Offensive Security Engineer / Penetration Tester

Job not on LinkedIn

🔥 0 minutes ago

🌐 Poland, Bulgaria, +3 more countries – Remote

infoinfo

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 12%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Genesis Tech

Genesis Tech

1001 - 5000 employees

📣 Marketing

💼 Consulting

📦 Logistics

💰 Series B on 2015-01

Marketing • Consulting • Logistics

Genesis Tech is a Ukrainian co-founding IT company that partners with top entrepreneurs in Central and Eastern Europe to build global tech businesses. Known as one of the most powerful tech teams in Ukraine and the CEE region, Genesis Tech has succeeded in publishing applications utilized by millions around the globe, with 400 million downloads worldwide. The company develops a range of tech products across various fields, including education, social discovery, dating, and health & fitness, integrating creative authoring with advanced AI technology. Genesis Tech is dedicated to enhancing the quality of life by creating fast-growing products, participating in cyber security, and spearheading educational initiatives. It's recognized for its entrepreneurial management structure and its influence in the tech industry.

📋 Description

• Deliver end-to-end penetration tests of web and mobile applications, Active Directory and cloud environments • Handle engagements from scoping and reconnaissance through exploitation, post-exploitation, evidence collection and retesting • Validate findings from Application Security and Infrastructure Security services • Triage automated scan output by eliminating false positives, confirming exploitability and business impact, and assigning accurate risk ratings • Write client-facing technical reports in English with reproduction steps, evidence, business-impact framing and practical remediation guidance • Communicate directly with clients through kick-off calls, status updates, report walkthroughs, remediation Q&A and retest agreement • Build automation and internal tooling to shorten reconnaissance, enumeration and active-scanning phases • Develop AI-agent-based workflows for offensive security testing • Create and maintain internal methodology, testing checklists and knowledge bases • Research new attack techniques, evaluate tooling and share findings with the team • Deliver client engagements end to end in the first months • Build the internal methodology for AWS cloud security assessment • Become the team's reference point on at least one platform within a year

🎯 Requirements

• 2.5+ years of hands-on commercial penetration testing experience • Several penetration-testing engagements delivered end to end • Experience writing penetration-testing reports • At least one practical certification — OSCP, CPTS, GPEN or CWEE, or a proven equivalent • Web application testing according to the OWASP Web Security Testing Guide and beyond • Experience identifying authentication and authorisation flaws, IDOR, injection, SSRF, insecure deserialization and business-logic abuse • Burp Suite Professional as a daily tool • Mobile application testing based on OWASP MASTG for Android and/or iOS • Static and dynamic mobile application analysis • Traffic interception and certificate-pinning bypass • Knowledge of insecure local storage, IPC and platform misuse • Working knowledge of Active Directory and internal network attacks • Knowledge of enumeration, Kerberos abuse, credential relaying, lateral movement and privilege-escalation paths • Scripting in Python and/or Bash • Ability to read application source code and trace vulnerable patterns in at least one of PHP, Java, C#, JS/TS or Python • English at B2 or above • Nice-to-have: second practical certification: BSCP, CWEE, CAPE, GWAPT, OSWE, CRTO, eWPTX or eMAPT • Nice-to-have: cloud security testing in AWS, Azure or GCP • Nice-to-have: hands-on experience or genuine interest in AI and LLM security • Nice-to-have: public technical contributions such as CVEs, open-source tooling, research write-ups, conference talks or high-quality bug-bounty reports

🏖️ Benefits

• Flexible hours and the option to work from anywhere that suits you • Medical insurance • 20 paid vacation days per year • Unlimited sick leave • All the equipment you need for work • Compensation for professional training • Access to the internal learning platform and lectures • Corporate events and networking • Free sports training • Corporate discounts • Massage when visiting the office • Support for colleagues and their families serving in the Defence Forces • Support for veterans • Assistance in case of harm to health or property caused by the war

Apply Now

Similar Jobs

🔥 19 hours ago

MWDN

51 - 200

💼 Consulting

📦 Logistics

🏥 Healthcare

Security Researcher investigating browser, mobile, and AI-driven fraud signals. Supporting MWDN’s IAM cybersecurity client with detection research, experiments, and SDK requirements.

Android

Cyber Security

iOS

Java

JavaScript

Kotlin

Objective-C

Python

Swift

TypeScript

🕒 3 days ago

Callstack

51 - 200

💼 Consulting

📣 Marketing

IT Security Officer securing systems, devices, identities, and data at Callstack, a cross-platform development consultancy. Managing cybersecurity, infrastructure, compliance, incident response, and security awareness.

AWS

Azure

Cloud

Cyber Security

DNS

Firewalls

Google Cloud Platform

Linux

MacOS

🕒 3 days ago

Attio

11 - 50

💼 Consulting

📣 Marketing

☁️ SaaS

Security Engineering Lead building Product Security for Attio’s AI-native CRM. Securing customer data, leading incident response, and hiring the security team.

🕒 3 days ago

Omilia - Conversational Intelligence

201 - 500

💼 Consulting

🛡️ Insurance

✈️ Travel

Senior Cloud Security Engineer securing Omilia’s AWS conversational AI platform. Automating Terraform, GitOps, CI/CD, and cloud compliance across distributed engineering teams.

AWS

Cloud

Kubernetes

Python

SDLC

Terraform

Go

🕒 5 days ago

Interact Software

201 - 500

🏢 Enterprise

☁️ SaaS

⚡ Productivity

Cyber Security Engineer building automated security capabilities for Interact’s enterprise intranet platform. Improving Splunk, cloud controls, and incident response through engineering and automation.

Cloud

Cyber Security

Firewalls

Splunk