Penetration Tester

Andersen Lab

Polska

Hybrid

PLN 120,000 - 190,000

Full time

14 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Private health insurance
Sports compensation
Remote/hybrid work options

Job summary

Andersen Lab is seeking a seasoned Penetration Tester to strengthen cybersecurity for a multinational project. You will identify vulnerabilities across web apps, APIs, networks, Active Directory, and cloud environments, and help mitigate risks.

You will work with SOC teams, produce clear reports for technical and executive audiences, and support remediation and retesting. Remote and hybrid work options are available, with opportunities to grow through mentoring, training, and a competitive bonus

Qualifications

  • 5+ years in cybersecurity with 3+ years hands-on pentesting.

Responsibilities

  • Plan and conduct penetration tests of web apps, APIs, networks, AD, and cloud environments.
  • Perform manual testing beyond automated scans, including exploitation within rules of engagement.
  • Validate findings and produce technical and executive reports.
  • Present results to system owners and management and support remediation and retesting.
  • Contribute to red/purple teaming exercises with SOC/detection teams.
  • Maintain testing methodologies, tools and templates.

Skills

Penetration testing
Web application testing
API testing
OWASP Top 10
Active Directory attacks
Security tooling
Scripting (Python, PowerShell, Bash)
Certification awareness

Education

Hands-on certifications (OSCP/OSWE/OSEP/CRTO/eWPTX/GPEN/GWAPT)

Tools

Burp Suite Pro
Nmap
Metasploit
BloodHound
Impacket

Job description

Andersen is hiring a Penetration Tester for a project strengthening cybersecurity, identifying vulnerabilities, and mitigating security risks across complex digital environments.

Our customer is a technology and consulting organization providing digital infrastructure, cloud services, cybersecurity, data-driven solutions, and managed IT support. It helps organizations modernize complex technology environments, strengthen security, and improve the reliability and scalability of their digital operations. By combining technical expertise with modern technologies and service-oriented delivery, the company supports digital transformation, operational efficiency, and the continuous improvement of critical IT systems across multiple markets.

The project is focused on providing cybersecurity and digital services for international organizations within a large, heterogeneous, multi-tenant environment. It includes developing and strengthening vulnerability management capabilities to identify, assess, prioritize, and mitigate security risks across multiple organizations worldwide.

Responsibilities:
  • Planning and performing penetration tests of web applications, APIs, internal and external networks, Active Directory and cloud environments.
  • Carrying out manual testing beyond automated scanning, including exploitation and privilege escalation within the agreed rules of engagement.
  • Validating findings, assessing business risk and producing clear technical and executive reports.
  • Presenting results to system owners and management, and supporting remediation and retesting.
  • Contributing to red teaming or purple teaming exercises with SOC and detection teams.
  • Maintaining testing methodologies, tools and templates.
Requirements:
  • Experience in cybersecurity for 5+ years, including 3+ years in hands‑on penetration testing.
  • Experience with web application and API testing according to OWASP (Top 10, WSTG, ASVS).
  • Experience conducting internal and external infrastructure testing, including Active Directory attacks
  • Working knowledge of standard tools (Burp Suite Pro, Nmap, Metasploit, BloodHound, Impacket, etc.).
  • At least one recognized hands‑on certification: OSCP, OSWE, OSEP, CRTO, eWPTX, GPEN or GWAPT.
  • Clean professional records and willingness to undergo background verification.
  • Level of English – from Upper-Intermediate and above.
Nice‑to‑haves:
  • Hands‑on experience with cloud penetration testing (Azure, Microsoft 365, AWS).
  • Experience with mobile application testing (Android, iOS).
  • Red Teaming or Purple Teaming experience, including familiarity with C2 frameworks.
  • Strong scripting and security tooling skills (Python, PowerShell, Bash).
  • Experience with PTES, OSSTMM or NIST SP 800-115 methodologies.
  • Proven security research track record, such as published CVEs or recognized bug bounty findings.
Reasons why this job would be interesting to you:
  • Experience in teamwork with leaders in FinTech, Healthcare, Retail, Telecom, and others. Andersen cooperates with such businesses as Samsung, Siemens, Johnson & Johnson, BNP Paribas, Ryanair, Mercedes, TUI, Verivox, Allianz, T-Systems, etc..
  • The opportunity to change the project and/or develop expertise in an interesting business domain.
  • Job conditions – you can work both fully remote and from the office or can choose a hybrid variant.
  • Guarantee of professional, financial, and career growth! The company has introduced systems of mentoring and adaptation for each new employee.
  • The opportunity to earn up to an additional 1,000 EUR per month, depending on the level of expertise, which will be included in the annual bonus, by participating in the company's activities.
  • Access to the corporate training portal, where the entire knowledge base of the company is collected and which is constantly updated.
  • Referral program.
  • Private health insurance and sports compensation, depending on the type of employment.

Your personal data is protected in accordance with GDPR regulations. Learn more: https://andersenlab.com/privacy-policy/pl

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vulnerability Management Consultant
Vulnerability Management Consultant

Andersen Lab • Polska

On-site
PLN 140,000 - 210,000
Private health insurance
Sports compensation
Mentoring programs
DevSecOps Architect / Technical Lead
DevSecOps Architect / Technical Lead

DOU Polska • Warszawa

Hybrid
PLN 180,000 - 280,000
Private health insurance and sports
Certification compensation
Referral program
+2
Penetration Tester
Penetration Tester

Atos • Bydgoszcz

On-site
PLN 120,000 - 170,000
Hybrid work model
Private medical care
Benefits platform
+4
Penetration Tester
Penetration Tester

Atos SE • Bydgoszcz

On-site
PLN 120,000 - 180,000
Hybrid work model
Private medical care
Training & certifications
+2
Remote Penetration Tester — Cloud, Web & Purple Team Expert
Remote Penetration Tester — Cloud, Web & Purple Team Expert

Andersen Lab • Polska

Hybrid
PLN 120,000 - 190,000
Private health insurance
Sports compensation
Remote/hybrid work options
Penetration Tester
Penetration Tester

Antal Poland • Kraków

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Private medical care (LuxMed)
MyBenefit platform
+1
Senior Penetration Tester – Web & Infra Security (Remote)
Senior Penetration Tester – Web & Infra Security (Remote)

thyssenkrupp Hohenlimburg GmbH • Województwo pomorskie

Hybrid
PLN 180,000 - 260,000
Sports cards and wellness benefits
MyBenefit platform
Private medical care
+2
Cybersecurity Senior Consultant - Senior Pentester
Cybersecurity Senior Consultant - Senior Pentester

Ernst & Young Advisory Services Sdn Bhd • Warszawa

On-site
PLN 150,000 - 190,000
Continuous learning
Global exposure
Diverse and inclusive culture
+1
Cybersecurity Senior Consultant - Senior Pentester
Cybersecurity Senior Consultant - Senior Pentester

EY • Warszawa

On-site
PLN 120,000 - 180,000
Senior Penetration Tester
Senior Penetration Tester

Capgemini • Poland

On-site
PLN 240,000 - 300,000
Private medical care
Access to training tracks
Hybrid working model
+1