Ethical Hacker/Pentester

your Jared

Kraków

Hybrid

PLN 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Private medical care package
MultiSport card
Flexible working hours

Job summary

your Jared is seeking an experienced security R&D specialist to advance next‑generation MFA and passwordless authentication research. The role involves threat modeling, cryptographic analysis, and prototyping in secure environments, with collaboration across product and engineering.

You will investigate authentication flows, attack surfaces, and security hardening, publishing findings and driving production-ready features with a small expert team.

Qualifications

  • Foundational penetration-testing experience on Windows 10/11 or Windows Server, including use of tools such as Nmap, Responder, and BloodHound.
  • Understanding of MFA, Kerberos, NTLM, pass-the-hash, and credential-relay attack paths.
  • Working knowledge of Active Directory security, including group policy, privilege assignments, trust relationships, and MFA-related exposures.
  • Familiarity with WebAuthn/FIDO2 passkeys, smartcards, one-time codes, and their threat models.
  • Ability to write PowerShell or Python scripts for reconnaissance, log parsing, and proof-of-concept demonstrations.
  • Clear written and verbal communication of security risks and remediation steps.
  • Continuous learning of CVEs, attack techniques, and defensive practices.
  • Ability to collaborate in remote, cross-functional teams.

Responsibilities

  • Research next-generation MFA technologies by investigating Windows, Windows Server, Active Directory, Azure AD, and passwordless standards such as WebAuthn/FIDO2 passkeys; identify secure integration paths and attack surfaces.
  • Analyze Kerberos, NTLM, OAuth 2.0, and SAML authentication flows; uncover weaknesses, propose hardening strategies, and validate cryptographic soundness.
  • Prototype TPM 2.0, U2F/FIDO2 security keys, biometrics, and Bluetooth LE proximity for phishing-resistant login experiences.
  • Produce risk-ranked reports with reproduction steps, proof-of-concepts, and remediation guidance for product engineering and customer-success teams.
  • Create internal advisories and threat-model updates covering emerging threats and bypass techniques.
  • Lead red-team scenarios and post-test debriefs to help prioritize fixes.

Skills

Penetration testing
MFA & Kerberos
AD security
FIDO2/WebAuthn
Scripting: PowerShell/Python
Communication
Threat intel
Remote collaboration

Tools

BloodHound
Mimikatz
Impacket
Metasploit
Responder
Nmap

Job description

R&D on Multi-Factor Authentication Security Research and development activities on multi-factor authentication security will enable the development of new solutions for passwordless multi-factor authentication. Conduct in-depth threat modeling and cryptographic analysis of authentication flows, prototype and validate next-generation passwordless methods such as WebAuthn/FIDO2 passkeys , and monitor emerging attack vectors. Work with product and engineering teams to translate research insights into production-ready features and publish security findings.

How You’ll Work

Location: Remote or from offices in Kraków or Zielona Góra, Poland

Assessment Targets & Tooling: Windows 10/11, Windows Server, Active Directory, Entra ID (Azure AD), Kerberos, NTLM, WebAuthn/FIDO2 passkeys, Linux servers; BloodHound, Mimikatz, Impacket, Metasploit, Responder, Nmap, and custom PowerShell/Python scripts

Team: Work closely with security researchers/analysts and a project manager; coordinate priorities and share findings in weekly threat-hunting syncs

Language: Communicate in Polish or English

Hardware & Lab Access: Modern laptop, isolated virtual test environments, and security keys, including TPM-enabled devices and FIDO2 keys

Self-development: Company-funded online courses and certification vouchers

Employee Benefits:

