Link Group
2 months ago
Pentester WebAPP and API
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- Link Group
- Location
- Polska, mazowieckie, Warszawa Poland
- Posted
- 2 months ago
Job description
Key Responsibilities (What You’ll Do) Advanced Technical Testing: Personally lead and execute end-to-end penetration tests across web applications, APIs, mobile apps (iOS/Android), cloud environments, and internal/external networks. Deep Active Directory Assessments: Perform sophisticated AD security testing, including privilege escalation, lateral movement, delegation/ACL abuse, and attack path analysis. Exploit Development: Write custom scripts, tooling, and proof-of-concept (PoC) exploits using Python, PowerShell, and/or Bash. End-to-End Engagement Management: Own the lifecycle of assignments—from initial scoping and effort estimation to final report delivery and remediation retesting. Quality Assurance & Pre-Sales: Review and QA technical findings/reports from the team, and provide technical input during scoping calls and proposal creation. Client & Stakeholder Communication: Act as the primary technical point of contact, translating complex technical risks into clear insights for both devs and non-technical executives. Required Skills & Experience (What You’ll Need) Experience: ~5+ years of hands-on offensive security experience, ideally within a cybersecurity consultancy or multi-client delivery environment. Core Depth: Proven expertise in at least three domains: web applications, network, mobile, or Active Directory testing. Tooling Infrastructure: Mastery of industry-standard tools (Burp Suite, Nmap, Metasploit, BloodHound, Impacket, CrackMapExec/NetExec, Cobalt Strike, Frida, etc.). Certifications (Minimum of ONE required): OSCP (Offensive Security Certified Professional) CRTP / CRTO (Active Directory/Red Team) CREST CRT / CPSA (CCT App or Infra strongly preferred) Soft Skills: Exceptional report-writing skills and fluent professional English. Highly Desirable / Nice to Have Advanced certifications (OSEP, OSWE, OSED, CRTE, SANS GXPN/GWAPT, or Cloud offensive certs). Prior experience within a Big 4 firm or an established boutique security consultancy. Hands-on exposure to AWS/Azure/GCP cloud environments and Kubernetes/containers. Active community presence: Published research, CVEs, open-source tooling contributions, conference talks, or top CTF achievements.
Required skills
- quality assurance
- python
- aws
- kubernetes
- android
- gcp
- azure
- containers
- bash
- powershell
- cloud environments
- active directory
- api
- mobile apps
- ios
- web applications
- pre-sales
- penetration testing
- oscp
- technical reports
- report writing
- mobile testing
- burp suite
- metasploit
- stakeholder communication
- client communication
- ctf
- big 4
- network testing
- scoping
- cpsa
- technical risks
- proposal creation
- crtp
- effort estimation
- nmap
- offensive security
- cves
- exploit development
- oswe
- frida
- cobalt strike
- engagement management
- open-source tooling
- osep
- professional english
- bloodhound
- crte
- crest crt
- internal networks
- crto
- technical point of contact
- osed
- technical findings
- external networks
- lateral movement
- offensive security certified professional
- impacket
- proof-of-concept (poc)
- scoping calls
- conference talks
- web applications testing
- published research
- netexec
- attack path analysis
- community presence
- privilege escalation
- report delivery
- remediation retesting
- cybersecurity consultancy
- active directory testing
- crackmapexec
- cct app
- cct infra
- sans gxpn
- sans gwapt
- cloud offensive certifications
- security consultancy
Interested in this position?
Create your free account and tailor your CV to match this job.