3 дня назад
Offensive Security Engineer, Penetration Testing (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Offensive Security Engineer, Penetration Testing (Cybersecurity): Leading defined-scope penetration tests across applications, APIs, cloud environments, networks, IoT devices, mobile applications, and enterprise systems with an accent on vulnerability exploitation, attack-chain validation, and security-control testing. Focus on testing AI-enabled applications, automating reconnaissance and reporting workflows, and producing actionable remediation guidance for engineering and security teams.
Location: Warsaw, Poland; hybrid work with the option to work from home two days per week and regular office presence
Company
Procter & Gamble's Information Security Protect organization conducts realistic simulated exercises and security-control testing across the enterprise.
What you will do
- Lead defined-scope penetration tests across websites, services, APIs, infrastructure, cloud environments, networks, IoT devices, mobile applications, and enterprise applications.
- Coordinate objectives, access, rules of engagement, assumptions, and readiness with intake management, senior testers, and stakeholders.
- Perform reconnaissance, vulnerability discovery, exploitation, evidence collection, reporting, and remediation validation.
- Validate related vulnerabilities and complex attack chains while operating safely within the approved scope.
- Investigate Vulnerability Disclosure Program and Bug Bounty findings and escalate complex or high-impact issues.
- Work with engineering, product, cloud, infrastructure, and security teams to explain findings and support practical remediation.
Requirements
- Bachelor's degree or equivalent Polish higher education qualification in Information Security, Cybersecurity, Computer Science, or a related field, or 2+ years of relevant experience in lieu of a degree.
- At least 2 years of experience in penetration testing, application security testing, vulnerability validation, offensive security, or related security work.
- Experience testing at least two domains, such as web applications, APIs, mobile applications, cloud infrastructure, enterprise applications, networks, IoT devices, identity platforms, or AI-enabled systems.
- Ability to automate tasks with scripts or programs in Python, PowerShell, Bash, Go, C#, JavaScript, or a similar language.
- Basic Linux command-line experience, familiarity with Windows environments, ability to read code, and hands-on experience with AWS, Azure, GCP, or another major cloud provider.
- Clear written and verbal communication skills, an adversarial mindset, and the ability to follow rules of engagement and safety guidance.
Nice to have
- Penetration testing or security certifications such as OSCP, OSWE, GPEN, GXPN, GWAPT, PNPT, or eJPT.
- Experience with CTFs, Bug Bounty programs, Vulnerability Disclosure Programs, coordinated vulnerability research, or public technical write-ups.
- Experience using AI tools or testing AI-enabled applications, LLM systems, AI agents, RAG systems, and model integrations.
- Experience with mobile, IoT, embedded systems, firmware, reverse engineering, hardware security, cloud identity attack paths, or privilege escalation.
- Familiarity with Burp Suite, Nmap, Metasploit, Frida, Ghidra, IDA, BloodHound, or cloud security testing tools.
Culture & Benefits
- Large-scale projects with access to international IT partners and technologies from the first day.
- Training and certification development paths.
- Private healthcare, P&G stock, savings plans, and sport cards.
- Regular salary reviews and promotion opportunities based on performance.
- Opportunities to change roles every few years to support professional development.
- Employment is exclusively offered under a Polish full-time employment contract (Umowa o Pracę).
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →