Senior Offensive Security Engineer

PLP Group

Warszawa

On-site

PLN 180,000 - 300,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Klarna is seeking an experienced Offensive Security professional to perform white-box and black-box penetration testing on internal and public-facing systems. You will triage bug bounty submissions, analyze variants across the stack, and assess third-party integrations for security risks.

The role emphasizes building tooling in Python, guiding development teams, and maturing Klarna's security program through hands-on demonstrations and training.

Qualifications

  • 5+ years of penetration testing and security assessments against production systems.
  • Able to read and understand code in Java and Node.js.
  • Experience operating in AWS and reviewing microservice architectures for security gaps.
  • Ability to write clear findings with remediation steps, not just severity labels.
  • Scripting in Python and building security tooling.
  • Active participation in security community or industry programs.

Responsibilities

  • Run white-box and black-box penetration tests against internal systems and public-facing applications.
  • Manage, triage, and investigate Bug Bounty submissions and external pentest findings.
  • Perform variant analysis to locate similar root causes across codebases.
  • Research third-party solutions and integrations for security.
  • Build tooling for reconnaissance, automation, and metrics collection.
  • Guide developers, product security teams, and SOC investigations with hands-on expertise.
  • Run demos, workshops, and training on offensive security practices.

Skills

Penetration testing
Code reading
Python scripting
AWS security
Vulnerability analysis
Security tooling
Clear remediation writing

Tools

Python

Job description

Klarna, brieflyAt Klarna, we're building an everyday finance network, helping over 120 million consumers across 26 countries save time and money, and worry less about their finances. Working here means taking on problems most companies never get to solve, and being hands-on enough that the interesting part of the work lands with you, not someone else — you'll build with AI, not watch it happen.This is the stretch zone. Come find out what you're capable of.About the roleKlarna runs a public Bug Bounty program and works with external pentest vendors year-round, which means a constant stream of real findings — and someone has to work out which ones matter, why, and what else might be affected by the same root cause. That's this position.You'll sit on the Offensive Security team, running your own penetration tests against Klarna's internal and public-facing systems while also triaging what comes in from bug hunters, pentest vendors, and the SOC. When you find something, you won't stop at the one instance — you'll dig for variants across the codebase and infrastructure, and take what you learn back to the teams that own the code.Klarna's stack runs Java and Node.js services on AWS in a microservice architecture, with third-party integrations added constantly — you'll need to keep pace with all of it, not just one corner.What you'll doYou'll run white-box and black-box penetration tests against internal systems and public-facing applications.You'll manage, triage, and investigate Bug Bounty submissions and external pentest findings.You'll perform variant analysis on issues surfaced through any channel, tracing where else the same class of bug might exist.You'll research and assess the security of Klarna's third-party solutions and integrations.You'll build tooling for reconnaissance, automation, and metrics collection.You'll guide developers, product security teams, and SOC investigations with hands-on expertise.You'll run demos, workshops, and training that spread offensive security practices across Klarna.You'll assess the security of Klarna's tech stack and help mature the security program overall.Who you areYou've spent 5+ years running penetration tests and technical security assessments against production systems, not just lab environments.You can read code and find real vulnerabilities in it, particularly in Java and Node.js.You're comfortable operating in AWS and reviewing microservice architectures for security gaps.You write up what you find so developers can act on it — clear findings tied to concrete remediation steps, not just severity labels.You script your own tooling in Python rather than relying only on off-the-shelf scanners.You push offensive security forward at Klarna on your own initiative, not just when assigned a ticket.Bonus points forIndustry certifications such as OSCP, OSWE, CREST, GIAC, or an AWS security certification.Active participation in CTFs or the broader security research community.Public security research you can point to — CVEs, conference talks, or published tooling.Things you should know before applyingThis position is based in Klarna's Milan office; most teams currently meet in person 2–3 days per week, and this varies by team and can change over time.Non-obvious backgrounds are welcome. Diversity of skills, perspectives, and backgrounds is how we create, innovate, and disrupt like no other.Final compensation will be based on the candidate's qualifications, skills, and experience.Please include a CV in English. Concrete beats comprehensive — what you built, what it did, what it cost.Curious to learn more about Klarna and what it's like to work here? Explore our career site!
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Offensive Security Engineer Pen Testing & Bug Bounty
Senior Offensive Security Engineer Pen Testing & Bug Bounty

PLP Group • Warszawa

On-site
PLN 180,000 - 300,000
Senior Machine Learning Engineer - Credit modelling
Senior Machine Learning Engineer - Credit modelling

PLP Group • Warszawa

Hybrid
PLN 519,000 - 779,000
Engineer
Engineer

PLP Group • Warszawa

Hybrid
PLN 140,000 - 240,000
Security Engineer (SecOps)
Security Engineer (SecOps)

inFakt • Kraków

Hybrid
Private medical care for you and your family/partner
MultiSport Benefit card for you and a loved one
Daily lunches, fresh fruit, and good coffee
+2
Senior Security Research Engineer
Senior Security Research Engineer

Elastic • Poland

On-site
PLN 290,000 - 458,000
Health coverage for you and yourfamily
Flexible locations and schedules
Generous vacation days
+2
Offensive Security - Pen Test Senior
Offensive Security - Pen Test Senior

Euroclear • Poland

Hybrid
PLN 120,000 - 180,000
Diverse international environment
Learning and development opportunities
Competitive salary and comprehensive"
Security Engineer (DevSecOps)
Security Engineer (DevSecOps)

co.brick • Gliwice

Hybrid
PLN 180,000 - 260,000
Offensive Security - Pen Test Senior
Offensive Security - Pen Test Senior

Euroclear • Kraków

Hybrid
PLN 140,000 - 200,000
Competitive salary and comprehensive…
Learning and development environment
Knowledge sharing and training
+1
Lead Security Engineer
Lead Security Engineer

OANDA Corporation • Kraków

On-site
PLN 200,000 - 320,000
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)
Senior Security Research Engineer, SONAR (Security Operations and Novel Adversary Research)

Elastic • Poland

On-site
PLN 346,000 - 547,000
Health coverage
Flexible locations & schedules
Generous vacation
+3