JustJoin.IT Praca zdalna Mid

Pentester WebAPP and API

Link Group

⚲ Warszawa, Białystok, Lublin, Kraków, Wrocław, Poznań, Szczecin, Gdańsk, Olsztyn, Łódź

21 840 - 23 520 PLN netto (B2B)

Wymagania

  • QA
  • Cybersecurity
  • Active Directory

Opis stanowiska

Key Responsibilities (What You’ll Do)


Advanced Technical Testing: Personally lead and execute end-to-end penetration tests across web applications, APIs, mobile apps (iOS/Android), cloud environments, and internal/external networks.
• Deep Active Directory Assessments: Perform sophisticated AD security testing, including privilege escalation, lateral movement, delegation/ACL abuse, and attack path analysis.
• Exploit Development: Write custom scripts, tooling, and proof-of-concept (PoC) exploits using Python, PowerShell, and/or Bash.
• End-to-End Engagement Management: Own the lifecycle of assignments—from initial scoping and effort estimation to final report delivery and remediation retesting.
• Quality Assurance & Pre-Sales: Review and QA technical findings/reports from the team, and provide technical input during scoping calls and proposal creation.
• Client & Stakeholder Communication: Act as the primary technical point of contact, translating complex technical risks into clear insights for both devs and non-technical executives.
Required Skills & Experience (What You’ll Need)


Experience: ~5+ years of hands-on offensive security experience, ideally within a cybersecurity consultancy or multi-client delivery environment.

• Core Depth: Proven expertise in at least three domains: web applications, network, mobile, or Active Directory testing.
• Tooling Infrastructure: Mastery of industry-standard tools (Burp Suite, Nmap, Metasploit, BloodHound, Impacket, CrackMapExec/NetExec, Cobalt Strike, Frida, etc.).
• Certifications (Minimum of ONE required):

OSCP (Offensive Security Certified Professional)

• CRTP / CRTO (Active Directory/Red Team)
• CREST CRT / CPSA (CCT App or Infra strongly preferred)
• Soft Skills: Exceptional report-writing skills and fluent professional English.
Highly Desirable / Nice to Have
• Advanced certifications (OSEP, OSWE, OSED, CRTE, SANS GXPN/GWAPT, or Cloud offensive certs).
• Prior experience within a Big 4 firm or an established boutique security consultancy.
• Hands-on exposure to AWS/Azure/GCP cloud environments and Kubernetes/containers.
• Active community presence: Published research, CVEs, open-source tooling contributions, conference talks, or top CTF achievements.

🔍 Dekoder Ogłoszenia

🔴
Personally lead and execute end-to-end penetration tests
Oczekuje się, że będziesz samodzielnie prowadzić i realizować testy od początku do końca, a nie tylko wspierać innych.
🔴
End-to-End Engagement Management
Będziesz odpowiedzialny za cały cykl projektu, od ustalenia zakresu po końcowy raport i weryfikację poprawek.
🔴
Quality Assurance & Pre-Sales
Oprócz testowania, będziesz musiał przeglądać raporty innych oraz brać udział w rozmowach sprzedażowych i tworzeniu ofert.
🟡
Client & Stakeholder Communication
Będziesz głównym punktem kontaktu technicznego, co oznacza konieczność częstej i jasnej komunikacji z różnymi grupami odbiorców.
🔴
ideally within a cybersecurity consultancy or multi-client delivery environment
Preferowane jest doświadczenie w pracy dla wielu klientów, co może oznaczać zmienne projekty i presję czasu.