Pentester WebAPP and API
Posted bythe hiring team· about 5 hours ago
Posted bythe hiring team· about 5 hours ago
Pentester WebAPP and API
USD 65,773 – USD 70,832
Be among the first applicants
Verified team
HR-vetted before going live.
Transparent pay
Salary stated upfront.
Be among the first applicants
Just opened — your application stands out.
About this role
Key Responsibilities (What You’ll Do)
Advanced Technical Testing: Personally lead and execute end-to-end penetration tests across web applications, APIs, mobile apps (iOS/Android), cloud environments, and internal/external networks.
Deep Active Directory Assessments: Perform sophisticated AD security testing, including privilege escalation, lateral movement, delegation/ACL abuse, and attack path analysis.
Exploit Development: Write custom scripts, tooling, and proof-of-concept (PoC) exploits using Python, PowerShell, and/or Bash.
End-to-End Engagement Management: Own the lifecycle of assignments—from initial scoping and effort estimation to final report delivery and remediation retesting.
Quality Assurance & Pre-Sales: Review and QA technical findings/reports from the team, and provide technical input during scoping calls and proposal creation.
Client & Stakeholder Communication: Act as the primary technical point of contact, translating complex technical risks into clear insights for both devs and non-technical executives.
Required Skills & Experience (What You’ll Need)
Experience: ~5+ years of hands-on offensive security experience, ideally within a cybersecurity consultancy or multi-client delivery environment.
Core Depth: Proven expertise in at least three domains: web applications, network, mobile, or Active Directory testing.
Tooling Infrastructure: Mastery of industry-standard tools (Burp Suite, Nmap, Metasploit, BloodHound, Impacket, CrackMapExec/NetExec, Cobalt Strike, Frida, etc.).
Certifications (Minimum of ONE required):
OSCP (Offensive Security Certified Professional)
CRTP / CRTO (Active Directory/Red Team)
CREST CRT / CPSA (CCT App or Infra strongly preferred)
Soft Skills: Exceptional report-writing skills and fluent professional English.
Highly Desirable / Nice to Have
Advanced certifications (OSEP, OSWE, OSED, CRTE, SANS GXPN/GWAPT, or Cloud offensive certs).
Prior experience within a Big 4 firm or an established boutique security consultancy.
Hands-on exposure to AWS/Azure/GCP cloud environments and Kubernetes/containers.
Active community presence: Published research, CVEs, open-source tooling contributions, conference talks, or top CTF achievements.
The Pentester WebAPP and API role with the hiring team offers USD 65,773–70,832 per year. Salary information is published as part of every JobRemotely listing so candidates can self-screen before applying.
Yes — the hiring team has marked this Pentester WebAPP and API role as open to candidates based in Poland. Eligibility requirements are surfaced in the JobPosting structured data on the listing.
The hiring team uses the JobRemotely structured hiring pipeline: candidates apply through the listing, complete a paid test task or screening, and only then proceed to interviews. This skips the resume black hole and respects everyone's time.
Similar roles
Hand-picked from the same category.
the hiring team· Poland·Remote·about 5 hours ago
USD 50,594 – USD 70,832
Viewthe hiring team· Poland·Remote·about 5 hours ago
USD 50,594 – USD 70,832
Viewthe hiring team· Poland·Remote·about 5 hours ago
USD 50,594 – USD 65,773
Viewthe hiring team· Poland·Remote·about 5 hours ago
USD 100,936 – USD 116,873
ViewJob ads say a lot about where engineering is going — if you read enough of them. We went through all 335 remote engineering roles on our board, every one with a published salary, and counted what they actually ask for.