We are looking for a Principal Mobile Application Penetration Tester to join a global cybersecurity organization and elevate the standards of mobile app security testing. In this hands‑on role, you will lead complex mobile security assessments from start to finish, shaping our methodologies and helping stakeholders navigate the evolving threat landscape. This position is based in Cracow and offers a hybrid work mode, allowing for flexibility in your work environment.
Your tasks
- Leading end-to-end mobile application penetration tests, including scoping, planning, execution, and reporting
- Delivering clear, high-quality outputs with practical remediation guidance and well-articulated risk assessments
- Acting as the go-to escalation point for complex technical challenges and high-impact findings
- Setting and evolving mobile testing methodologies, playbooks, and quality standards across the team
- Partnering with global penetration testing leads to aligning ways of working and sharing insights across regions
- Contributing to the improvement of frameworks, tooling, automation, and best practices with a strong focus on mobile security
- Building and maintaining an internal knowledge base of findings, trends, and lessons learned
- Supporting the vulnerability management lifecycle, including tracking, remediation, and risk acceptance
- Assisting in incident response and security investigations when needed
- Staying ahead of emerging attack vectors, tools, and techniques, especially in the mobile space
Requirements
- Minimum 5 years of hands‑on penetration testing experience, with a strong focus on mobile application security
- Practical experience testing iOS and Android applications, including common mobile attack paths and platform‑specific risks
- Strong expertise in mobile security plus at least one additional domain: web applications or infrastructure
- Solid understanding of common vulnerabilities, attack techniques, and application security principles
- Strong grasp of TCP/IP fundamentals and network security concepts
- Confident using both manual and automated testing techniques
- Ability to explain complex technical issues to non‑technical audiences clearly and calmly
- Strong analytical thinking and problem‑solving skills
- Experience with scripting or programming languages
- Knowledge of OWASP mobile standards such as MASVS and MSTG
- Advanced level of English
Nice to have
- Experience in/or ability to run and deliver tests using the Corellium platform
- Ability to operate within a secure mobile testing environment, including access to appropriate test devices and tooling, in line with client and organizational security requirements
- Previous work with SAST, DAST, and IAST tools
- Familiarity with modern architectures, including microservices, APIs, and cloud environments
- Code review experience in Java, Kotlin, Swift, or Objective‑C
- Knowledge of authentication and security mechanisms like OAuth2, JWT, biometrics, and SSL pinning
- Background in software development or secure SDLC
- Experience in financial services or other regulated environments
Sii ensures that all hiring decisions are made solely on the basis of qualifications and competence. We are committed to equal and fair treatment of all, regardless of legally protected characteristics. At Sii, we promote a diverse and inclusive work environment, in full compliance with applicable anti‑discrimination laws.