Senior Penetration Tester
Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Software Engineering
In short
Nordea is seeking an experienced Senior Penetration Tester to join their Cyber Security team in Gdańsk or Warsaw. The role involves leading penetration tests for web applications, APIs, infrastructure, and cloud environments, with a focus on identifying and validating vulnerabilities, and reporting findings to stakeholders.
Responsibilities
- Lead penetration tests of web applications, APIs, infrastructure, and cloud-based solutions.
- Perform in-depth vulnerability assessments and exploit validation.
- Prepare high-quality security testing reports and present technical findings.
- Support the development of testing methods, tools, and team knowledge.
Requirements
- 3+ years of hands-on experience in penetration testing and red teaming.
- Strong knowledge of penetration testing tools: Burp Suite, Metasploit, Nmap, Wireshark, BloodHound.
- Good understanding of Windows and Linux operating systems.
- Scripting in PowerShell and Bash.
- Solid knowledge of networking concepts.
- Familiarity with OWASP Top 10 and MITRE ATT&CK frameworks.
- Specialization in at least two of: Web application security, AI based penetration testing, Infrastructure penetration testing, Cloud security assessments, Reverse engineering, Secure code review.
- Ability to explain complex technical issues clearly.
Desired Qualifications
- Working knowledge of software development concepts.
- Ability to read code in Java, Python, C, or C#.
- Relevant security certifications (OSCP, OSWE, OSEP, OSED, GPEN, GXPN, WAPT, WAPTX, Security+, MASPT, CEH, CRTP/CRTE) are an advantage.
- Track record of meaningful research achievements (CVEs, bug bounty recognitions, public security contributions) is a strong advantage.
Benefits
- Collaboration, Ownership, Passion, Courage values.
- Opportunities to evolve, develop and learn from brilliant colleagues.
- Hybrid working model.
- Diversity and inclusion initiatives.
#cyber security#penetration testing#vulnerability assessment#API security#cloud security#web application security#infrastructure security