World
Country
Language

poland Poland

portugal Portugal

netherlands Netherlands

Pentester

  • Hybrid/On-site
  • English/Polish
  • Banking
  • Regular
Add to Job Cart RECOMMEND A CANDIDATE

Join us and hack for Good – Protect What Matters!

Warsaw-based opportunity to work in hybrid model

As a Pentester, you will be working for our client, a leading global financial institution known for delivering a wide range of innovative financial services across capital markets, risk management, and digital platforms. In this role, you will be part of an elite internal penetration testing team assessing critical systems, applications, and cloud infrastructures. The client is focused on secure software development, operational resilience, and proactive risk mitigation.
You will test high-value systems, access source code, and work directly with engineers to implement secure solutions across global environments.

Your main responsibilities: Perform penetration tests on internal web applications, cloud environments, and infrastructure

  • Identify and report vulnerabilities with clear technical and business impact
  • Analyse source code, configurations, and systems to support deep security assessments
  • Develop proof-of-concept exploits or demonstrate real-world attack vectors
  • Collaborate with engineers to recommend fixes and propose systemic improvements
  • Document findings in structured reports for technical and non-technical audiences
  • Participate in red team exercises and threat simulation scenarios
  • Review server, network, and cloud configurations for weaknesses
  • Share knowledge and techniques with peers in the internal security community
  • Contribute to the continuous evolution of internal testing tools and frameworks

You’re ideal for this role if you have:

  • Proven experience in penetration testing across web applications, cloud, and infrastructure
  • Strong understanding of web security principles and ability to build exploit chains
  • Proficiency in analysing systems via source code review and reverse engineering
  • Familiarity with tools such as Burp Suite, Wireshark, netcat, and Ghidra
  • Knowledge of one or more programming languages like Java, Python, JavaScript, or C++
  • Solid understanding of the TCP/IP stack and common network protocols
  • High-level knowledge of cryptographic concepts and their implementation risks
  • Experience developing or customizing proof-of-concept exploits
  • Awareness of security concerns in cloud-native architectures

It is a strong plus if you have:

  • Experience in adopting or crafting custom proof of concept exploits
  • Knowledge of common cloud products and solutions
  • Bachelor of Science in Computer Science, Cyber-Security, or Information Security is preferred
  • Experience or trainings in related disciplines such as computer security, network security, network device management, IT administration, cloud security, or infrastructure pentesting is preferred
  • Certificates (or equivalent knowledge) such as OSCP, OSEP, OSWP

#GETREADY  to meet with us!

We would like to meet you. If you are interested please apply and attach your CV in English or Polish, including a statement that you agree to our processing and storing of your personal data. You can always also apply by sending us an email at recruitment@itds.pl.

Internal number #7217

Benefits

Access to Healthcare
fintech-delivery
Access to Multisport
Training platforms
Access to Pluralsight

Apply for this job now

    I agree to receive marketing information from ITDS Polska to the e-mail address provided
    The data controller of your personal data is ITDS Polska sp. z o.o. We process your personal data for recruitment process for selected jobs, to inform you of similar jobs in the future and to pursue ITDS's other legitimate interests, such as handling correspondence, securing our recruitment processes or pursuing/defending against claims. Also, by providing ITDS with personal data in the scope specified in art. 22(1a) § 1 of Labor Code, you agree that ITDS will process them for the purpose of recruitment. You have the right to withdraw your consent (the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal), request access to personal data, their rectification, deletion or restriction of processing; to object to processing, as well as the right to data portability; to lodge a complaint with the supervising authority. Please find more information in our Privacy Policy.

    You can report violations in accordance with ITDS's Whistleblower Procedure available here.