Red Team Engineer

Solidgate

Warszawa

On-site

PLN 30,000 - 60,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

30+ days off
Unlimited sick leave
Free office meals
Health coverage
Courses and conferences

Job summary

Solidgate is seeking an experienced offensive security expert to own red teaming operations, develop adversary emulation programs, and enhance security measures in a complex AWS environment.

This role offers a unique chance to shape the offensive security strategy while working with a highly skilled InfoSec team in the fintech domain, delivering crucial insights that directly influence architectural decisions and risk management.

Expect creative freedom in a greenfield security program with comprehensive benefits including 30+ days off, health coverage, and opportunities for professional growth.

Qualifications

  • 4+ years in offensive security and real engagements.
  • Hands-on red team experience mapped to MITRE ATT&CK.
  • Manual web and API exploitation techniques.
  • Cloud attack experience, primarily AWS.
  • Scripting and tool development for automation.
  • Strong ability to explain attack paths and business impact.

Responsibilities

  • Plan and execute full-scope red team operations.
  • Build and run external testing programs.
  • Deliver risk-ranked reports with impact analysis.
  • Develop custom offensive tooling.
  • Validate security controls in deployed environments.

Skills

Offensive security experience
Penetration testing
Red team operations
AWS cloud attacks
Scripting in Python
Manual web/API exploitation
Strong written reporting
OPSEC and ethics

Job description

What You Will Own
  • Plan and execute full‑scope red team operations across external perimeter, web/API, AWS infrastructure, corporate identity providers, and human attack vectors (phishing, social engineering).
  • Build and run external testing programs—structured pentests and a bug bounty program with defined scope, rules of engagement, and triage process.
  • Run purple team cycles with the SOC: exercise specific techniques together, assess detection coverage, and hand off concrete recommendations for improving detection use cases.
  • Deliver risk‑ranked reports with realistic impact analysis written for both engineers and management, and track findings through remediation to revalidation.
  • Develop custom offensive tooling and automate repeatable test scenarios so coverage scales without bottlenecking on manual effort.
  • Validate that security controls actually work in the environment where they’re deployed, not just in theory.
Our Ideal Candidate
  • 4+ years in offensive security, penetration testing, or red team operations with real engagements in production environments, not just labs or CTFs.
  • Hands‑on red team / adversary emulation experience mapped to MITRE ATT&CK—end‑to‑end operations, not automated scanning.
  • Web and API exploitation beyond automated tools: manual techniques, OWASP Top 10 at the exploitation level.
  • Cloud attack experience, primarily AWS: IAM abuse, privilege escalation, misconfiguration exploitation, CI/CD pipeline attacks.
  • Scripting and tool development in Python, Go, or Bash/PowerShell for custom scenarios and automation.
  • Strong written reporting: Ability to explain an attack path and its business impact to a CISO and to an engineer, in the same document.
  • High operational discipline: OPSEC, ethics, and rules of engagement in environments with sensitive financial data.
The Points That Make You Stand Out
  • Purple teaming experience and enough detection knowledge to translate an attack into a detection use case for the SOC.
  • Secure code review and exploit development for specific scenarios rather than generic vulnerability classes.
  • Familiarity with payment domain specifics: card processing flows, PCI DSS scope, SWIFT.
  • Contributions to open‑source offensive tooling, published research, or CVEs.
Why This Role Is a Career Accelerator
  • Own the offensive security direction at Solidgate from scratch—adversary emulation program, tooling, bug bounty, and purple team cadence are yours to define.
  • The attack surface is genuinely complex: AWS‑native infrastructure, 120+ microservices, a proprietary acquiring module, and regulated payment data flows.
  • Your findings directly change architecture decisions and engineering practices—not just a backlog of low‑priority tickets.
  • Develop on the intersection of offensive security, cloud‑native environments, and detection engineering through real purple team collaboration.
  • Regulated fintech red team experience at this scale is rare—this engagement belongs on a short list of defining career moves in the field.
Why Join Solidgate

Impactful work: You’re testing financial infrastructure that processes millions of real payments. What you find and fix directly affects the company’s risk profile and the businesses relying on the platform.

Creative freedom: The offensive security program is greenfield. No inherited methodology, no legacy tooling, no scope decisions made by someone who left two years ago. You design the adversary emulation program from scratch.

Career growth: A realistic path to leading the Offensive Security function within 6‑12 months, with direct collaboration with a CISO who came up through the technical side. Want to go deeper into cloud attack research or detection engineering? That door is open.

Ownership culture: You own engagements end to end—scoping, execution, reporting, remediation tracking, and revalidation. No hand‑offs to a PM, no findings that disappear into a backlog.

People worth working with: A senior InfoSec team that takes security seriously and treats offensive findings as engineering inputs, not audit outcomes. Smart, experienced teammates who raise the bar and actually have each other’s backs.

The extras: 30+ days off, unlimited sick leave, free office meals, health coverage, and Apple gear. Courses, conferences, and wellness benefits—all there when you need them.

The best red teamers want a target worth attacking. This is it.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Solidgate • Województwo mazowieckie

On-site
30+ days off
Unlimited sick leave
Free office meals
+2
Lead Red Team Engineer: Cloud, Pentesting & Purple Team
Lead Red Team Engineer: Cloud, Pentesting & Purple Team

Solidgate • Warszawa

On-site
PLN 30,000 - 60,000
30+ days off
Unlimited sick leave
Free office meals
+2
Tech Risk Advisory - Red Team Operator/Pentester - Associate/Vice President - Warsaw
Tech Risk Advisory - Red Team Operator/Pentester - Associate/Vice President - Warsaw

Goldman Sachs • Warszawa

On-site
PLN 80,000 - 100,000
Lead Security Engineer
Lead Security Engineer

S&P Global, Inc. • Poland

On-site
PLN 254,000 - 382,000
Health care coverage
Generous time off
Continuous learning resources
+2
Tech Risk Advisory - Red Team Operator - Associate/Vice President - Warsaw Warsaw · Poland · Vi[...]
Tech Risk Advisory - Red Team Operator - Associate/Vice President - Warsaw Warsaw · Poland · Vi[...]

Goldman Sachs Bank AG • Warszawa

On-site
Senior (Staff) Penetration Tester
Senior (Staff) Penetration Tester

Snowflake • Warszawa

On-site
PLN 296,000 - 372,000
Fast-paced working environment
Strong support for innovation
Collaborative team culture
Software Engineer and Security Researcher
Software Engineer and Security Researcher

Commit • Warszawa

Hybrid
PLN 190,000 - 270,000
Security Engineer
Security Engineer

Flox • Poland

Hybrid
PLN 167,400 - 223,200
Flexible hybrid environment
Meaningful equity
Senior Security Engineer (Red Team)
Senior Security Engineer (Red Team)

Atos SE • Bydgoszcz

On-site
PLN 213,310 - 298,634
Dynamic international environment
Professional growth opportunities
Competitive salary and benefits package
Red Team Operator
Red Team Operator

EY • Wrocław

Hybrid
PLN 260,000 - 520,000
Continuous learning
Success as defined by you
Transformative leadership
+1