(Cybersecurity) Senior Penetration Tester
100 - 200 PLN/ godz.B2B
SeniorFull-time·B2B
#431362·Dodano wczoraj·0
Źródło: AntalTech Stack / Keywords
CybersecuritySecurityNetworksManual TestingAPITestingDevOpsTCP/IP
Firma i stanowisko
Antal is recruiting for a Senior Penetration Tester role based in Kraków, Poland, focused on cybersecurity within the banking discipline.
Wymagania
- Minimum 3 years of hands-on penetration testing experience.
- Strong practical experience in at least one penetration testing domain: web applications, mobile applications, APIs, infrastructure, or networks.
- Excellent knowledge of common vulnerabilities, attack techniques, and security testing methodologies.
- Strong understanding of TCP/IP, networking, and security protocols.
- Strong web application security testing experience.
- Practical experience with manual and automated security testing.
- Good programming or scripting skills.
- Strong analytical and critical-thinking skills.
- Ability to understand business impact of technical security findings.
- Ability to communicate complex security topics clearly to technical and non-technical audiences.
- Ability to work independently, manage priorities, and own security assessments.
- Strong written and spoken English skills.
- Ability to solve complex technical problems and adapt to new technologies.
Nice to have:
- Mobile security testing experience, including Android/iOS security models, mobile vulnerabilities, and frameworks.
- Familiarity with OWASP MASVS and OWASP MSTG.
- Experience with static and dynamic analysis, SSL/TLS, biometric authentication, JWT, OAuth 2.0, SAML, RASP, reverse engineering.
- Experience with SAST, DAST, and IAST tools and security code reviews.
- Knowledge of Java, Kotlin, Swift, and/or Objective-C.
- Understanding of software development lifecycles and DevOps practices.
- Experience testing cloud-hosted applications.
- Understanding of enterprise application architectures and security issues.
- Prior software development experience, especially Android or iOS.
- Experience with HTML, XML, JavaScript, JSON, REST, and microservices.
- Understanding of applied cryptography in application development.
- Relevant professional security certifications (e.g., OSCP, OSWE, OSEP, CREST) considered an advantage.
Obowiązki
- Plan and perform penetration tests and security assessments across web, mobile, API, infrastructure, and network environments.
- Conduct hands-on manual testing and automated security testing.
- Identify, validate, and assess vulnerabilities and security weaknesses.
- Develop proof-of-concept exploits to demonstrate impact.
- Perform source code and configuration reviews.
- Assess security risks in custom applications and implementations.
- Review business requirements and technical designs for security risks.
- Document findings including root cause, business impact, risk, and remediation recommendations.
- Collaborate with engineering and DevOps teams for vulnerability remediation.
- Contribute to automation of repetitive security testing activities.
- Advise development teams on security controls and remediation approaches.
- Support vulnerability tracking, remediation, and risk acceptance.
- Prepare test plans, test cases, and security assessment reports.
- Evaluate and recommend security testing technologies and tools.
- Stay updated with vulnerabilities, attack techniques, and industry developments.
- Improve security testing processes, methodologies, and standards.
- Support security incident response activities as needed.
- Act as a subject matter expert in at least one penetration testing domain.
- Share knowledge and mentor less experienced penetration testers.
- Work independently or lead security testing activities involving other testers.
Benefity
- B2B contract
- Hybrid working model with 6 days per month from the office in Kraków
- Private healthcare provided by Lux Med
- MyBenefit cafeteria
- Dedicated support from a Contractor Care Specialist
Opieka zdrowotna
Antal
921 aktywnych ofert