Lead end-to-end penetration testing for web applications and APIs, focusing on advanced security assessments and remediation. Requires 4+ years of offensive security experience, expertise in web/API, Active Directory, and scripting. Must communicate risks to stakeholders and manage engagements independently.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Job Description
Hello,
We are called People More because we treat our employees with respect, but also because the projects we work on are for people and should be easy and pleasant to use. We are technological, but we look at the bigger picture :)
The company is made up of people with a huge client base in the country and abroad, for whom we build projects from scratch (UX, UI, frontend, backend, mobile) or in part. We work directly for our clients and also support our partners in their own solutions. This ensures a wide range of projects and the ability to change! We work with clients all over the world.
For the project that we are working on with our partner, we are looking for Penetration Tester - WebAPP and API.
Your Duties Will Include
- Lead end-to-end penetration tests and remediation retests.
- Perform advanced Active Directory assessments, including privilege escalation, lateral movement, and attack path analysis.
- Develop custom scripts and PoC exploits using Python, PowerShell, or Bash.
- Manage engagements from scoping and estimation to reporting.
- Review technical findings and support pre-sales activities.
- Communicate risks and recommendations to technical and non-technical stakeholders.
- 4+ years of hands-on offensive security experience, preferably in a cybersecurity consultancy or multi-client environment.
- Strong expertise in at least three areas: web/API, network, mobile, or Active Directory testing.
- Ability to independently lead penetration testing engagements—from scoping and estimation to reporting and remediation retesting.
- Advanced proficiency with tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, NetExec, Cobalt Strike, and Frida.
- Experience developing scripts and PoC exploits using Python, PowerShell, or Bash.
- Strong client-facing, technical reporting, and stakeholder communication skills.
- At least one certification: OSCP, CRTP, CRTO, CREST CRT, CPSA, CCT App, or CCT Infra.
- Very good English and Polish
Interested in remote work opportunities in QA & Testing? Discover QA & Testing Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
- We are open and honest and we solve problems instead of generating them.
- Maybe it’s obvious, but we really respect our employees and associates. We used to be software developers, too, and we appreciate that job!
- A small team
- An international working environment and international projects
- Private medical care
- Sports card
- Training courses
- Work that is 100% remote (unless you prefer another system)
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
Why it’s a good idea to work with People More?
- If you are not satisfied with your work or your tasks, we’ll find a way out together!
- If you get bored, we will offer you a new product and new, fascinating tasks
- We will work on your brand together: you will get an opportunity to attend conferences, including as a speaker, and we will help you publish in recognized magazines and online
- We will facilitate your access to challenges that are usually difficult to get
- At any time, you can talk directly to the board of People More—we talk your language because the company’s founders are software developers and designers!
- A friendly remote initial interview
- A remote technical talk
- The decision to work together!
85 - 110 zł/h
contract
B2B
Location
Kraków / remote
Similar Jobs
Explore other opportunities that match your interests