Unlock Full Resume Report
ATS Pass
Missing keywords
Tailored AI suggestions
Job match analysis
Interview-focused insights
New offer - be the first one to apply!
September 6, 2026
Ethical Hacker/Pentester
Junior • Remote
13,000 - 18,000 PLN/yr
Kraków, Poland
Apply now
R&D on Multi-Factor Authentication Security
Research and development activities on multi-factor authentication security will enable the development of new solutions for passwordless multi-factor authentication. Conduct in-depth threat modeling and cryptographic analysis of authentication flows, prototype and validate next-generation passwordless methods such as WebAuthn/FIDO2 passkeys, and monitor emerging attack vectors. Work with product and engineering teams to translate research insights into production-ready features and publish security findings.
How You’ll Work
- Location: Remote or from offices in Kraków or Zielona Góra, Poland
- Assessment Targets & Tooling: Windows 10/11, Windows Server, Active Directory, Entra ID (Azure AD), Kerberos, NTLM, WebAuthn/FIDO2 passkeys, Linux servers; BloodHound, Mimikatz, Impacket, Metasploit, Responder, Nmap, and custom PowerShell/Python scripts
- Team: Work closely with security researchers/analysts and a project manager; coordinate priorities and share findings in weekly threat-hunting syncs
- Language: Communicate in Polish or English
- Hardware & Lab Access: Modern laptop, isolated virtual test environments, and security keys, including TPM-enabled devices and FIDO2 keys
- Self-development: Company-funded online courses and certification vouchers
- Employee Benefits: Private medical care package, MultiSport card, and flexible working hours
What You’ll Do
- Research next-generation MFA technologies by investigating Windows, Windows Server, Active Directory, Azure AD, and passwordless standards such as WebAuthn/FIDO2 passkeys; identify secure integration paths and attack surfaces
- Analyze Kerberos, NTLM, OAuth 2.0, and SAML authentication flows; uncover weaknesses, propose hardening strategies, and validate cryptographic soundness
- Prototype TPM 2.0, U2F/FIDO2 security keys, biometrics, and Bluetooth LE proximity for phishing-resistant login experiences
- Produce risk-ranked reports with reproduction steps, proof-of-concepts, and remediation guidance for product engineering and customer-success teams
- Create internal advisories and threat-model updates covering emerging threats and bypass techniques
- Lead red-team scenarios and post-test debriefs to help prioritize fixes
Skills You Have
- Foundational penetration-testing experience on Windows 10/11 or Windows Server, including use of tools such as Nmap, Responder, and BloodHound
- Understanding of MFA, Kerberos, NTLM, pass-the-hash, and credential-relay attack paths
- Working knowledge of Active Directory security, including group policy, privilege assignments, trust relationships, and MFA-related exposures
- Familiarity with WebAuthn/FIDO2 passkeys, smartcards, one-time codes, and their threat models
- Ability to write PowerShell or Python scripts for reconnaissance, log parsing, and proof-of-concept demonstrations
- Clear written and verbal communication of security risks and remediation steps
- Continuous learning of CVEs, attack techniques, and defensive practices
- Ability to collaborate in remote, cross-functional teams
Nice To Haves
- Experience testing or administering Azure AD/Entra ID environments
- Exposure to TPM, YubiKey, or Bluetooth LE proximity in authentication flows
- Familiarity with MITRE ATT&CK and threat-modeling methodologies
- CompTIA Security+, eJPT, OSCP, or CRTP certification
- Participation in CTFs, security meet-ups, or published security blogs or papers
Why Apply
- Work on security challenges that directly shape next-generation MFA products and protect users from account takeover
- Collaborate with experienced penetration testers, cryptographers, and software engineers
- Work in a small expert team where recommendations can move quickly from report to remediation
Steps After You Apply
- Online meeting with a recruiter
- Small assignment discussed with a technical lead
- Offer and final interview if successful
Similar jobs you might like

C++ Windows Security Researcher
Rublon
Senior
Technology
Kraków, MA, Poland · Remote
14K zł - 20K zł/yr
1h ago

Identity Security Engineer (German) – DACH
Rublon
Senior
Technology
Krakow, Poland · Remote
15K zł - 22K zł/yr
4 days ago

Młodszy Administrator IT (k/m)
Rublon
Junior
Technology
Zielona Góra, LB, Poland · On-site
0K zł - 0K zł/yr
4 days ago

Identity Security Engineer – Spain & LATAM
Rublon
Senior
Technology
Krakow, MA, Poland · Remote
15K zł - 22K zł/yr
4 days ago

Młodszy Etyczny Haker/Pentester (k/m)
Rublon
Junior
Technology
Zielona Gora, LB, Poland · On-site
0K zł - 0K zł/yr
4 days ago

Inżynier Identity Security (k/m)
Rublon
Mid
Technology
Krakow, MA, Poland · Remote
15K zł - 22K zł/yr
4 days ago

Inżynier Rozwiązań MFA (Presales) (k/m)
Rublon
Mid
Technology
Kraków, Poland · On-site
15K zł - 22K zł/yr
1h ago

Specjalista ds. Rozwoju Sprzedaży (SDR)
Rublon
Junior
Technology
Krakow, Poland · On-site
0K zł - 0K zł/yr
4 days ago

Senior Identity Infrastructure Engineer
Link Group
Senior
Technology
Kraków, MA, Poland · On-site
20K zł - 24K zł/yr
3 days ago
Specjalista ds. Cyberbezpieczeństwa i Compliance (K/M/X)
COMARCH
Mid
Technology
Kraków, MA, Poland · On-site
N/A
4 days ago