Senior Penetration Tester

Reposted Yesterday
Be an Early Applicant
Warsaw, Warszawa, Mazowieckie, POL
In-Office
Senior level
Software
The Role
Lead penetration testing engagements across various platforms, develop custom tools, mentor junior testers, and support pre-sales efforts while ensuring security in product design.
Summary Generated by Built In

BrainRocket is a global company creating end-to-end tech products for clients across Fintech, iGaming, and Marketing. ‍Young, ambitious, and unstoppable, we've already taken Cyprus, Malta, Portugal, Poland, and Serbia by storm. Our BRO team consists of 1,300 bright minds creating innovative ideas and products. We don’t follow formats. We shape them. We build what works, launch it fast, and make sure it hits.

We invite a Senior Penetration Tester to join our team. It's an office-based role – no remote or hybrid options.

✅ Responsibilities: 
✔️ Lead end-to-end penetration testing engagements across web applications, APIs, mobile, internal and external networks and cloud (primarily AWS).
✔️ Run red-team and assumed-breach operations - initial access, privilege escalation, lateral movement, persistence, exfiltration - including against fraud and detection stacks.  ✔️ Perform security reviews of cloud-native services, Kubernetes workloads, CI/CD pipelines, and microservices.
✔️ Discover and exploit vulnerabilities across real-money flows - payments, deposits and withdrawals, wallets, KYC / AML, bonus systems, and affiliate tracking.
✔️ Partner with product, engineering, AppSec, payments, and fraud teams to translate findings into concrete fixes and durable controls.
✔️ Develop custom tooling, scripts, and methodology where no out-of-the-box approach exists.
✔️ Build and validate declarative threat models and contribute to "secure by design" practice.
✔️ Mentor mid and junior testers, review their engagement plans and reports.
✔️ Track new CVEs, TTPs, MITRE ATT&CK updates, and regulator advisories - translate them into concrete changes here.
✔️ Support pre-sales scoping, effort estimation, and pre-certification engagements for new products and jurisdictions.
✔️ Serve as a trusted offensive-security advisor to product, engineering, and compliance teams. 

✅ Requirements:
✔️ Minimum 4 years of hands-on penetration testing or offensive-security experience.
✔️ Proven track record across at least three of: web / API, internal, external network, cloud (AWS / GCP), mobile (iOS / Android).
✔️ OSCP or an equivalent in-the-box certification.
✔️ Strong working knowledge of SAST/SCA/DAST tooling, AWS/GCP, MITRE ATT&CK, OWASP ASVS / WSTG, PTES.
✔️ Understanding of the data flow, MVC model.
✔️ Understanding of supply chain attacks.
✔️ Good reporting skills.
✔️ Comfortable scripting in Python plus Bash.
✔️ Knowledge at least one of major cloud provider's IAM model.
✔️ Experience pentesting cloud-native systems and Kubernetes environments, plus the CI/CD pipelines around them (GitLab, GitHub Actions, Jenkins) and IaC (Terraform, Helm, CloudFormation).
✔️ Strong written and verbal communication in English.
✔️ Experience balancing security and business demands under release pressure.
✔️ Familiarity with industry regulations, frameworks, and practices: PCI DSS, ISO 27001, NIST, GDPR

PREFERRED QUALIFICATIONS: 
✔️ One of offensive-security certifications: OSWE, OSEP, OSED, CRTO, BSCP, ARTE, GRTE.
✔️ In-depth experience architecting secure services on Kubernetes and AWS.
✔️ Prior iGaming, fintech, or payments domain experience.
✔️ Public CVEs, advisories, write-ups, conference talks.
✔️ HTB Pro Lab completions, real CTF placements.
✔️ Open-source contributions to offensive or defensive tooling. 

We offer excellent benefits, including but not limited to:
🚀 Career growth opportunities in an international and dynamic environment;
📚 Opportunity to develop language skills with partial compensation for language courses;
🎁 Special gifts for birthdays, weddings, and newborns;
🏝️ 20 working days of paid annual vacation, plus 6 paid sick leave;
🍲 Office snacks and refreshments;
🏋️‍♂️ Sports package to support a healthy lifestyle;
🩺 Comprehensive medical insurance for you and your partner;
📍 Comfortable office with great facilities in a prime location;
 🎉 Exciting corporate events, team-building activities, and international company parties.

Bold moves start here. Make yours. Apply today! 

By submitting your application, you agree to our Privacy Policy.

Skills Required

  • Minimum 4 years of hands-on penetration testing or offensive-security experience.
  • Proven track record across web / API, internal, external network, cloud, mobile.
  • OSCP or an equivalent certification.
  • Strong working knowledge of SAST/SCA/DAST tooling, AWS/GCP, MITRE ATT&CK, OWASP ASVS/WSTG, PTES.
  • Good reporting skills.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
1,300 Employees
Year Founded: 2020

What We Do

BrainRocket is a multinational IT company creating end-to-end tech products for clients across Fintech, iGaming, and Marketing.

Similar Jobs

Snowflake Logo Snowflake

Senior (Staff) Penetration Tester

Artificial Intelligence • Big Data • Cloud • Machine Learning • Software • Database • Analytics
In-Office
Warsaw, Warszawa, Mazowieckie, POL
9023 Employees
7-7 Annually

Mondelēz International Logo Mondelēz International

Junior HR Admin with Dutch and English

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Hybrid
2 Locations
90000 Employees

Ericsson Logo Ericsson

Design Engineer

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office or Remote
109 Locations
88000 Employees

Capco Logo Capco

Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
Poland
6000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account