Ethical Hacker / Pentester
RUBLON sp. z o.o.
Zobacz wszystkie oferty
13000 - 18000 PLN
Mid
Zielona Góra
Wygasa 26 wrz 2026
22 dni temu
W skrócie
Ethical Hacker/Pentester role focusing on next-gen MFA technologies for RUBLON sp. z o.o. Responsibilities include researching Windows/AD security, analyzing authentication protocols, and documenting findings. Requires pentesting experience on Microsoft platforms, understanding of AD security, and scripting skills.
Słowa kluczowe
Skrót przygotowany przez AI na podstawie treści ogłoszenia.
Technologies we use
About the project
This is how we organize our work
Team size
This is how we work
Team members
Your responsibilities
- Research next-generation MFA technologies: Investigate Windows / Windows Server, Active Directory (on-prem & Azure AD), and emerging passwordless standards such as WebAuthn / FIDO2 passkeys, identifying secure integration paths and potential attack surfaces.
- Deep-dive into authentication protocols: Analyze Kerberos, NTLM, OAuth 2.0, and SAML flows to uncover weaknesses, propose hardening strategies, and validate cryptographic soundness.
- Explore hardware-backed security options: Prototype the use of TPM 2.0, security keys (U2F / FIDO2), biometrics, and Bluetooth LE proximity for frictionless, phishing-resistant login experiences.
- Document and communicate findings: Produce clear, risk-ranked reports with reproduction steps, proof-of-concepts, and actionable remediation guidance tailored for product engineering and customer success teams.
- Track emerging threats and bypass techniques: Create internal advisories and threat-model updates that inform roadmap and defensive controls.
- Support incident simulation and response: Lead red-team scenarios and post-test debriefs, helping stakeholders understand impact and prioritize fixes.
Our requirements
- Foundational penetration-testing experience on Microsoft platforms – you’ve performed security assessments of Windows 10/11 or Windows Server environments and can use common tools (e.g., Nmap, Responder, BloodHound) to spot basic misconfigurations.
- Good understanding of authentication concepts – you know how MFA, Kerberos, and NTLM work at a high level and can explain typical attack paths such as pass-the-hash or credential relays.
- Working knowledge of Active Directory security – you can review group-policy and privilege assignments, map trust relationships, and identify exposures that weaken MFA deployments.
- Familiarity with modern MFA standards – you’ve read specifications or lab-tested solutions that use WebAuthn / FIDO2 passkeys, smartcards, or one-time codes, and understand their basic threat models.
- Comfort with scripting and PoC creation – you can write small PowerShell or Python snippets to automate reconnaissance, parsing logs, or demonstrating a finding.
- Clear written and verbal communication – you translate technical findings into concise, well-structured reports and enjoy explaining risk and remediation steps to engineers and non-technical stakeholders.
- Continuous learner mindset – you track new CVEs, read security blogs, and are eager to dig into fresh attack techniques or defensive best practices.
- Team-oriented approach – you collaborate well in remote, cross-functional groups, ask questions when stuck, and give constructive feedback during peer reviews and debriefs.
Optional
- Hands-on experience testing or administering Azure AD / Entra ID environments.
- Practical exposure to hardware-backed factors (TPM, YubiKey, or Bluetooth LE proximity) in authentication flows.
- Familiarity with red-team frameworks (e.g., MITRE ATT&CK) and basic threat-modeling methodologies.
- Industry certifications such as CompTIA Security+, eJPT, OSCP, or CRTP—proof of commitment to offensive-security skills.
- Previous participation in security communities (CTFs, local meet-ups, or published blog posts/papers).
What we offer
- Work on mission-critical security challenges – your findings will directly shape Rublon’s next-generation MFA products and protect millions of users from account takeover.
- Learn from and with high-performing peers – collaborate daily with experienced penetration testers, cryptographers, and software engineers who enjoy sharing knowledge and sharpening each other’s skills.
- Impact without bureaucracy – small, expert teams ship improvements quickly; your recommendations move from report to remediation in weeks, not quarters.
This is how we work on a project
Development opportunities we offer
Benefits
Steps After You Apply
- You’ll be invited to an online meeting with our recruiter
- Afterwards, we’ll ask you to do a small assignment, which will then be discussed with one of our technical leads
- If everything goes well, we will make you an offer and invite you to a final interview
| Opublikowana | 2026-08-27 |
| Źródło |
|
Hexjobs App
Narzędzia dopasowane do tej oferty.
Pozostało 8 dni
26.09.2026
Hexjobs App
Narzędzia dopasowane do tej oferty.
Podobne oferty
Senior Oracle Database Administrator
RUBLON sp. z o.o.
Zielona Góra, LubuszPython Software Engineer (Cybersecurity)
RUBLON sp. z o.o.
Zielona Góra, LubuszPHP Laravel Developer (Cybersecurity)
RUBLON sp. z o.o.
Zielona Góra, LubuszIdentity Security Engineer – Spain & LATAM
RUBLON sp. z o.o.
Zielona Góra, LubuszIdentity Security Engineer (German) – DACH
RUBLON sp. z o.o.
Zielona Góra, Lubusz