Offensive Security Engineer, Penetration Testing

Procter & Gamble

Warszawa

Hybrid

PLN 180,000 - 280,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Private health care
P&G stock
Saving plans
Sport cards

Job summary

Procter & Gamble is seeking a skilled security tester to lead penetration tests across websites, APIs, cloud environments, and enterprise apps. You will collaborate with engineering, product, and security teams to validate findings, document evidence, and support practical remediation.

The role requires 2+ years in security testing or a related field, with a focus on attacker mindset and clear communication. A hybrid work model is offered to balance in-office collaboration and remote work.

Qualifications

  • Bachelor’s degree or equivalent in Information Security, Cybersecurity, Computer Science, or related field, OR 2+ years of relevant experience.
  • 2+ years of experience in penetration testing, application security testing, vulnerability validation, offensive security, or related security work.
  • Ability to lead defined-scope penetration tests, manage day-to-day execution, document results clearly, and upscale complex or high-risk issues appropriately.

Responsibilities

  • Lead defined-scope penetration tests across websites, services, APIs, infrastructure, cloud environments, networks, and mobile apps.
  • Partner with Intake Management and stakeholders to confirm objectives, access, rules of engagement, and engagement readiness.
  • Execute testing activities including reconnaissance, vulnerability discovery, exploitation, evidence collection, reporting, and remediation validation.
  • Identify, validate, exploit, and document security vulnerabilities while operating within approved scope.
  • Provide remediation guidance and work with engineering and security teams to support fixes.

Skills

Penetration testing
Application security testing
Vulnerability validation
Offensive security
Lead penetration tests
Code reading
Scripting
Cloud basics
Linux
Windows
Attacker mindset
Communication skills

Education

Bachelor’s degree or equivalent in InfoSec/CS
2+ years experience in lieu of degree

Tools

Burp Suite
Nmap
Metasploit
Frida
Ghidra
IDA
BloodHound

Job description

Job Location: WARSAW PLANT & GO

Are you a person who is passionate about breaking applications, devices, services and/or processes to help protect them against the worlds most advanced cyber security adversaries?

The Information Security Protect organization at Procter & Gamble is responsible for providing a realistic depiction of threat actor behaviors and scenarios during simulated exercises. We drive improvements to applications and systems, as well as detection and response capabilities through regular testing of security controls across the enterprise.

Responsibilities
  • Lead defined-scope penetration tests across assigned areas such as websites, services, APIs, infrastructure, cloud environments, networks, IoT devices, mobile applications, and enterprise applications.
  • Partner with Intake Management, senior testers, and stakeholders to confirm objectives, access, rules of engagement, test assumptions, and engagement readiness.
  • Execute testing activities including reconnaissance, vulnerability discovery, exploitation, evidence collection, reporting, and remediation validation.
  • Identify, validate, exploit, and clearly document security vulnerabilities while operating safely within approved scope.
  • Validate related vulnerabilities together where appropriate to demonstrate realistic impact within the boundaries of the engagement, escalating complex attack chains as needed.
  • Test for control gaps where relevant and document observed weaknesses in preventative or detective controls.
  • Investigate and validate Vulnerability Disclosure Program and Bug Bounty findings, escalating complex or high-impact issues as needed.
  • Work with engineering, product, cloud, infrastructure, and security teams to explain findings and support practical remediation.
  • Use approved scripts, templates, automation, and AI-assisted workflows to support testing efficiency, triage, reporting, and remediation validation.
  • Assist with testing AI-enabled applications and integrations for common risks such as prompt injection, sensitive data exposure, insecure tool use, and authorization flaws.
  • Produce clear standardized reports with reproduction steps, evidence, impact, affected systems, and remediation guidance.
  • Contribute to team knowledge sharing, documentation, test notes, templates, and process feedback.
Job Qualifications (Required)
  • Bachelor’s degree or equivalent Polish higher education qualification in Information Security, Cybersecurity, Computer Science, or a related field, OR 2+ years of relevant experience in lieu of a degree.
  • 2+ years of experience in penetration testing, application security testing, vulnerability validation, offensive security, or related security work.
  • Ability to lead defined-scope penetration tests, manage day-to-day execution, document results clearly, and upscale complex, novel, or high-risk issues appropriately.
  • Experience identifying, validating, and exploiting weaknesses in 2 or more domains such as web applications, APIs, mobile applications, cloud infrastructure, enterprise applications, databases, networks, servers, IoT devices, identity platforms, directory services, or AI-enabled systems.
  • Ability to automate tasks with basic scripts or programs in at least one language such as Python, PowerShell, Bash, Go, C#, JavaScript, or similar.
  • Basic Linux command-line experience and familiarity with Windows-based environments.
  • Ability to read and understand code well enough to follow application behavior and identify security-relevant logic.
  • Basic hands-on experience with at least one major cloud provider such as GCP, AWS, or Azure.
  • Adversarial mindset with the ability to think from an attacker’s perspective while following rules of engagement and safety guidance.
  • Clear written and verbal communication skills with the ability to explain technical findings concisely.
Job Qualifications (Preferred Skills)
  • One or more penetration testing or security certifications such as OSCP, OSWE, GPEN, GXPN, GWAPT, PNPT, eJPT, or similar.
  • Experience with CTFs, Bug Bounty programs, Vulnerability Disclosure Programs, coordinated vulnerability research, or public technical write-ups.
  • Experience using AI tools to assist with reconnaissance, code review, vulnerability triage, payload development, reporting, or remediation validation.
  • Exposure to testing AI-enabled applications, LLM-based systems, AI agents, RAG systems, model integrations, or AI-enabled workflows.
  • Experience with mobile, IoT, embedded systems, firmware, reverse engineering, or hardware security testing.
  • Exposure to cloud and identity attack paths involving SSO, MFA, OAuth, IAM, secrets exposure, conditional access, or privilege escalation.
  • Familiarity with tools such as Burp Suite, Nmap, Metasploit, Frida, Ghidra, IDA, BloodHound, or cloud security testing tools.
  • Curiosity, humility, and a desire to improve technical depth, reporting quality, and testing consistency.
Compensation & Benefits
  • Competitive starting salary and benefits program (private health care, P&G stock, saving plans, sport cards).
  • Regular salary increases and possible promotions - in line with your results and performance.
  • Opportunity to change role every few years to be in the best place for you and best for P&G.

