API Pentester
⚲ Wrocław
28 560 - 30 240 PLN netto (B2B)
Wymagania
- API Testing
- iOS
- Active Directory
- Security testing
Opis stanowiska
Join our Offensive Security team and lead penetration testing engagements for clients across financial services, technology, healthcare, government, and critical infrastructure sectors. This is a hands-on role for an experienced security professional who wants to remain highly technical while taking ownership of project delivery, client relationships, and mentoring junior consultants.
Key Responsibilities:
• Lead and perform penetration tests across web applications, APIs, internal/external networks, mobile applications, cloud environments, and Active Directory.
• Conduct advanced Active Directory security assessments and infrastructure testing.
• Develop custom scripts, tooling, and proof-of-concept exploits.
• Manage engagements from scoping to reporting and remediation validation.
• Present findings to technical and business stakeholders.
• Support proposal development, effort estimation, and pre-sales activities.
• Mentor junior team members and contribute to internal methodologies and best practices.
Required Experience:
• 5+ years of hands-on penetration testing or offensive security experience, ideally within a consulting environment.
• Strong expertise in at least three of the following: web, network, mobile, or Active Directory security testing.
• Experience with tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Cobalt Strike (or similar), Nessus/OpenVAS, Frida, and MobSF.
• Scripting skills in Python, PowerShell, or Bash.
• Strong communication, reporting, and client-facing skills.
Certifications:
At least one of:
• OSCP
• CREST CRT/CPSA
• CRTP or CRTO
Nice to Have:
• Big 4 or cybersecurity consultancy experience.
• Cloud security testing (AWS, Azure, GCP).
• Kubernetes/container security knowledge.
• Security research, CVEs, conference talks, or CTF achievements.
Offer:
• Multisport Card
• Life insurance
• Private healthcare
• PowerYou platform
Key Responsibilities:
• Lead and perform penetration tests across web applications, APIs, internal/external networks, mobile applications, cloud environments, and Active Directory.
• Conduct advanced Active Directory security assessments and infrastructure testing.
• Develop custom scripts, tooling, and proof-of-concept exploits.
• Manage engagements from scoping to reporting and remediation validation.
• Present findings to technical and business stakeholders.
• Support proposal development, effort estimation, and pre-sales activities.
• Mentor junior team members and contribute to internal methodologies and best practices.
Required Experience:
• 5+ years of hands-on penetration testing or offensive security experience, ideally within a consulting environment.
• Strong expertise in at least three of the following: web, network, mobile, or Active Directory security testing.
• Experience with tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Cobalt Strike (or similar), Nessus/OpenVAS, Frida, and MobSF.
• Scripting skills in Python, PowerShell, or Bash.
• Strong communication, reporting, and client-facing skills.
Certifications:
At least one of:
• OSCP
• CREST CRT/CPSA
• CRTP or CRTO
Nice to Have:
• Big 4 or cybersecurity consultancy experience.
• Cloud security testing (AWS, Azure, GCP).
• Kubernetes/container security knowledge.
• Security research, CVEs, conference talks, or CTF achievements.
Offer:
• Multisport Card
• Life insurance
• Private healthcare
• PowerYou platform
🔍 Dekoder Ogłoszenia
🟡
lead penetration testing engagements
Będziesz odpowiedzialny za całe projekty testów penetracyjnych, od początku do końca, a nie tylko za wykonywanie konkretnych zadań.
🔴
remain highly technical while taking ownership of project delivery, client relationships, and mentoring junior consultants
Oczekuje się, że będziesz nadal wykonywał pracę techniczną, ale jednocześnie będziesz zarządzał projektami, klientami i innymi pracownikami.
🟡
Develop custom scripts, tooling, and proof-of-concept exploits
Oprócz standardowych narzędzi, będziesz musiał tworzyć własne rozwiązania, co wymaga zaawansowanych umiejętności programistycznych i kreatywności.
🔴
Support proposal development, effort estimation, and pre-sales activities
Będziesz zaangażowany w proces sprzedaży i tworzenia ofert, co może oznaczać dodatkowe obowiązki poza technicznymi.
🔴
Strong communication, re
Ogłoszenie jest niekompletne, co może sugerować pośpiech w jego publikacji lub brak dopracowania.