Senior Penetration Tester

35 - 40 USDNet per hour - B2B
Security

Senior Penetration Tester

Security
Zabłocie 43A, Kraków +5 Locations

Spyrosoft

Full-time
B2B
Senior
Hybrid
35 - 40 USD
Net per hour - B2B

Job description

Project description:

We are looking for an experienced Senior Pentester who will be responsible for conducting advanced security assessments of applications, systems, and IT infrastructure. In this role, you will work on projects covering web and mobile applications as well as infrastructure environments, identifying vulnerabilities and supporting clients in effectively mitigating them. The position also involves designing attack scenarios, improving testing methodologies, and collaborating with both technical and business teams.

Main responsibilities:

  • Perform penetration tests of web applications, mobile applications, and infrastructure (internal and external)

  • Identify, analyze, and report vulnerabilities along with remediation recommendations

  • Develop realistic attack scenarios (manual and partially automated)

  • Collaborate with development and DevOps teams to improve security posture

  • Support threat modeling and security architecture reviews

  • Contribute to the development of internal tools and testing standards

  • Mentor junior and mid-level team members

Tech stack:

  • Web & API Security: Burp Suite Professional, OWASP Top 10, ASVS, OWASP API Security

  • Mobile Security: MobSF, Frida, Objection, Android & iOS Security Testing

  • Infrastructure & Network: Nmap, Nessus, Metasploit, Active Directory, Wireshark

  • Cloud Security: AWS, Azure, GCP (Security Services)

  • Methods & Frameworks: Manual Exploitation, Secure Code Review, SSDLC, PTES

  • Operating Systems: Kali Linux, Parrot OS, Windows Server, Linux (Debian/RHEL)

Requirements:

  • Minimum 5 years of hands-on experience in penetration testing

  • Strong knowledge of web application security (e.g., OWASP Top 10, ASVS, OWASP Top 10 API)

  • Experience in mobile application testing (Android/iOS)

  • Solid understanding of infrastructure security (networks, systems, Active Directory, cloud)

  • Proven ability to manually exploit vulnerabilities

  • Familiarity with tools such as Burp Suite, Metasploit, Nmap, Nessus, MobSF, Frida or similar

  • Ability to produce clear technical and executive-level reports

  • Strong analytical skills and an “attacker mindset”

Tech stack

    Polish

    B2

    English

    C1

    Burp Suite Professional

    advanced

    Metasploit Framework

    advanced

    Nmap

    advanced

    Nessus

    advanced

    Wireshark

    advanced

    Kali Linux

    advanced

    OWASP ZAP

    advanced

    Python

    advanced

    Docker

    advanced

    Amazon AWS

    advanced

Office location

About the company

Spyrosoft

Spyrosoft is a leading technology company specializing in software development and IT services. The company provides a wide range of expertise including artificial intelligence, cloud services, cybersecurity, digital pro...

Company profile

Senior Penetration Tester

35 - 40 USDNet per hour - B2B
Summary of the offer

Senior Penetration Tester

Zabłocie 43A, Kraków
Spyrosoft
35 - 40 USDNet per hour - B2B
By applying, I consent to the processing of my personal data for the purpose of conducting the recruitment process. Informujemy, że administratorem danych jest SpyroSoft S.A. z siedzibą w 50-141 Wrocław, pl. Nowy Targ 28 (dalej jako "administrator").... MoreThis site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.