Cybersecurity Senior Consultant – Senior Pentester
Location: Katowice / Warsaw - 2 days office / 3 days remote
The Opportunity
You will work in a multinational environment together with other top security experts and your responsibility will be to deliver Attack & Penetration Testing projects and various other security projects including application code review, social engineering, Red Team Assessments, Threat Modelling, Security Architecture reviews.
Your Key Responsibilities
As a Cybersecurity Senior Consultant, you’ll contribute technically to Cybersecurity client projects and internal projects. The role involves hands‑on testing, analysis, and reporting.
Skills And Attributes For Success
- Understanding of common attack paths and security weaknesses across web and mobile applications, infrastructure, and cloud environments with the ability to translate findings into business-relevant risks and actionable remediation steps
- Structured and disciplined work style, including thorough documentation, evidence handling, clear communication, and a strong focus on quality
- Strong investigative mindset with attention to detail
To qualify for the role, you must have
- 4+ years of experience in Dev / ITSec conducting penetration tests projects
- Knowledge of security issues at the technical level
- Knowledge of solutions and recommendations to prevent or mitigate security vulnerabilities
- Knowledge of the application security verification standards
Deep understanding of how information’s technology systems work
- Networking architecture
- Networking protocols
- Operating systems
- How web applications work, from backend to frontend
- OWASP Top10 concepts
- Familiarity with Red Team methodologies (MITRE, Social engineering, OSINT, etc.)
- Autonomy and maturity in what you do as a security professional
- Consulting and communication skills to provide technical security expertise understandable by non-technical audience
- OSCP, OSWE, GPEN certificate or similar
- Excellent command of English language (German or other European language would be an advantage but not mandatory)
Ideally, you’ll also have
- Documented participation in Bug Bounty programs or acknowledgement of Responsible Disclosures outside those programs
- Granted CVEs
- Programming language skills (Python, C++, C# or Java)
What We Look For
We look for senior pentester who combine technical depth with maturity and discipline. Deliver findings that teams can fix and provide analysis for the testing results.
What We Offer
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
In compliance with the requirements of the Whistleblower Protection Act, our company has established the Procedure for reporting breaches of law and undertaking appropriate follow-up actions. Any misconduct should be reported through the EY Ethics Hotline.