Senior Penetration Tester

artest Armenia
Visa Sponsorship Relocation
Apply
AI Summary

We are seeking a Senior Penetration Tester to lead offensive security engagements across web applications, APIs, mobile, networks, and cloud environments. The role requires conducting comprehensive security assessments, developing custom tooling, and mentoring junior team members. Candidates must have 4+ years of hands-on penetration testing experience and proven expertise in cloud-native systems, Kubernetes, and CI/CD pipelines.

Key Highlights
Lead end-to-end penetration testing engagements across web, API, mobile, network, and cloud environments
Perform red-team operations including initial access, privilege escalation, lateral movement, and exfiltration
Develop custom tooling and contribute to secure-by-design practices for cloud-native services
Key Responsibilities
Lead end-to-end penetration testing engagements across web applications, APIs, mobile, internal and external networks and cloud (primarily AWS)
Run red-team and assumed-breach operations including initial access, privilege escalation, lateral movement, persistence, and exfiltration
Perform security reviews of cloud-native services, Kubernetes workloads, CI/CD pipelines, and microservices
Discover and exploit vulnerabilities across real-money flows including payments, deposits, withdrawals, wallets, KYC/AML, bonus systems, and affiliate tracking
Partner with product, engineering, AppSec, payments, and fraud teams to translate findings into concrete fixes and durable controls
Develop custom tooling, scripts, and methodology where no out-of-the-box approach exists
Build and validate declarative threat models and contribute to secure-by-design practice
Mentor mid and junior testers, review their engagement plans and reports
Track new CVEs, TTPs, MITRE ATT&CK updates, and regulator advisories and translate them into concrete changes
Support pre-sales scoping, effort estimation, and pre-certification engagements for new products and jurisdictions
Serve as a trusted offensive-security advisor to product, engineering, and compliance teams
Technical Skills Required
Penetration Testing Python Bash AWS
Benefits & Perks
Learning and development opportunities
Relocation package (tickets, hotel, visa support)
Private medical coverage
20 non-business days per year + 6 paid sick days
Nice to Have
OSWE, OSEP, OSED, CRTO, BSCP, ARTE, or GRTE certification
In-depth experience architecting secure services on Kubernetes and AWS
Prior iGaming, fintech, or payments domain experience
Public CVEs, advisories, write-ups, or conference talks
HTB Pro Lab completions or real CTF placements
Open-source contributions to offensive or defensive tooling

Job Description


We build tech with art at the heart.


Artest is a product-focused tech company based in Yerevan. We design products, build software systems, and grow a strong quality culture — with art at the heart of everything we do.

We believe every professional should feel seen, inspired, and trusted. At Artest, we’ve created a space where ideas come to life through collaboration, passion, and precision.


‼️ It's an office-based role – NO remote or hybrid options. ‼️


We invite a Senior Penetration Tester to join our team.


Responsibilities:

✔️ Lead end-to-end penetration testing engagements across web applications, APIs, mobile, internal and external networks and cloud (primarily AWS).

✔️ Run red-team and assumed-breach operations - initial access, privilege escalation, lateral movement, persistence, exfiltration - including against fraud and detection stacks. ✔️ Perform security reviews of cloud-native services, Kubernetes workloads, CI/CD pipelines, and microservices.

✔️ Discover and exploit vulnerabilities across real-money flows - payments, deposits and withdrawals, wallets, KYC / AML, bonus systems, and affiliate tracking.

✔️ Partner with product, engineering, AppSec, payments, and fraud teams to translate findings into concrete fixes and durable controls.

✔️ Develop custom tooling, scripts, and methodology where no out-of-the-box approach exists.

✔️ Build and validate declarative threat models and contribute to "secure by design" practice.

✔️ Mentor mid and junior testers, review their engagement plans and reports.

✔️ Track new CVEs, TTPs, MITRE ATT&CK updates, and regulator advisories - translate them into concrete changes here.

✔️ Support pre-sales scoping, effort estimation, and pre-certification engagements for new products and jurisdictions.

✔️ Serve as a trusted offensive-security advisor to product, engineering, and compliance teams.


Requirements:

✔️ Minimum 4 years of hands-on penetration testing or offensive-security experience.

✔️ Proven track record across at least three of: web / API, internal, external network, cloud (AWS / GCP), mobile (iOS / Android).

✔️ OSCP or an equivalent in-the-box certification.

✔️ Strong working knowledge of SAST/SCA/DAST tooling, AWS/GCP, MITRE ATT&CK, OWASP ASVS / WSTG, PTES.

✔️ Understanding of the data flow, MVC model.

✔️ Understanding of supply chain attacks.

✔️ Good reporting skills.

✔️ Comfortable scripting in Python plus Bash.

✔️ Knowledge at least one of major cloud provider's IAM model.

✔️ Experience pentesting cloud-native systems and Kubernetes environments, plus the CI/CD pipelines around them (GitLab, GitHub Actions, Jenkins) and IaC (Terraform, Helm, CloudFormation).

✔️ Strong written and verbal communication in English.

✔️ Experience balancing security and business demands under release pressure.

✔️ Familiarity with industry regulations, frameworks, and practices: PCI DSS, ISO 27001, NIST, GDPR.


PREFERRED QUALIFICATIONS:

✔️ One of offensive-security certifications: OSWE, OSEP, OSED, CRTO, BSCP, ARTE, GRTE.

✔️ In-depth experience architecting secure services on Kubernetes and AWS.

✔️ Prior iGaming, fintech, or payments domain experience.

✔️ Public CVEs, advisories, write-ups, conference talks.

✔️ HTB Pro Lab completions, real CTF placements.

✔️ Open-source contributions to offensive or defensive tooling.


We offer excellent benefits, including but not limited to:

💻 Learning and development opportunities and interesting, challenging tasks.

✈️ Relocation package (tickets, staying in a hotel for up to 2 weeks, and visa relocation support for our employees and their family members).

📚 Opportunity to develop language skills, with partial compensation for the cost of English/Spanish language classes (for localization purposes).

🏥 Private medical coverage.

🏝 Time for proper rest, with 20 non-business days per year and an additional 6 paid sick days.

📈 Competitive remuneration level with annual review.

🤝 Team building activities.


Similar Jobs

Explore other opportunities that match your interests

Senior Penetration Tester

Testing
2h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

big stars

Serbia

RF Engineer

Testing
2h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

vantari recruitment group

Greater Barcelona Metropolitan Area

Electrical Engineer

Testing
18h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Raytheon

United State

Subscribe our newsletter

New Things Will Always Update Regularly