World
Country
Language

poland Poland

portugal Portugal

netherlands Netherlands

Pentester

  • Hybrid/On-site
  • English/Polish
  • Banking
  • Regular
Dodaj do koszyka POLEĆ KANDYDATA

Join us and hack for Good – Protect What Matters!

Warsaw-based opportunity to work in hybrid model

As a Pentester, you will be working for our client, a leading global financial institution known for delivering a wide range of innovative financial services across capital markets, risk management, and digital platforms. In this role, you will be part of an elite internal penetration testing team assessing critical systems, applications, and cloud infrastructures. The client is focused on secure software development, operational resilience, and proactive risk mitigation.
You will test high-value systems, access source code, and work directly with engineers to implement secure solutions across global environments.

Your main responsibilities: Perform penetration tests on internal web applications, cloud environments, and infrastructure

  • Identify and report vulnerabilities with clear technical and business impact
  • Analyse source code, configurations, and systems to support deep security assessments
  • Develop proof-of-concept exploits or demonstrate real-world attack vectors
  • Collaborate with engineers to recommend fixes and propose systemic improvements
  • Document findings in structured reports for technical and non-technical audiences
  • Participate in red team exercises and threat simulation scenarios
  • Review server, network, and cloud configurations for weaknesses
  • Share knowledge and techniques with peers in the internal security community
  • Contribute to the continuous evolution of internal testing tools and frameworks

You’re ideal for this role if you have:

  • Proven experience in penetration testing across web applications, cloud, and infrastructure
  • Strong understanding of web security principles and ability to build exploit chains
  • Proficiency in analysing systems via source code review and reverse engineering
  • Familiarity with tools such as Burp Suite, Wireshark, netcat, and Ghidra
  • Knowledge of one or more programming languages like Java, Python, JavaScript, or C++
  • Solid understanding of the TCP/IP stack and common network protocols
  • High-level knowledge of cryptographic concepts and their implementation risks
  • Experience developing or customizing proof-of-concept exploits
  • Awareness of security concerns in cloud-native architectures

It is a strong plus if you have:

  • Experience in adopting or crafting custom proof of concept exploits
  • Knowledge of common cloud products and solutions
  • Bachelor of Science in Computer Science, Cyber-Security, or Information Security is preferred
  • Experience or trainings in related disciplines such as computer security, network security, network device management, IT administration, cloud security, or infrastructure pentesting is preferred
  • Certificates (or equivalent knowledge) such as OSCP, OSEP, OSWP

#GETREADY  to meet with us!

We would like to meet you. If you are interested please apply and attach your CV in English or Polish, including a statement that you agree to our processing and storing of your personal data. You can always also apply by sending us an email at recruitment@itds.pl.

Internal number #7217

Benefits

Access to +100 projects
Access to Healthcare
fintech-delivery
Access to Multisport
Training platforms
Access to Pluralsight
Make your CV shine
B2B or Permanent Contract
Flexible & remote work
Flexible hours and remote work

Aplikuj na to stanowisko

    Wyrażam zgodę na otrzymywanie informacji marketingowych od ITDS Polska na podany adres e-mail.
    Administratorem Twoich danych osobowych jest ITDS Polska sp. z o.o. Przetwarzamy Twoje dane osobowe w celu prowadzenia rekrutacji na wybrane stanowiska, informowania Cię o podobnych ofertach pracy w przyszłości oraz w celu realizacji innych prawnie uzasadnionych interesów ITDS, takich jak obsługa korespondencji, zabezpieczenie naszych procesów rekrutacyjnych lub dochodzenie/obrona przed roszczeniami. Ponadto, przekazując ITDS dane osobowe w zakresie określonym w art. 22(1a) § 1 Kodeksu pracy, wyrażasz zgodę na ich przetwarzanie przez ITDS w celu rekrutacji. Przysługuje Ci prawo do cofnięcia zgody (cofnięcie zgody nie wpływa na zgodność z prawem przetwarzania, którego dokonano na podstawie zgody przed jej cofnięciem), żądania dostępu do danych osobowych, ich sprostowania, usunięcia lub ograniczenia przetwarzania; wniesienia sprzeciwu wobec przetwarzania, a także prawo do przenoszenia danych; wniesienia skargi do organu nadzoru. Więcej informacji można znaleźć w naszej Polityce Prywatności lub kontaktując się z nami pod adresem privacy@itds.pl.

    Naruszenia można zgłaszać zgodnie z Procedurą Sygnalizowania Nieprawidłowości ITDS, dostępną pod linkiem.