NoFluffJobs Hybrydowo Senior

Cybersecurity Penetration Testing Lead

Antal

⚲ Kraków

30 240 - 36 960 PLN (B2B)

Wymagania

  • Penetration testing
  • TCP/IP
  • Manual Testing
  • Automated testing
  • Network Security
  • Mobile security (nice to have)
  • OWASP (nice to have)
  • SAST (nice to have)
  • DAST (nice to have)
  • Microservices (nice to have)
  • Java (nice to have)
  • Kotlin (nice to have)
  • Swift (nice to have)
  • SSL (nice to have)

Opis stanowiska

O projekcie:
Penetration Testing Team Lead

📍 Location: Kraków (preferable) / Warszawa ( 6 days per month)
Area: Cybersecurity – Research & Offensive Security
Level: Senior / Leadership
Model: B2B
Rate: 180-220PLN netto

About the role

We are looking for a Penetration Testing Team Lead to join a global cybersecurity organization and lead a team responsible for identifying and exploiting vulnerabilities across applications, infrastructure, and mobile platforms.

This role combines hands-on penetration testing expertise with team leadership and delivery ownership. You will lead complex security assessments, shape testing methodologies, and work closely with stakeholders to strengthen the overall security posture in a rapidly evolving threat landscape.

Key responsibilities

- Lead and manage a team of penetration testers delivering security assessments across multiple domains
- Oversee end-to-end penetration testing lifecycle: scoping, planning, execution, and reporting
- Ensure high-quality, actionable deliverables, including clear risk articulation and remediation guidance
- Act as the main escalation point for complex technical challenges and stakeholder concerns
- Collaborate with global penetration testing leads to:

- align methodologies and standards
- share knowledge and insights
- ensure consistency across regions

- Contribute to the development and continuous improvement of testing frameworks, tools, and best practices
- Build and maintain internal knowledge base (findings, trends, lessons learned)
- Support vulnerability management lifecycle (tracking, remediation, risk acceptance)
- Participate in incident response and security investigations when needed
- Evaluate new tools, techniques, and emerging attack vectors

What we offer

- Opportunity to lead and shape a high-performing penetration testing team
- Work in a global, collaborative cybersecurity environment
- Exposure to complex and large-scale security challenges
- Real impact on improving security posture across the organization
- Competitive compensation and benefits _ Luxmed and Multisport

Wymagania:
- Minimum 5 years of hands-on experience in penetration testing- Proven experience leading or mentoring penetration testing teams- Strong expertise in at least two domains:- web applications- infrastructure- mobile security- Solid understanding of:- common vulnerabilities and attack techniques- TCP/IP and network security- application security principles- Strong experience with manual and automated testing techniques- Ability to clearly communicate complex technical findings to non-technical stakeholders- Strong analytical thinking and problem-solving skills- Experience with scripting/programmingNice to have- Experience with mobile security (iOS, Android) and related risks- Knowledge of OWASP standards (e.g., MASVS, MSTG)- Experience with SAST, DAST, IAST tools- Understanding of modern architectures (microservices, APIs, cloud environments)- Experience with code reviews (Java, Kotlin, Swift, Objective-C)- Knowledge of authentication and security mechanisms (OAuth2, JWT, biometrics, SSL pinning)- Background in software development or secure SDLC- Experience in financial services or other regulated environmentsLeadership & collaboration- Mentor, coach, and develop team members (technical and career growth)- Foster a collaborative, knowledge-sharing culture within the team- Work closely with stakeholders across technology, security, and business teams- Translate technical findings into business-relevant insights- Support cross-regional collaboration and alignment

🔍 Dekoder Ogłoszenia

🔴
lead a team responsible for identifying and exploiting vulnerabilities across applications, infrastructure, and mobile platforms
Będziesz zarządzać zespołem, który wykonuje testy penetracyjne, ale Twoja rola może obejmować również aktywne uczestnictwo w testach, a nie tylko zarządzanie.
🔴
This role combines hands-on penetration testing expertise with team leadership and delivery ownership
Oczekuje się, że będziesz nie tylko zarządzać zespołem, ale także aktywnie wykonywać testy penetracyjne i brać odpowiedzialność za dostarczane wyniki.
🔴
Act as the main escalation point for complex technical challenges and stakeholder concerns
Będziesz rozwiązywać problemy techniczne i komunikować się z interesariuszami, co może oznaczać dużo pracy poza zakresem stricte technicznym.
🔴
Collaborate with global penetration testing leads to: align methodologies and standards, share knowledge and insights, ensure consistency across regions
Może to oznaczać konieczność dostosowywania się do istniejących, globalnych procesów i standardów, które niekoniecznie muszą być optymalne lokalnie.
🟡
Contribute to the development and continuous improvement of testing frameworks, tools, and best practices
Oprócz bieżących zadań, będziesz zaangażowany w tworzenie i ulepszanie narzędzi i procesów, co może wymagać dodatkowego czasu i wysiłku.