Pentester WebAPP and API
W skrócie
Link Group seeks an experienced Pentester WebAPP and API in Białystok. Responsibilities include penetration testing, Active Directory assessment, exploit development, and client communication. Requires 5+ years of experience, expertise in web apps/network/mobile/AD, and mastery of tools like Burp Suite, Metasploit, and Cobalt Strike. OSCP or equivalent cert required.
Skrót przygotowany przez AI na podstawie treści ogłoszenia.
Key Responsibilities (What You’ll Do)
Advanced Technical Testing: Personally lead and execute end-to-end penetration tests across web applications, APIs, mobile apps (iOS/Android), cloud environments, and internal/external networks.
Deep Active Directory Assessments: Perform sophisticated AD security testing, including privilege escalation, lateral movement, delegation/ACL abuse, and attack path analysis.
Exploit Development: Write custom scripts, tooling, and proof-of-concept (PoC) exploits using Python, PowerShell, and/or Bash.
End-to-End Engagement Management: Own the lifecycle of assignments—from initial scoping and effort estimation to final report delivery and remediation retesting.
Quality Assurance & Pre-Sales: Review and QA technical findings/reports from the team, and provide technical input during scoping calls and proposal creation.
Client & Stakeholder Communication: Act as the primary technical point of contact, translating complex technical risks into clear insights for both devs and non-technical executives.
Required Skills & Experience (What You’ll Need)
Experience: ~5+ years of hands-on offensive security experience, ideally within a cybersecurity consultancy or multi-client delivery environment.
Core Depth: Proven expertise in at least three domains: web applications, network, mobile, or Active Directory testing.
Tooling Infrastructure: Mastery of industry-standard tools (Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Crack
Map
Exec/NetExec, Cobalt Strike, Frida, etc.).
Certifications (Minimum of ONE required):
OSCP (Offensive Security Certified Professional)CRTP / CRTO (Active Directory/Red Team)CREST CRT / CPSA (CCT App or Infra strongly preferred)
Soft Skills: Exceptional report-writing skills and fluent professional English.
Highly Desirable / Nice to Have
Advanced certifications (OSEP, OSWE, OSED, CRTE, SANS GXPN/GWAPT, or Cloud offensive certs).
Prior experience within a Big 4 firm or an established boutique security consultancy.
Hands-on exposure to AWS/Azure/GCP cloud environments and Kubernetes/containers.
Active community presence: Published research, CVEs, open-source tooling contributions, conference talks, or top CTF achievements.
| Opublikowana | 2026-07-09 |
| Źródło |
|
Hexjobs App
Narzędzia dopasowane do tej oferty.
Hexjobs App
Narzędzia dopasowane do tej oferty.
Podobne oferty
Full Stack Engineer (Python + Vue)
Link Group
BiałystokSenior Application Security Analyst
Svitla Systems
BiałystokData Scientist – Python & Cloud Data Platforms (f/m/x)
Sii Sp. z o.o.
BiałystokData Scientist – Python & Cloud Data Platforms (f/m/x)
Sii
BiałystokPython Django Developer
Britenet
Białystok