Pracuj.pl Stacjonarnie Expert

Principal Penetration Tester - Mobile Application (f/m/x)

Sii Sp. z o.o.

⚲ Kraków, Podgórze

Do uzgodnienia

Wymagania

  • Penetration Testing
  • Cybersecurity
  • iOS
  • Android
  • Java
  • Kotlin
  • Swift
  • Objective-C

Opis stanowiska

Nasze wymagania:
Minimum 5 years of hands-on penetration testing experience, with a strong focus on mobile application security
Practical experience testing iOS and Android applications, including common mobile attack paths and platform-specific risks
Strong expertise in mobile security plus at least one additional domain: web applications or infrastructure
Solid understanding of common vulnerabilities, attack techniques, and application security principles
Strong grasp of TCP/IP fundamentals and network security concepts
Confident using both manual and automated testing techniques
Ability to explain complex technical issues to non-technical audiences clearly and calmly
Strong analytical thinking and problem-solving skills
Experience with scripting or programming languages
Knowledge of OWASP mobile standards such as MASVS and MSTG
Advanced level of English

Mile widziane:
Experience in/or ability to run and deliver tests using the Corellium platform
Ability to operate within a secure mobile testing environment, including access to appropriate test devices and tooling, in line with client and organizational security requirements
Previous work with SAST, DAST, and IAST tools
Familiarity with modern architectures, including microservices, APIs, and cloud environments
Code review experience in Java, Kotlin, Swift, or Objective-C
Knowledge of authentication and security mechanisms like OAuth2, JWT, biometrics, and SSL pinning
Background in software development or secure SDLC
Experience in financial services or other regulated environments

O projekcie:
We are looking for a Principal Mobile Application Penetration Tester to join a global cybersecurity organization and elevate the standards of mobile app security testing. In this hands-on role, you will lead complex mobile security assessments from start to finish, shaping our methodologies and helping stakeholders navigate the evolving threat landscape. This position is based in Cracow and offers a hybrid work mode, allowing for flexibility in your work environment.

Zakres obowiązków:
Leading end-to-end mobile application penetration tests, including scoping, planning, execution, and reporting
Delivering clear, high-quality outputs with practical remediation guidance and well-articulated risk assessments
Acting as the go-to escalation point for complex technical challenges and high-impact findings
Setting and evolving mobile testing methodologies, playbooks, and quality standards across the team
Partnering with global penetration testing leads to aligning ways of working and sharing insights across regions
Contributing to the improvement of frameworks, tooling, automation, and best practices with a strong focus on mobile security
Building and maintaining an internal knowledge base of findings, trends, and lessons learned
Supporting the vulnerability management lifecycle, including tracking, remediation, and risk acceptance
Assisting in incident response and security investigations when needed
Staying ahead of emerging attack vectors, tools, and techniques, especially in the mobile space

Oferujemy:
Great Place to Work since 2015 - it’s thanks to feedback from our workers that we get this special title and constantly implement new ideas
Employment stability - revenue of PLN 2.1BN, no debts, since 2006 on the market
We share the profit with Workers - over PLN 76M has already been allocated for this aim since 2022
Attractive benefits package - private healthcare, benefits cafeteria platform, car discounts and more
Comfortable workplace – class A offices or remote work
Dozens of fascinating projects for prestigious brands from all over the world – you can change them thanks to Job Changer application
PLN 1 000 000 per year for your ideas - with this amount, we support the passions and voluntary actions of our workers
Investment in your growth – meetups, webinars, training platform and technology blog – you choose
Fantastic atmosphere created by all Sii Power People

🔍 Dekoder Ogłoszenia

🔴
Ability to explain complex technical issues to non-technical audiences clearly and calmly
Oczekuje się, że będziesz musiał często tłumaczyć skomplikowane problemy techniczne osobom nietechnicznym, co może być frustrujące.
🔴
Strong expertise in mobile security plus at least one additional domain: web applications or infrastructure
Może oznaczać, że będziesz musiał pracować również nad testami webowymi lub infrastrukturalnymi, nawet jeśli ogłoszenie skupia się na mobilnych.
🔴
Experience with scripting or programming languages
Prawdopodobnie będziesz musiał pisać skrypty do automatyzacji testów lub analizy wyników, a nie tylko używać gotowych narzędzi.
🔴
Background in software development or secure SDLC
Może sugerować, że od kandydata oczekuje się zrozumienia procesów tworzenia oprogramowania i jego zabezpieczania, a nie tylko samego testowania.