Unlock Full Resume Report

New offer - be the first one to apply!

September 6, 2026

Ethical Hacker/Pentester

Junior • Remote

13,000 - 18,000 PLN/yr

Kraków, Poland

R&D on Multi-Factor Authentication Security

Research and development activities on multi-factor authentication security will enable the development of new solutions for passwordless multi-factor authentication. Conduct in-depth threat modeling and cryptographic analysis of authentication flows, prototype and validate next-generation passwordless methods such as WebAuthn/FIDO2 passkeys, and monitor emerging attack vectors. Work with product and engineering teams to translate research insights into production-ready features and publish security findings.

How You’ll Work

  • Location: Remote or from offices in Kraków or Zielona Góra, Poland
  • Assessment Targets & Tooling: Windows 10/11, Windows Server, Active Directory, Entra ID (Azure AD), Kerberos, NTLM, WebAuthn/FIDO2 passkeys, Linux servers; BloodHound, Mimikatz, Impacket, Metasploit, Responder, Nmap, and custom PowerShell/Python scripts
  • Team: Work closely with security researchers/analysts and a project manager; coordinate priorities and share findings in weekly threat-hunting syncs
  • Language: Communicate in Polish or English
  • Hardware & Lab Access: Modern laptop, isolated virtual test environments, and security keys, including TPM-enabled devices and FIDO2 keys
  • Self-development: Company-funded online courses and certification vouchers
  • Employee Benefits: Private medical care package, MultiSport card, and flexible working hours

What You’ll Do

  • Research next-generation MFA technologies by investigating Windows, Windows Server, Active Directory, Azure AD, and passwordless standards such as WebAuthn/FIDO2 passkeys; identify secure integration paths and attack surfaces
  • Analyze Kerberos, NTLM, OAuth 2.0, and SAML authentication flows; uncover weaknesses, propose hardening strategies, and validate cryptographic soundness
  • Prototype TPM 2.0, U2F/FIDO2 security keys, biometrics, and Bluetooth LE proximity for phishing-resistant login experiences
  • Produce risk-ranked reports with reproduction steps, proof-of-concepts, and remediation guidance for product engineering and customer-success teams
  • Create internal advisories and threat-model updates covering emerging threats and bypass techniques
  • Lead red-team scenarios and post-test debriefs to help prioritize fixes

Skills You Have

  • Foundational penetration-testing experience on Windows 10/11 or Windows Server, including use of tools such as Nmap, Responder, and BloodHound
  • Understanding of MFA, Kerberos, NTLM, pass-the-hash, and credential-relay attack paths
  • Working knowledge of Active Directory security, including group policy, privilege assignments, trust relationships, and MFA-related exposures
  • Familiarity with WebAuthn/FIDO2 passkeys, smartcards, one-time codes, and their threat models
  • Ability to write PowerShell or Python scripts for reconnaissance, log parsing, and proof-of-concept demonstrations
  • Clear written and verbal communication of security risks and remediation steps
  • Continuous learning of CVEs, attack techniques, and defensive practices
  • Ability to collaborate in remote, cross-functional teams

Nice To Haves

  • Experience testing or administering Azure AD/Entra ID environments
  • Exposure to TPM, YubiKey, or Bluetooth LE proximity in authentication flows
  • Familiarity with MITRE ATT&CK and threat-modeling methodologies
  • CompTIA Security+, eJPT, OSCP, or CRTP certification
  • Participation in CTFs, security meet-ups, or published security blogs or papers

Why Apply

  • Work on security challenges that directly shape next-generation MFA products and protect users from account takeover
  • Collaborate with experienced penetration testers, cryptographers, and software engineers
  • Work in a small expert team where recommendations can move quickly from report to remediation

Steps After You Apply

  • Online meeting with a recruiter
  • Small assignment discussed with a technical lead
  • Offer and final interview if successful

Similar jobs you might like