(Cybersecurity) Senior Penetration Tester

(Cybersecurity) Senior Penetration Tester

Senior Penetration Tester

We are looking for an experienced Senior Penetration Tester to join a cybersecurity team responsible for identifying vulnerabilities, assessing security risks and helping engineering teams build more secure applications and services.

In this role, you will perform hands-on security assessments across web applications, APIs, mobile applications, infrastructure and networks. You will combine manual testing, automated security tools, source code and configuration reviews to identify vulnerabilities and demonstrate their potential impact.

The role is highly technical, but also requires strong communication skills. You will work closely with technical and non-technical stakeholders, explain security risks in a clear and practical way, and provide guidance on remediation and secure development.

What you will do

  • Plan and perform penetration tests and security assessments across web, mobile, API, infrastructure and network environments.
  • Conduct hands-on manual testing as well as automated security testing.
  • Identify, validate and assess vulnerabilities and security weaknesses.
  • Develop basic proof-of-concept exploits where required to demonstrate the impact of identified vulnerabilities.
  • Perform source code and configuration reviews to identify security issues.
  • Assess security risks in custom applications and their implementations.
  • Review business requirements and technical designs to identify potential security risks and misuse scenarios.
  • Document findings clearly, including root cause, business impact, risk and recommended remediation.
  • Work closely with engineering and DevOps teams to support vulnerability remediation and secure development practices.
  • Contribute to the automation of repetitive security testing activities.
  • Advise development teams on security controls and appropriate remediation approaches.
  • Support vulnerability tracking, remediation and risk acceptance processes.
  • Prepare test plans, test cases and security assessment reports.
  • Evaluate new security testing technologies and tools and recommend improvements where appropriate.
  • Keep up to date with current vulnerabilities, attack techniques, security research and industry developments.
  • Contribute to improving security testing processes, methodologies and standards.
  • Support security incident response activities when required.
  • Act as a subject matter expert in at least one penetration testing domain.
  • Share knowledge and mentor less experienced penetration testers.
  • Work independently or take ownership of security testing activities involving other testers.

What we are looking for

Essential

  • 3+ years of hands-on penetration testing experience.
  • Strong practical experience in at least one penetration testing domain, such as:
    • Web applications
    • Mobile applications
    • APIs
    • Infrastructure and networks
  • Strong understanding of common vulnerabilities, attack techniques and security testing methodologies.
  • Excellent knowledge of TCP/IP, networking and security protocols.
  • Strong web application security testing experience.
  • Practical experience with both manual and automated security testing.
  • Good programming or scripting skills.
  • Strong analytical and critical-thinking skills.
  • Ability to understand the business impact of technical security findings.
  • Ability to communicate complex security topics clearly to both technical and non-technical audiences.
  • Ability to work independently, manage priorities and take ownership of assigned security assessments.
  • Strong written and spoken English.
  • Ability to solve complex technical problems and adapt to new technologies and scenarios.

Mobile Security – nice to have

Experience with mobile application security testing would be a strong advantage, particularly:

  • Android and/or iOS security models.
  • Common mobile application vulnerabilities and attack techniques.
  • OWASP MASVS and OWASP MSTG.
  • Mobile application testing frameworks and tools.
  • Static and dynamic analysis.
  • Security testing of authentication and authorization mechanisms.
  • SSL/TLS and certificate pinning.
  • Biometric authentication.
  • JWT, OAuth 2.0 and SAML.
  • RASP and other application security controls.
  • Reverse engineering and application disassembly.

Application Security & Development – nice to have

  • Experience with SAST, DAST and IAST tools and understanding of their limitations.
  • Experience with security code reviews.
  • Knowledge of Java, Kotlin, Swift and/or Objective-C.
  • Understanding of software development lifecycles and DevOps practices.
  • Experience testing cloud-hosted applications and services.
  • Understanding of enterprise application architectures and common security issues.
  • Previous software development experience, particularly for Android or iOS, would be an advantage.
  • Experience with technologies such as HTML, XML, JavaScript, JSON, REST and microservices.
  • Understanding of applied cryptography in application development.

Certifications

Professional security certifications are not required, but relevant certifications such as OSCP, OSWE, OSEP, CREST or equivalent will be considered an advantage.

What we offer

  • B2B contract
  • Hybrid working model – 6 days per month from the office in Kraków
  • Private healthcare – Lux Med
  • MyBenefit cafeteria
  • Dedicated support from a Contractor Care Specialist
ID: 16653 job_post.published_on: 09/09/2026
announcement.apply