Pracuj.pl Hybrydowo Senior

Principal Mobile Application Penetration Tester

Mindbox Sp. z o.o.

⚲ Kraków

160–210 zł netto (+ VAT) / godz.

Wymagania

  • iOS
  • Android
  • Java
  • Swift
  • Objective-C
  • Kotlin
  • OAuth2
  • JWT

Opis stanowiska

Nasze wymagania:
3–5 years in penetration testing with a strong focus on mobile application security
Hands-on experience testing iOS and Android apps, addressing platform-specific risks
Expertise in mobile security plus at least one additional domain (web apps or infrastructure)
Strong understanding of vulnerabilities, attack techniques, and security principles
Knowledge of TCP/IP fundamentals, network security, and OWASP mobile standards (MASVS, MSTG)
Experience with manual and automated testing tools
Strong problem-solving, analytical skills, and ability to communicate complex topics clearly
Familiarity with scripting or programming

Mile widziane:
Experience with Corellium platform, SAST/DAST/IAST tools, or secure SDLC
Code review experience in Java, Swift, Objective-C, or Kotlin
Understanding of OAuth2, JWT, biometrics, and SSL pinning
Familiarity with microservices, APIs, and cloud environments
Experience in financial or other regulated industries

O projekcie:
We’re looking for a Principal Mobile Application Penetration Tester to join a global cyber security organization and raise the bar on how we test and protect mobile apps. This is a hands-on, principal role where you’ll lead complex mobile security assessments from start to finish, influence standards, and guide stakeholders in navigating an ever-evolving threat landscape.
You’ll work at the core of mobile security—testing iOS and Android applications, innovating on methodologies, and driving excellence across teams worldwide. If you’re passionate about being a trusted security leader, this role is for you!
Sounds like your kind of challenge?

Zakres obowiązków:
Lead end-to-end mobile app penetration tests: scoping, planning, execution, and reporting
Deliver high-quality testing outputs with actionable remediation guidance
Serve as the escalation point for complex technical challenges and high-impact findings
Set and evolve mobile testing methodologies and frameworks across the organization
Collaborate with global penetration testing leads to ensure consistency across regions
Drive improvements in tooling, automation, and best practices for mobile security
Support vulnerability management lifecycle and incident response when needed
Stay ahead of emerging mobile attack vectors, tools, and security trends
Note: Detailed project information will be shared during the recruitment process.

Oferujemy:
Flexible cooperation model – choose the form that suits you best (B2B, employment contract, etc.).
Hybrid work setup – Kraków: 6 days/month on-site.
Collaborative team culture – work alongside experienced professionals eager to share knowledge.
Continuous development – access to training platforms and growth opportunities.
Comprehensive benefits – including Interpolska Health Care, Multisport card, Warta Insurance, and more.
High quality equipment – laptop and essential software provided.

🔍 Dekoder Ogłoszenia

🔴
raise the bar on how we test and protect mobile apps
Oczekuje się, że wprowadzisz nowe, lepsze metody testowania i ochrony aplikacji mobilnych, co może oznaczać potrzebę tworzenia nowych narzędzi lub procesów od podstaw.
🟡
lead complex mobile security assessments from start to finish
Będziesz odpowiedzialny za cały cykl życia oceny bezpieczeństwa, od planowania po raportowanie, co może wymagać dużej samodzielności i zarządzania projektami.
🟢
influence standards
Masz szansę kształtować wewnętrzne standardy bezpieczeństwa, co może oznaczać konieczność przekonywania innych i wprowadzania zmian w istniejących procesach.
🟡
guide stakeholders in navigating an ever-evolving threat landscape
Będziesz musiał tłumaczyć złożone zagrożenia bezpieczeństwa osobom nietechnicznym i doradzać im, co wymaga umiejętności komunikacyjnych i strategicznego myślenia.
🔴
innovating on methodologies
Oczekuje się, że będziesz aktywnie poszukiwał i wdrażał nowe, innowacyjne metody testowania bezpieczeństwa aplikacji mobilnych.