  • Private medical care package
  • MultiSport card
  • flexible working hours
What You’ll Do
  • Research next-generation MFA technologies by investigating Windows, Windows Server, Active Directory, Azure AD, and passwordless standards such as WebAuthn/FIDO2 passkeys; identify secure integration paths and attack surfaces
  • Analyze Kerberos, NTLM, OAuth 2.0, and SAML authentication flows; uncover weaknesses, propose hardening strategies, and validate cryptographic soundness
  • Prototype TPM 2.0, U2F/FIDO2 security keys, biometrics, and Bluetooth LE proximity for phishing-resistant login experiences
  • Produce risk-ranked reports with reproduction steps, proof-of-concepts, and remediation guidance for product engineering and customer-success teams
  • Create internal advisories and threat-model updates covering emerging threats and bypass techniques
  • Lead red-team scenarios and post-test debriefs to help prioritize fixes
Skills You Have
  • Foundational penetration-testing experience on Windows 10/11 or Windows Server, including use of tools such as Nmap, Responder, and BloodHound
  • Understanding of MFA, Kerberos, NTLM, pass-the-hash, and credential-relay attack paths
  • Working knowledge of Active Directory security, including group policy, privilege assignments, trust relationships, and MFA-related exposures
  • Familiarity with WebAuthn/FIDO2 passkeys, smartcards, one-time codes, and their threat models
  • Ability to write PowerShell or Python scripts for reconnaissance, log parsing, and proof-of-concept demonstrations
  • Clear written and verbal communication of security risks and remediation steps
  • Continuous learning of CVEs, attack techniques, and defensive practices
  • Ability to collaborate in remote, cross-functional teams
Nice To Haves
  • Experience testing or administering Azure AD/Entra ID environments
  • Exposure to TPM, YubiKey, or Bluetooth LE proximity in authentication flows
  • Familiarity with MITRE ATT&CK and threat-modeling methodologies
  • CompTIA Security+, eJPT, OSCP, or CRTP certification
  • Participation in CTFs, security meet-ups, or published security blogs or papers
Why Apply

Work on security challenges that directly shape next-generation MFA products and protect users from account takeover

Collaborate with experienced penetration testers, cryptographers, and software engineers

Work in a small expert team where recommendations can move quickly from report to remediation

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Ethical Hacker/Pentester
Ethical Hacker/Pentester

Rublon Access Gateway • Kraków

Remote
Private medical care package
MultiSport card
Flexible working hours
+1
Engineer - Cybersecurity (Vulnerability & Threat Management)
Engineer - Cybersecurity (Vulnerability & Threat Management)

Sysco Corporation • Poland

Hybrid
PLN 40,000 - 60,000
Professional development opportunities
Collaborative culture
Modern security technologies
Senior Security Engineer (Red Team)
Senior Security Engineer (Red Team)

Atos Poland Global Services Sp. z o.o. • Województwo kujawsko-pomorskie

Hybrid
PLN 670,000 - 894,000
Hybrid working model
C++ Windows Software Engineer
C++ Windows Software Engineer

Rublon • Kraków

Hybrid
PLN 45,000 - 65,000
Access to private medical care
MultiSport card
Access to online training courses
Application Security Engineer
Application Security Engineer

AXA IT Solutions • Poland

Hybrid
PLN 180,000 - 240,000
Personal development
International environment
English work environment
+9
Principal Security Researcher
Principal Security Researcher

ALTEN • Kraków

Hybrid
PLN 180,000 - 240,000
Medicover medical care
Medicover dental care
Medicover Benefits platform
+5
Cybersecurity Senior Consultant - Senior Pentester
Cybersecurity Senior Consultant - Senior Pentester

Ernst & Young Advisory Services Sdn Bhd • Warszawa

Hybrid
PLN 150,000 - 190,000
Continuous learning
Global exposure
Diverse and inclusive culture
+1
Security Engineer (SecOps)
Security Engineer (SecOps)

inFakt • Kraków

Hybrid
Private medical care for you and your family/partner
MultiSport Benefit card for you and a loved one
Daily lunches, fresh fruit, and good coffee
+2
Lead Security Testing Engineer
Lead Security Testing Engineer

EPAM Systems • Łódź

Hybrid
PLN 180,000 - 280,000
Hybrid work model
Relocation opportunities
Employee stock purchase plan
+5
Cybersecurity Senior Consultant - Senior Pentester
Cybersecurity Senior Consultant - Senior Pentester

EY • Katowice

Hybrid
PLN 180,000 - 280,000