Unlock Full Resume Report

New offer - be the first one to apply!

September 4, 2026

Pentester WebAPP and API

Senior • Remote

130 - 140 PLN/yr

Warsaw, MZ, Poland

Key Responsibilities (What You’ll Do)

Advanced Technical Testing

  • Personally lead and execute end-to-end penetration tests across web applications, APIs, mobile apps (iOS/Android), cloud environments, and internal/external networks.

Deep Active Directory Assessments

  • Perform sophisticated AD security testing, including privilege escalation, lateral movement, delegation/ACL abuse, and attack path analysis.

Exploit Development

  • Write custom scripts, tooling, and proof-of-concept (PoC) exploits using Python, PowerShell, and/or Bash.

End-to-End Engagement Management

  • Own the lifecycle of assignments—from initial scoping and effort estimation to final report delivery and remediation retesting.

Quality Assurance & Pre-Sales

  • Review and QA technical findings/reports from the team, and provide technical input during scoping calls and proposal creation.

Client & Stakeholder Communication

  • Act as the primary technical point of contact, translating complex technical risks into clear insights for both developers and non-technical executives.

Required Skills & Experience (What You’ll Need)

Experience

  • Approximately 5+ years of hands-on offensive security experience, ideally within a cybersecurity consultancy or multi-client delivery environment.

Core Depth

  • Proven expertise in at least three domains: web applications, network, mobile, or Active Directory testing.

Tooling Infrastructure

  • Mastery of industry-standard tools: Burp Suite, Nmap, Metasploit, BloodHound, Impacket, CrackMapExec/NetExec, Cobalt Strike, Frida, and others.

Certifications

  • Minimum of one required: OSCP (Offensive Security Certified Professional); CRTP / CRTO (Active Directory/Red Team); CREST CRT / CPSA.
  • CCT App or Infra strongly preferred.

Soft Skills

  • Exceptional report-writing skills and fluent professional English.

Highly Desirable / Nice to Have

  • Advanced certifications: OSEP, OSWE, OSED, CRTE, SANS GXPN/GWAPT, or cloud offensive certifications.
  • Prior experience within a Big 4 firm or an established boutique security consultancy.
  • Hands-on exposure to AWS, Azure, or GCP cloud environments and Kubernetes/containers.
  • Active community presence through published research, CVEs, open-source tooling contributions, conference talks, or top CTF achievements.

Similar jobs you might like