Offensive Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Offensive Security Engineer (Cybersecurity): Perform in-depth penetration tests across web apps, APIs, and infrastructure with an accent on uncovering meaningful flaws beyond automated tools. Focus on developing impactful PoCs, collaborating with engineers on remediations, contributing to threat modeling and design reviews, and building testing tools for efficiency.
Location: Hybrid working model with onsite collaboration in Vienna, Bucharest, Barcelona, or Berlin; 25 days per year to work from a city or country of your choice.
Company
Europe's leading user-friendly platform for investing in cryptocurrencies, stocks, precious metals, and commodities, serving over 6 million customers.
What you will do
- Perform in-depth penetration tests on web apps, APIs, and infrastructure, going beyond automated tools
- Develop clear PoCs demonstrating real risks to help prioritize fixes
- Collaborate with engineers, product managers, and DevOps on remediation and re-testing
- Contribute to threat modeling and design reviews to identify security gaps early
- Build and refine scripts, tools, and testing approaches for better coverage
Requirements
- 3–5+ years hands-on experience in offensive security, penetration testing, or product security
- Strong understanding of OWASP Top 10, SANS Top 25, and real-world vulnerability manifestations
- Practical hands-on mindset for testing, exploiting, and explaining vulnerabilities end-to-end
- Ability to communicate technical findings and fixes clearly to engineering teams
- Curious, persistent approach to digging deep and connecting security dots
Culture & Benefits
- Hybrid flexibility with onsite in Vienna, Bucharest, Barcelona, or Berlin, plus 25 days work-from-anywhere per year
- Competitive pay-for-impact compensation including stock options
- Mental health support via confidential coaching and resources
- Extra time off including 3 wellbeing days in 2026 and 8 weeks gender-neutral parental leave
- Unlimited Udemy courses, free onsite dining in offices, perks, events, and recognition programs
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →