Penetration Testing Specialist
Education/Qualifications:
– A bachelor's degree or higher in a relevant field would be a plus.
– Certification or equivalent experience in penetration testing (e.g., CEH, OSCP, OSWE).
– Programming/scripting abilities. If you are or have been a software developer/DevOps would be a plus.
– Applied security research – if you have CVE’s, been on hall-of-fame boards, and similar would be a plus.
Experience:
– 5 years or more of prior experience in penetration testing and vulnerability assessment.
– Experience in drafting recommendations to mitigate the risks associated with uncovered vulnerabilities and weak spots.
– Proficiency in the gambling industry operations and understanding of affiliate partnerships, casino infrastructure, and provider relationships would be a significant advantage.
Skills:
– Knowledge of industry best practices and standards such as PTES, NIST SP 800-115, OSSTMM, OWASP Testing Guide, PCI SSC Testing Guide would be a plus.
– Fluent knowledge of OSI model, TCP/IP stack and routing.
– Fluent understanding of web technologies (WebSockets, OAuth2, JWT, etc.) and APIs (REST, GraphQL, gRPC, etc.) with the ability to demonstrate expertise in web technology stack.
– Understanding browser security mechanisms such as SOP, CSP, and HSTS.
– Ability to script basic operations for tasks such as parsing and exploiting bugs.
– Excellent communication skills, both written and verbal.
– Strong analytical skills and problem-solving abilities.
– Ability to work collaboratively in a team and independently.
– Deadline-oriented with the capability to manage multiple tasks.
– Cultural adaptability and the ability to work across diverse environments.
- Utilize proficient skills with tools such as Burp Suite, various extensions, diverse scanners, and nuances of their configurations to conduct penetration testing effectively.
- Demonstrate expertise in a popular web technology stack to review code when necessary.
- Identify, exploit, and address vulnerabilities outlined in OWASP Top 10, employing comprehensive knowledge of detection, exploitation, and remediation.
- Develop and conduct attacks against existing business logic rules and existing weak spots discovered.
- Participate in designing and implementing API-driven integrations between inventory management systems and vulnerability scanners to automate end-to-end vulnerability management, including scanning, risk-based prioritization, and remediation workflows.
- Analyze systems, construct threat models, strategize exploitation scenarios, and identify weak points.
- Understanding of gambling industry operations including affiliate partnerships, casino infrastructure, and the role of providers to effectively test gaming platforms.
- Draft recommendations for vulnerability remediation tailored to project specifics.
☘️An exciting and challenging job in a fast-growing holding, the opportunity to be part of a multicultural team of top professionals in Development, Architecture, Management, Operations, Marketing, Legal, Finance and more
🤝🏻Great working atmosphere with passionate experts and leaders, sharing a friendly culture and a success-driven mindset is guaranteed
📍Beautiful offices in Warsaw, Limassol, Kyiv, Almaty, Yerevan — work remotely or on-site with comfort and enjoy the opportunity to build a network of connections with professionals day by day
🧑🏻💻Modern corporate equipment based on macOS or Windows and additional equipment are provided
🏖Paid vacations, sick leave, personal events days, days off
👨🏻⚕️Corporate healthcare program for your well-being
💵Referral program — enjoy cooperation with your colleagues and get the bonus
📚Educational support by our L&D team: internal and external trainings and conferences, courses on Udemy
🗣Free internal English courses
🤸♀Sport benefit
🦄Multiple internal activities: online platform with newsletters, quests, gamification, and presents for collecting bonuses, PIN-UP talks club for movie and book lovers, board games cozy evenings, special office days dedicated to holidays, etc
🎳Company events, team buildings
