similar pentest service-delivery position.
  • Strong experience in pentesting and related cybersecurity practices.
  • Strong experience in service delivery and team management within worldwide organizations.
  • Problem-solving mindset and hands-on experience implementing international processes and procedures.
  • Ability to manage or facilitate meetings and committees, with confidence presenting to C-suite and regulatory bodies.
  • Ability to collaborate with and coordinate services for teams operating across multiple countries.
  • Excellent written and verbal English communication skills.
  • Bachelor’s degree or equivalent experience in Computer Science or Cybersecurity.
  • At least one of the following certifications: OSCP, OSCE, CREST-CRT, CREST+CCT, CISSP, CISM, GIAC GPEN, or equivalent.

Additional assets

  • Experience in banking or financial services, particularly in a global investment bank.
  • Strategic, risk-based thinking using data and metrics to support decision-making.

Nice to have

  • Experience advising a CISO or participating in a risk-steering committee.
  • Hands-on red-team or purple-team expertise, threat modeling, or exploit development.

Benefits

  • Hybrid work mode.
  • Equivalent for remote work expenses: 120 PLN per month.
  • Stable employment in an international company.
  • Fully paid private medical care for the employee.
  • Pre-paid lunch card.
  • Employee Pension Plan.
  • Co-financed Multisport Card.
  • MyBenefit Cafeteria Platform.
  • Life insurance.
  • Car parking available in the office building.
  • Training and development opportunities.

Similar jobs you might like