
Offensive Security Engineer / Penetration Tester
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Poland, +4 more countries.
• Conduct comprehensive penetration tests on web and mobile applications, Active Directory, and cloud environments.
• Manage engagements from the initial scoping and reconnaissance through to exploitation, post-exploitation, evidence collection, and retesting.
• Validate results from Application Security and Infrastructure Security services.
• Analyze automated scan outputs by filtering out false positives, confirming exploitability and business impact, and assigning precise risk ratings.
• Compose client-facing technical reports in English, including reproduction steps, evidence, business-impact context, and actionable remediation advice.
• Engage directly with clients via kick-off calls, status updates, report walkthroughs, remediation Q&A, and retest agreements.
• Develop automation and internal tools to streamline reconnaissance, enumeration, and active scanning phases.
• Create AI-agent-driven workflows for offensive security testing.
• Establish and maintain internal methodologies, testing checklists, and knowledge bases.
• Investigate new attack methods, assess tools, and share insights with the team.
• Complete client engagements from start to finish within the initial months.
• Develop the internal methodology for AWS cloud security assessments.
• Become the team's go-to expert on at least one platform within a year.
• Minimum of 2.5 years of hands-on commercial penetration testing experience.
• Proven track record of delivering several end-to-end penetration testing engagements.
• Experience in drafting penetration testing reports.
• At least one practical certification—OSCP, CPTS, GPEN, or CWEE, or a recognized equivalent.
• Proficient in web application testing based on the OWASP Web Security Testing Guide and beyond.
• Experience identifying vulnerabilities such as authentication and authorization flaws, IDOR, injection, SSRF, insecure deserialization, and business logic abuse.
• Daily use of Burp Suite Professional.
• Experience in mobile application testing based on OWASP MASTG for Android and/or iOS.
• Skills in static and dynamic mobile application analysis.
• Knowledge of traffic interception and bypassing certificate pinning.
• Understanding of insecure local storage, IPC, and platform misuse.
• Familiarity with Active Directory and internal network attack strategies.
• Knowledge of enumeration, Kerberos abuse, credential relaying, lateral movement, and privilege escalation paths.
• Proficiency in scripting with Python and/or Bash.
• Ability to read application source code and identify vulnerable patterns in at least one of the following: PHP, Java, C#, JS/TS, or Python.
• Proficiency in English at a B2 level or higher.
• Nice-to-have: a second practical certification such as BSCP, CWEE, CAPE, GWAPT, OSWE, CRTO, eWPTX, or eMAPT.
• Nice-to-have: experience in cloud security testing within AWS, Azure, or GCP.
• Nice-to-have: hands-on experience or a keen interest in AI and LLM security.
• Nice-to-have: public technical contributions like CVEs, open-source tools, research papers, conference presentations, or high-quality bug bounty reports.
• Flexible working hours and the possibility to work from any location that suits you.
• Medical insurance coverage.
• 20 paid vacation days annually.
• Unlimited sick leave.
• All necessary work equipment provided.
• Financial support for professional training.
• Access to an internal learning platform and lectures.
• Opportunities for corporate events and networking.
• Complimentary sports training sessions.
• Corporate discounts available.
• Massage services when visiting the office.
• Support for colleagues and their families serving in the Defence Forces.
• Assistance for veterans.
• Help available in case of health or property damage caused by the war.
The Cigna Group
Adecco Professional Colombia-
WTime Business Intelligence
NTT
Get handpicked remote jobs straight to your inbox weekly.