Unlock Full Resume Report

New offer - be the first one to apply!

September 18, 2026

Penetration Tester

Senior • On-site

Warsaw, Maz, Poland

Quick Facts

  • Role: Penetration Tester

Description

You will independently conduct penetration tests for IT infrastructure, web applications, mobile applications, and cloud environments. The work includes planning test scope, performing recon and attack-surface analysis, exploiting and validating vulnerabilities safely, and executing social engineering/phishing when relevant. You will produce risk-rated reports and present findings to both technical and business stakeholders.

Responsibilities

  • Plan penetration test scope and choose methods/tools based on the project
  • Perform reconnaissance, identify attack surface, and analyze environment architecture
  • Identify, confirm, and safely use security vulnerabilities
  • Conduct social engineering and phishing tests
  • Test web application security using OWASP Web Security Testing Guide and OWASP ASVS
  • Test Active Directory environments and verify privilege escalation and lateral movement
  • Validate the effectiveness of implemented controls and perform retests after fixes
  • Create technical and management reports with vulnerability descriptions, risk assessment (CVSS), and remediation recommendations
  • Present results to clients and participate in summary meetings
  • Collaborate with SOC, Incident Response, Vulnerability Management teams, and system administrators
  • Improve penetration testing methodologies, automate selected tasks, and build supporting tools
  • Monitor new attack techniques, vulnerabilities, and attacker tooling and incorporate them into testing

Requirements

  • Minimum 2 years of penetration testing experience across at least two areas: IT infrastructure, web applications, cloud environments
  • Experience with Black Box, Grey Box, and White Box testing
  • Knowledge of security testing methodologies/standards: OWASP Testing Guide (WSTG), OWASP ASVS, PTES, NIST SP 800-115, MITRE ATT&CK
  • Strong knowledge of Windows and Linux
  • Knowledge of network protocols and security topics: TCP/IP, DNS, HTTP/HTTPS, SMB, RDP, LDAP, Kerberos, NTLM, SNMP, VPN
  • Ability to manually identify, exploit, and verify vulnerabilities and map them to realistic attack scenarios
  • Practical experience with Burp Suite Professional, Nmap, Nessus, Metasploit, Impacket, NetExec (CrackMapExec), ffuf, sqlmap, Responder, Wireshark (or equivalents)
  • Ability to report to technical and business audiences with CVSS risk scoring and remediation recommendations
  • Ability to lead client meetings and present results to technical and business stakeholders
  • English level enabling free use of technical documentation (at least B2)
  • Self-sufficiency, responsibility, curiosity, and strong analytical skills

Benefits

  • Private medical care and group life insurance
  • Training and development programs, funding for professional qualification improvement, and advancement opportunities
  • Multisport card
  • Subsidy for rest/holidays

Similar jobs you might like