🇵🇱 Warsaw, Poland · 21h ago

Senior Penetration Tester

LionHires Recruitment

LinkedInseniorEnglish-friendly
About the RoleAre you an offensive security expert who loves breaking complex cloud architectures, real-money payment pipelines, and modern microservices? We are seeking a Senior Penetration Tester to spearhead end-to-end testing, lead red-team operations, and serve as a trusted offensive advisor to our high-scale engineering teams.About the ClientOur partner is a tech company building product engineering across Fintech, iGaming, and Marketing. They turn innovative ideas into high-performing engines and launch them at scale. As their exclusive recruitment partner, we manage their full-cycle talent acquisition.What You Will DoLead End-to-End Engagements: Execute penetration testing across web applications, mobile platforms, external/internal networks, and cloud infrastructure (primarily AWS).Run Advanced Operations: Conduct red-team and assumed-breach exercises—including initial access, lateral movement, and privilege escalation—to test and harden our detection and fraud stacks.Secure Cloud-Native Architecture: Perform rigorous security reviews of Kubernetes workloads, CI/CD pipelines, microservices, and cloud-native services.Deep-Dive Analysis: Identify and exploit complex vulnerabilities within real-money flows, including payments, wallets, KYC/AML systems, and affiliate tracking.Collaborate & Influence: Partner closely with product, engineering, and AppSec teams to translate security findings into durable, concrete controls and architectural fixes.Innovate Tooling: Develop custom scripts and tooling to bridge capability gaps and automate testing methodologies where out-of-the-box solutions fall short.Mentor & Advise: Act as a trusted security advisor to engineering and compliance teams, while mentoring mid-level and junior testers on engagement strategies and high-quality reporting.Stay Ahead of Threats: Proactively track new CVEs, TTPs, and MITRE ATT&CK developments, translating intelligence into actionable defensive hardening.What You BringExperience: 4+ years of hands-on offensive security experience, with a proven track record across at least three of the following: web/API, networks, cloud (AWS/GCP), or mobile (iOS/Android).Core Certification: OSCP or an equivalent in-the-box certification.Technical Proficiency: Strong scripting skills in Python and Bash for custom tool development and automation.Cloud & Infrastructure: Deep expertise in cloud-native systems, Kubernetes, IaC (Terraform, Helm, CloudFormation), and CI/CD security (GitLab/GitHub Actions/Jenkins).Foundational Knowledge: Solid working knowledge of SAST/SCA/DAST tooling, MITRE ATT&CK, OWASP ASVS/WSTG, and cloud IAM models.Regulatory Awareness: Familiarity with industry regulations and frameworks such as PCI DSS, ISO 27001, NIST, and GDPR.Communication: Strong written and verbal communication skills; ability to balance rigorous security requirements with the demands of a fast-paced release cycle.Bonus Points: Advanced certifications (OSWE, OSEP, OSED, CRTO, etc.), fintech/payments domain experience, or a portfolio of public CVEs, write-ups, and CTF/Pro Lab accomplishments.What's in It for YouTrue Ownership: You will have the autonomy to influence our security roadmap and make architectural decisions that protect our production environments.Impactful Work: Your work directly safeguards real-money flows and critical financial data, making a tangible difference in the security of our users.Collaborative Culture: Join a cross-functional team of experts in engineering, fraud, and payments who value security and knowledge sharing.Continuous Growth: We invest in your professional development through support for advanced certifications, conference attendance, and research time.Competitive Benefits: We offer a comprehensive benefits package, including competitive compensation, health coverage, and flexible working arrangements.

Sourced from LinkedIn. Relocantly aggregates public job postings; apply on the original site.