Senior Offensive Security Engineer

Klarna

Warszawa

On-site

PLN 370,000 - 479,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Klarna is seeking an experienced Offensive Security professional to run penetration tests and triage bug bounty findings across internal and public systems. You will analyze variants, assess third-party security and build tooling while guiding developers and SOC teams with practical remediation steps.

The role emphasizes hands-on security across Klarna's stack (Java/Node.js, AWS, microservices) and may involve training and demonstrations to spread best practices.

Qualifications

  • 5+ years running penetration tests and security assessments on production systems.
  • Able to read code and find vulnerabilities in Java and Node.js.
  • Experience operating in AWS and reviewing microservice architectures for security gaps.
  • Ability to write clear remediation steps for developers.
  • Skilled in scripting with Python rather than relying on off-the-shelf scanners.
  • Proactive in advancing offensive security at Klarna.

Responsibilities

  • Run white-box and black-box penetration tests against internal systems and public-facing applications.
  • Manage, triage, and investigate Bug Bounty submissions and external pentest findings.
  • Perform variant analysis across codebase and infrastructure to identify related issues.
  • Research and assess the security of third-party solutions and integrations.
  • Build tooling for reconnaissance, automation, and metrics collection.
  • Guide developers, product security teams, and SOC investigations with hands-on expertise.
  • Run demos, workshops, and training that spread offensive security practices.
  • Assess the security of Klarna's tech stack and help mature the security program.

Skills

Penetration testing
Code reading
AWS familiarity
Python scripting
Vulnerability assessment

Tools

Python

Job description

Klarna, briefly At Klarna, we're building an everyday finance network, helping over 120 million consumers across 26 countries save time and money, and worry less about their finances. Working here means taking on problems most companies never get to solve, and being hands-on enough that the interesting part of the work lands with you, not someone else — you'll build with AI, not watch it happen.

This is the stretch zone. Come find out what you're capable of.

About The Role

Klarna runs a public Bug Bounty program and works with external pentest vendors year-round, which means a constant stream of real findings — and someone has to work out which ones matter, why, and what else might be affected by the same root cause. That's this position.

You’ll sit on the Offensive Security team, running your own penetration tests against Klarna's internal and public-facing systems while also triaging what comes in from bug hunters, pentest vendors, and the SOC. When you find something, you won't stop at the one instance — you'll dig for variants across the codebase and infrastructure, and take what you learn back to the teams that own the code.

Klarna's stack runs Java and Node.js services on AWS in a microservice architecture, with third‑party integrations added constantly — you'll need to keep pace with all of it, not just one corner.

What You’ll Do
  • You’ll run white-box and black-box penetration tests against internal systems and public-facing applications.
  • You’ll manage, triage, and investigate Bug Bounty submissions and external pentest findings.
  • You’ll perform variant analysis on issues surfaced through any channel, tracing where else the same class of bug might exist.
  • You’ll research and assess the security of Klarna's third‑party solutions and integrations.
  • You’ll build tooling for reconnaissance, automation, and metrics collection.
  • You’ll guide developers, product security teams, and SOC investigations with hands‑on expertise.
  • You’ll run demos, workshops, and training that spread offensive security practices across Klarna.
  • You’ll assess the security of Klarna's tech stack and help mature the security program overall.
Who You Are
  • You’ve spent 5+ years running penetration tests and technical security assessments against production systems, not just lab environments.
  • You can read code and find real vulnerabilities in it, particularly in Java and Node.js.
  • You’re comfortable operating in AWS and reviewing microservice architectures for security gaps.
  • You write up what you find so developers can act on it — clear findings tied to concrete remediation steps, not just severity labels.
  • You script your own tooling in Python rather than relying only on off‑the‑shelf scanners.
  • You push offensive security forward at Klarna on your own initiative, not just when assigned a ticket.
Bonus points for
  • Industry certifications such as OSCP, OSWE, CREST, GIAC, or an AWS security certification.
  • Active participation in CTFs or the broader security research community.
  • Public security research you can point to — CVEs, conference talks, or published tooling.
Things you should know before applying
  • This position is based in Klarna's Milan office; most teams currently meet in person 2–3 days per week, and this varies by team and can change over time.
  • Non‑obvious backgrounds are welcome. Diversity of skills, perspectives, and backgrounds is how we create, innovate, and disrupt like no other.
  • Final compensation will be based on the candidate's qualifications, skills, and experience.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Offensive Security Engineer
Senior Offensive Security Engineer

PLP Group • Warszawa

On-site
PLN 180,000 - 300,000
Senior Offensive Security Engineer - Penetration Testing
Senior Offensive Security Engineer - Penetration Testing

Klarna • Warszawa

On-site
PLN 370,000 - 479,000
Senior Offensive Security Engineer Pen Testing & Bug Bounty
Senior Offensive Security Engineer Pen Testing & Bug Bounty

PLP Group • Warszawa

On-site
PLN 180,000 - 300,000
Senior Machine Learning Engineer - Credit modelling
Senior Machine Learning Engineer - Credit modelling

PLP Group • Warszawa

Hybrid
PLN 519,000 - 779,000
Engineer
Engineer

PLP Group • Warszawa

Hybrid
PLN 140,000 - 240,000
Senior Machine Learning Engineer - Credit modelling
Senior Machine Learning Engineer - Credit modelling

Klarna • Warszawa

Hybrid
PLN 250,000 - 420,000
Engineer
Engineer

Klarna • Warszawa

Hybrid
PLN 180,000 - 260,000
Senior Analyst - Consumer Credit Risk & Underwriting
Senior Analyst - Consumer Credit Risk & Underwriting

Klarna • Warszawa

Hybrid
PLN 180,000 - 260,000
Offensive Security - Pen Test Senior
Offensive Security - Pen Test Senior

Euroclear • Poland

Hybrid
PLN 120,000 - 180,000
Diverse international environment
Learning and development opportunities
Competitive salary and comprehensive"
Security Engineer (SecOps)
Security Engineer (SecOps)

inFakt • Kraków

Hybrid
Private medical care for you and your family/partner
MultiSport Benefit card for you and a loved one
Daily lunches, fresh fruit, and good coffee
+2