Назад
Company hidden
3 дня назад

Offensive Security Engineer, Penetration Testing (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Offensive Security Engineer, Penetration Testing (Cybersecurity): Leading defined-scope penetration tests across applications, APIs, cloud environments, networks, IoT devices, mobile applications, and enterprise systems with an accent on vulnerability exploitation, attack-chain validation, and security-control testing. Focus on testing AI-enabled applications, automating reconnaissance and reporting workflows, and producing actionable remediation guidance for engineering and security teams.

Location: Warsaw, Poland; hybrid work with the option to work from home two days per week and regular office presence

Company

Procter & Gamble's Information Security Protect organization conducts realistic simulated exercises and security-control testing across the enterprise.

What you will do

  • Lead defined-scope penetration tests across websites, services, APIs, infrastructure, cloud environments, networks, IoT devices, mobile applications, and enterprise applications.
  • Coordinate objectives, access, rules of engagement, assumptions, and readiness with intake management, senior testers, and stakeholders.
  • Perform reconnaissance, vulnerability discovery, exploitation, evidence collection, reporting, and remediation validation.
  • Validate related vulnerabilities and complex attack chains while operating safely within the approved scope.
  • Investigate Vulnerability Disclosure Program and Bug Bounty findings and escalate complex or high-impact issues.
  • Work with engineering, product, cloud, infrastructure, and security teams to explain findings and support practical remediation.

Requirements

  • Bachelor's degree or equivalent Polish higher education qualification in Information Security, Cybersecurity, Computer Science, or a related field, or 2+ years of relevant experience in lieu of a degree.
  • At least 2 years of experience in penetration testing, application security testing, vulnerability validation, offensive security, or related security work.
  • Experience testing at least two domains, such as web applications, APIs, mobile applications, cloud infrastructure, enterprise applications, networks, IoT devices, identity platforms, or AI-enabled systems.
  • Ability to automate tasks with scripts or programs in Python, PowerShell, Bash, Go, C#, JavaScript, or a similar language.
  • Basic Linux command-line experience, familiarity with Windows environments, ability to read code, and hands-on experience with AWS, Azure, GCP, or another major cloud provider.
  • Clear written and verbal communication skills, an adversarial mindset, and the ability to follow rules of engagement and safety guidance.

Nice to have

  • Penetration testing or security certifications such as OSCP, OSWE, GPEN, GXPN, GWAPT, PNPT, or eJPT.
  • Experience with CTFs, Bug Bounty programs, Vulnerability Disclosure Programs, coordinated vulnerability research, or public technical write-ups.
  • Experience using AI tools or testing AI-enabled applications, LLM systems, AI agents, RAG systems, and model integrations.
  • Experience with mobile, IoT, embedded systems, firmware, reverse engineering, hardware security, cloud identity attack paths, or privilege escalation.
  • Familiarity with Burp Suite, Nmap, Metasploit, Frida, Ghidra, IDA, BloodHound, or cloud security testing tools.

Culture & Benefits

  • Large-scale projects with access to international IT partners and technologies from the first day.
  • Training and certification development paths.
  • Private healthcare, P&G stock, savings plans, and sport cards.
  • Regular salary reviews and promotion opportunities based on performance.
  • Opportunities to change roles every few years to support professional development.
  • Employment is exclusively offered under a Polish full-time employment contract (Umowa o Pracę).

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →