Senior Penetration Tester

ALTEN

Kraków

On-site

PLN 60,000 - 90,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medicover medical care
Medicover Benefits platform
Medicover Sport card
Referral Program
Layette for a newborn employee’s child
Group life insurance

Job summary

ALTEN Polska is seeking a Subject Matter Expert in Penetration Testing to support Cyber Security efforts. You will operate with a global/regional team to provide expertise, oversight and assurance around security processes, controls, standards and regulatory requirements.

Responsibilities include leading and performing penetration tests across technologies, documenting findings, mentoring team members, coordinating with DevOps, and ensuring risk is communicated in business terms.

Responsibilities

  • Perform highly technical/analytical security assessments of custom mobile applications, widely understood infrastructure and networks, web services and APIs. This covers manual penetration testing, source code and configuration review.
  • Clearly and professionally document root cause and risk analysis of all findings
  • Adhere to the security testing process and raise any gaps or opportunities for improvement with manager.
  • Work closely with the DevOps teams to ensure that the security testing requirements are met and help automate repetitive tasks.
  • Develop understanding of business functionality and apply testing methodology as appropriate to technologies and risks
  • Code and demonstrate basic proof-of-concept exploits of vulnerabilities when required.
  • Assist with coordination of security testing projects according to a structured process, including writing test plans, test cases and test reports.
  • Advise on vulnerability remediation, control implementation and secure development practices
  • Assess product release risk and complexity and identify potential misuse scenarios through review of business requirements and design specifications
  • Assist with tracking, remediation, and risk acceptance for identified security vulnerabilities.
  • Assist in planning, test execution and vulnerability mitigation
  • Ensure that company security policies are implemented, enforced, and enhanced when appropriate
  • Participate in team discussions to formulate new or enhance existing processes and standards
  • Assist in security incident response activities
  • Adhere strictly to compliance and operational risk controls in accordance with company and regulatory standards, policies and practices; report control weaknesses, compliance breaches and operational loss events
  • Run evaluations of new security testing technologies and provide recommendations.
  • Monitor security industry information sources and keep abreast of events, research, and developments.
  • Identify opportunities to improve our processes, quality of the work and efficiencies.

Job description

This job role is responsible for providing subject matter expertise in Penetration Testing to support wider Cyber Security efforts and organization. The successful candidate will operate as part of a global/regional team within the Cybersecurity organization to provide expertise, oversight and assurance around security process, controls, standards and regulatory requirements.

Key purpose of this position is to:
  • Lead/perform and own the design and delivery of penetration tests across variety of technologies.
  • Work within virtual teams of security and technical specialists to ensure quality delivery of world class security solutions to the business.
  • Lead penetration tests designed to highlight and clearly articulate risk to the business, in terms the business can understand.
  • Drive and lead penetration tests and resulting deliverables, to aid in ensuring that the Bank operates within defined risk appetite
  • Represent Cybersecurity function as technical SME in internal and external discussions.
  • Help drive the maturity of Cybersecurity function by continuously improving quality of our services and removing inefficiencies, in line with wider Cybersecurity strategy.
  • Ensure adherence to the three lines of defence organisational model, with clear lines of responsibility, accountability and segregation of duties.
  • Ensure compliance with internal audit and external regulators, to ensure that any organisational changes are fit for purpose and meet their expectations.
  • Collaborate with relevant stakeholders to enhances the delivery of a Cybersecurity strategy to secure the bank’s technology, protecting and enhancing values, reputation and stakeholder value.
  • Provide supervision, guidance and mentor less experienced members of a team
Principal Accountabilities:
  • Perform highly technical/analytical security assessments of custom mobile applications, widely understood infrastructure and networks, web services and APIs. This covers manual penetration testing, source code and configuration review.
  • Clearly and professionally document root cause and risk analysis of all findings
  • Adhere to the security testing process and raise any gaps or opportunities for improvement with manager.
  • Work closely with the DevOps teams to ensure that the security testing requirements are met and help automate repetitive tasks.
  • Develop understanding of business functionality and apply testing methodology as appropriate to technologies and risks
  • Code and demonstrate basic proof-of-concept exploits of vulnerabilities when required.
  • Assist with coordination of security testing projects according to a structured process, including writing test plans, test cases and test reports.
  • Advise on vulnerability remediation, control implementation and secure development practices
  • Assess product release risk and complexity and identify potential misuse scenarios through review of business requirements and design specifications
  • Assist with tracking, remediation, and risk acceptance for identified security vulnerabilities.
  • Assist in planning, test execution and vulnerability mitigation
  • Ensure that company security policies are implemented, enforced, and enhanced when appropriate
  • Participate in team discussions to formulate new or enhance existing processes and standards
  • Assist in security incident response activities
  • Adhere strictly to compliance and operational risk controls in accordance with company and regulatory standards, policies and practices; report control weaknesses, compliance breaches and operational loss events
  • Run evaluations of new security testing technologies and provide recommendations.
  • Monitor security industry information sources and keep abreast of events, research, and developments.
  • Identify opportunities to improve our processes, quality of the work and efficiencies.
We offer a full-time employment contract
  • Stable and long-term cooperation
  • Well-defined career path at the European leader in engineering & IT consulting
  • Opportunity to relocate and work in different ALTEN Polska branches
  • After completion of the project, opportunity to engage in a subsequent one within the company
  • Introduction and cooperation with dedicated Competences Manager
  • Medicover medical care
  • Medicover Benefits platform
  • Medicover Sport card
  • Referral Program
  • Layette for a newborn employee’s child
  • Group life insurance
We also guarantee:
  • Access to professional certifications with our technology partners (e.g. Google, ISTQB)
  • Access to relevant industry events
  • Access to the Knowledge Sharing Program
  • Access to Referral program
We also offer cooperation based on a B2B or Contract of mandate (UZ).

NOTICE: We kindly inform you that we will contact the selected people.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Researcher
Principal Security Researcher

ALTEN • Kraków

On-site
PLN 180,000 - 240,000
Medicover medical care
Medicover dental care
Medicover Benefits platform
+5
Senior Penetration Tester
Senior Penetration Tester

Mindbox Sp. z o.o. • Kraków

Hybrid
PLN 180,000 - 240,000
Flexible cooperation
Hybrid work setup
Team culture
+3
Production Test Expert
Production Test Expert

ALTEN Polska • Lublin

On-site
PLN 90,000 - 150,000
Medicover medical care
Medicover Benefits platform
Medicover Sport card
+3
Expert Application Security Specialist – Identity & Access Management
Expert Application Security Specialist – Identity & Access Management

ALTEN Polska • Warszawa

Hybrid
PLN 156,000 - 257,000
Full-time contract
Hybrid work model
Relocation opportunities
+1
Senior Cybersecurity Penetration Tester – Mobile, Web, Infrastructure
Senior Cybersecurity Penetration Tester – Mobile, Web, Infrastructure

ITDS Polska Sp. z o.o. • Kraków

Hybrid
PLN 180,000 - 260,000
Stable cooperation and good conditions
Developing expertise in financial行业
Social events and international环境
+4
Test Technician
Test Technician

ALTEN • Kraków

On-site
PLN 58,000 - 85,000
Medicover medical care
Medicover dental care
Medicover Benefits platform
+5
Site Reliability Engineer
Site Reliability Engineer

ALTEN Polska • Kraków

On-site
PLN 180,000 - 250,000
Medicover medical care
Medicover Benefits platform
Medicover Sport card
+3
Fullstack Developer (Java, Python)
Fullstack Developer (Java, Python)

ALTEN Polska • Kraków

On-site
PLN 180,000 - 270,000
Medicover medical care
Medicover Benefits platform
Medicover Sport card
+2
Test Engineer
Test Engineer

ALTEN • Poland

On-site
PLN 120,000 - 180,000
Medicover medical care
Medicover Benefits platform/Medicover 
Employee referral program
+2
Senior FullStack Java Engineer
Senior FullStack Java Engineer

ALTEN Polska • Kraków

On-site
PLN 240,000 - 360,000
Stable cooperation
Career path
Conferences & trainings
+10