At Procter & Gamble we embrace a hybrid work model that combines the flexibility of remote work with the collaborative benefits of in-office engagement. Employees can enjoy the option to work from home two days a week while also spending time in the office to foster teamwork and enhance communication.

We ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process.

At P&G #weseeequal

We are an equal opportunity employer and value diversity at our company. At P&G we strive to build a culture where everyone feels welcome, included, and able to bring their full selves to work.

Job Number R000157572

Job Segmentation Experienced Professionals

P&G was founded over 180 years ago as a simple soap and candle company. Today, we're the world's largest consumer goods company and home to iconic, trusted brands that make life a little bit easier in small but meaningful ways. We've spanned three centuries thanks to three simple ideas: leadership, innovation and citizenship. The insight, innovation and passion of talented teams has helped us grow into a global company that is governed responsibly and ethically, that is open and transparent, and that supports good causes and protects the environment.

This is a place where you can be proud to work and do something that matters.

Job Schedule: Full time

Employment Contract: Umowa o Pracę (Full-time Employment Contract)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Offensive Security Engineer, Penetration Testing
Offensive Security Engineer, Penetration Testing

Procter & Gamble Company • Poland

On-site
PLN 70,000 - 90,000
Private health care
P&G stock
Sport cards
Automation QA Engineer
Automation QA Engineer

Procter & Gamble • Warszawa

On-site
PLN 150,000 - 230,000
Private health care
P&G stock
Saving plans
+1
Sr. DevOps Engineer, Environment, Social, and Governance
Sr. DevOps Engineer, Environment, Social, and Governance

Procter & Gamble • Warszawa

Hybrid
PLN 240,000 - 320,000
Hybrid work model
Private health care
P&G stock
+2
Senior Data Scientist
Senior Data Scientist

Procter & Gamble • Warszawa

Hybrid
PLN 260,000 - 380,000
Private health care
Life insurance
P&G stock options
+3
Senior Data Engineer - Superior Retail Execution
Senior Data Engineer - Superior Retail Execution

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 260,000
Hybrid work model
Professional development (training and
certifications paths
Platform Customer Success Engineer, Data & AI
Platform Customer Success Engineer, Data & AI

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 240,000
Senior AI Engineer
Senior AI Engineer

Procter & Gamble • Warszawa

On-site
PLN 260,000 - 380,000
Private health care
PG Dynamic Living programs
In-office fitness center
+2
SailPoint Operations Engineer
SailPoint Operations Engineer

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Private health care
P&G stock
+3
Senior Salesforce Developer
Senior Salesforce Developer

Procter & Gamble • Warszawa

Hybrid
PLN 180,000 - 240,000
P&G stock
Saving plans
Sport cards
+1
Senior AI Engineer (AI Factory)
Senior AI Engineer (AI Factory)

Procter & Gamble • Warszawa

Hybrid
PLN 250,000 - 380,000
Hybrid work model
In-office fitness center
PG stock options
+1