Перейти к основному содержимому
IGAMINGHUNT

Senior Penetration Tester

УдалённоSerbia, Poland только
Опубликовано
Роль
Безопасность
Опыт
Синьор
Занятость
Полная занятость
Зарплата не указана
Проверьте доступность

Доступно для: RS, PL only. Укажите, откуда вы работаете, чтобы проверить доступность.

Коротко по делу

Senior penetration tester with 4+ years in offensive security, OSCP or equivalent, and hands-on testing across at least three of web/API, networks, infrastructure, cloud, or mobile. Needs Python/Bash scripting, AWS/GCP security knowledge, Kubernetes/CI/CD/IaC testing experience, and Upper-Intermediate English. Remote role limited to Serbia and Poland.

Ключевые навыки

AWS/GCPKubernetesPenetration Testing

Обязательные навыки

SASTSCADASTMITRE ATT&CKOWASP ASVSOWASP WSTGPTESMVCPythonBashGitLab/GitHub Actions/JenkinsTerraform/Helm/CloudFormationPCI DSSISO 27001NISTGDPR

Желательные навыки

OSWEOSEPOSEDCRTOBSCPARTEGRTEHTB Pro Labs

Обязательные языки

English Upper-Intermediate

Чем предстоит заниматься

  • Plan and execute penetration testing activities across web applications, APIs, mobile applications, internal and external infrastructure, and AWS cloud environments
  • Perform offensive security exercises, including red team and assumed-breach scenarios covering privilege escalation, lateral movement, persistence, and data exfiltration
  • Assess the security of cloud-native services, Kubernetes environments, microservices, and CI/CD pipelines
  • Identify vulnerabilities affecting payment systems, wallets, KYC/AML processes, bonus mechanisms, affiliate tracking, and other business-critical workflows
  • Work with Product, Engineering, AppSec, Payments, and Fraud teams to prioritize findings and support remediation efforts
  • Develop custom scripts and internal tools to improve testing capabilities where standard solutions are insufficient
  • Contribute to threat modeling activities and support secure-by-design initiatives
  • Review penetration testing plans and reports, and provide technical guidance to junior and middle security specialists
  • Research emerging vulnerabilities, MITRE ATT&CK techniques, and security advisories, and translate them into actionable improvements
  • Support security assessments for new products, releases, and market launches, including effort estimation and pre-certification activities
  • Act as a security advisor for technical and business stakeholders on offensive security matters

Что требуется

  • 4+ years of hands-on experience in penetration testing or offensive security
  • Proven practical experience in at least three of the following areas: web applications/APIs, internal networks, external infrastructure, cloud environments (AWS/GCP), mobile applications (iOS/Android)
  • OSCP or an equivalent offensive security certification
  • Strong knowledge of SAST, SCA, DAST, AWS/GCP, MITRE ATT&CK, OWASP ASVS, OWASP WSTG, and PTES
  • Good understanding of application architecture, including MVC and data flow principles
  • Knowledge of supply chain attack techniques
  • Experience writing scripts in Python and Bash
  • Understanding of IAM models within at least one major cloud provider
  • Hands-on experience testing Kubernetes-based environments, cloud-native applications, CI/CD pipelines (GitLab, GitHub Actions, Jenkins), and Infrastructure as Code solutions (Terraform, Helm, CloudFormation)
  • Strong reporting, documentation, and communication skills
  • Ability to balance security priorities with business and release deadlines
  • Solid understanding of security frameworks and compliance standards, including PCI DSS, ISO 27001, NIST, and GDPR
  • At least Upper-Intermediate level of English
  • Preferred: advanced offensive security certifications such as OSWE, OSEP, OSED, CRTO, BSCP, ARTE, or GRTE
  • Preferred: experience designing secure architectures for Kubernetes and AWS environments
  • Preferred: previous background in iGaming, fintech, or payment products
  • Preferred: public security research, CVEs, advisories, technical publications, or conference presentations
  • Preferred: completion of HTB Pro Labs or strong CTF achievements
  • Preferred: contributions to open-source offensive or defensive security projects

Преимущества

  • Generous annual leave plus paid sick leave
  • Comprehensive benefits package including private medical and dental insurance, sports allowance, and food vouchers
  • Professional development support with an education budget and learning opportunities
  • Modern office with complimentary meals, snacks, and employee wellness initiatives
  • Recognition programs, regular team events, and gifts for personal milestones

IGAMINGHUNT is hiring a CTO to lead the technical organization behind a large-scale iGaming platform.

IGamingСтартап

Детали

Способ откликаDom
Зарплата не указана