Unlock Full Resume Report

New offer - be the first one to apply!

September 3, 2026

Penetration Tester - WebAPP and API

Senior • Remote

960 - 1,320 PLN/yr

Krakow, Poland

For the project carried out with a partner, we are looking for a Penetration Tester - WebAPP and API.

Responsibilities

  • Lead end-to-end penetration tests and remediation retests.
  • Perform advanced Active Directory assessments, including privilege escalation, lateral movement, and attack path analysis.
  • Develop custom scripts and PoC exploits using Python, PowerShell, or Bash.
  • Manage engagements from scoping and estimation to reporting.
  • Review technical findings and support pre-sales activities.
  • Communicate risks and recommendations to technical and non-technical stakeholders.

Requirements

  • 4+ years of hands-on offensive security experience, preferably in a cybersecurity consultancy or multi-client environment.
  • Strong expertise in at least three areas: web/API, network, mobile, or Active Directory testing.
  • Ability to independently lead penetration testing engagements—from scoping and estimation to reporting and remediation retesting.
  • Advanced proficiency with Burp Suite, Nmap, Metasploit, BloodHound, Impacket, NetExec, Cobalt Strike, and Frida.
  • Experience developing scripts and PoC exploits using Python, PowerShell, or Bash.
  • Strong client-facing, technical reporting, and stakeholder communication skills.
  • At least one certification: OSCP, CRTP, CRTO, CREST CRT, CPSA, CCT App, or CCT Infra.
  • Very good English and Polish.

What we offer

  • Small team.
  • International working environment and international projects.
  • Private medical care.
  • Sports card.
  • Training courses.
  • 100% remote work, with an office available in Krakow for those who prefer another work arrangement.

Recruitment process

  • Friendly remote initial interview.
  • Remote technical talk.
  • Decision to work together.

Similar jobs you might like