Senior Penetration Tester

Brak informacji o wynagrodzeniu
SeniorFull-time
#355334·Dodano dziś·0
Źródło: BrainRocket
Aplikuj teraz

Tech Stack / Keywords

TestingNetworksCloudAWSSecurityKubernetesCI/CDMicroservices

Firma i stanowisko

BrainRocket is a global company creating end-to-end tech products for clients across Fintech, iGaming, and Marketing. The company has a team of 1,300 employees and operates in Cyprus, Malta, Portugal, Poland, and Serbia.


Wymagania

  • Minimum 4 years of hands-on penetration testing or offensive-security experience.
  • Proven track record across at least three of: web / API, internal, external network, cloud (AWS / GCP), mobile (iOS / Android).
  • OSCP or an equivalent in-the-box certification.
  • Strong working knowledge of SAST/SCA/DAST tooling, AWS/GCP, MITRE ATT&CK, OWASP ASVS / WSTG, PTES.
  • Understanding of the data flow, MVC model.
  • Understanding of supply chain attacks.
  • Good reporting skills.
  • Comfortable scripting in Python plus Bash.
  • Knowledge of at least one major cloud provider's IAM model.
  • Experience pentesting cloud-native systems and Kubernetes environments, plus the CI/CD pipelines around them (GitLab, GitHub Actions, Jenkins) and IaC (Terraform, Helm, CloudFormation).
  • Strong written and verbal communication in English.
  • Experience balancing security and business demands under release pressure.
  • Familiarity with industry regulations, frameworks, and practices: PCI DSS, ISO 27001, NIST, GDPR.

Preferred qualifications:

  • One of offensive-security certifications: OSWE, OSEP, OSED, CRTO, BSCP, ARTE, GRTE.
  • In-depth experience architecting secure services on Kubernetes and AWS.
  • Prior iGaming, fintech, or payments domain experience.
  • Public CVEs, advisories, write-ups, conference talks.
  • HTB Pro Lab completions, real CTF placements.
  • Open-source contributions to offensive or defensive tooling.

Obowiązki

  • Lead end-to-end penetration testing engagements across web applications, APIs, mobile, internal and external networks, and cloud (primarily AWS).
  • Run red-team and assumed-breach operations including initial access, privilege escalation, lateral movement, persistence, and exfiltration, including against fraud and detection stacks.
  • Perform security reviews of cloud-native services, Kubernetes workloads, CI/CD pipelines, and microservices.
  • Discover and exploit vulnerabilities across real-money flows such as payments, deposits and withdrawals, wallets, KYC / AML, bonus systems, and affiliate tracking.
  • Partner with product, engineering, AppSec, payments, and fraud teams to translate findings into concrete fixes and durable controls.
  • Develop custom tooling, scripts, and methodology where no out-of-the-box approach exists.
  • Build and validate declarative threat models and contribute to "secure by design" practice.
  • Mentor mid and junior testers, review their engagement plans and reports.
  • Track new CVEs, TTPs, MITRE ATT&CK updates, and regulator advisories and translate them into concrete changes.
  • Support pre-sales scoping, effort estimation, and pre-certification engagements for new products and jurisdictions.
  • Serve as a trusted offensive-security advisor to product, engineering, and compliance teams.

Oferta

  • Career growth opportunities in an international and dynamic environment.
  • Partial compensation for language courses.
  • Special gifts for birthdays, weddings, and newborns.
  • 20 working days of paid annual vacation, plus 6 paid sick leave days.
  • Office snacks and refreshments.
  • Sports package to support a healthy lifestyle.
  • Comprehensive medical insurance for employee and partner.
  • Comfortable office with great facilities in a prime location.
  • Corporate events, team-building activities, and international company parties.
Dofinansowanie szkoleń
Płatny urlop
Darmowe przekąski
Karta sportowa
Opieka zdrowotna
Napoje w biurze
Spotkania integracyjne

Inne informacje

This is an office-based role with no remote or hybrid options.

BrainRocket

BrainRocket

37 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz