Quick Summary
Offensive Security Engineer / Penetration Tester
About Genesis
Genesis is an ecosystem of product IT companies dedicated to building global innovative products. Products created within the Genesis ecosystem have been downloaded over 1 billion times in total. Genesis is recognized as one of Europe's leading tech teams, ranked as the best employer by Forbes in 2023 and 2026, and the top IT employer by the DOU community in 2024 and 2025.
About the Team and the Role
Our Offensive Security Team, part of [TO FILL: name of the ecosystem company / service brand the candidate is joining], consists of five engineers delivering expert penetration testing services to external clients. This team works alongside our Application Security, Infrastructure Security, and Dark Web Monitoring service lines. As an Offensive Security Engineer, you will own engagements end-to-end, from scoping and testing to reporting and client conversations. Your findings will be reviewed by the Team Lead and fellow engineers, allowing you to focus on technical delivery rather than calendar management. Demand for our testing services is growing, and we are committed to raising the technical bar across all four platforms.
In your first months, you will deliver client engagements and build our internal methodology for AWS cloud security assessment. Within a year, you will become the team's reference point on at least one platform, and the AI agents you build will be covering the reconnaissance and enumeration phases of our tests.
What You'll Be Doing
- Deliver end-to-end penetration tests of Web and Mobile applications, Active Directory, and cloud environments, covering scoping, reconnaissance, exploitation, post-exploitation, evidence collection, and retesting.
- Validate findings from our Application Security and Infrastructure Security services and triage automated scan output, eliminating false positives, confirming exploitability and real business impact, and assigning accurate risk ratings.
- Write client-facing technical reports in English, including reproduction steps, evidence, business-impact framing, and practical remediation guidance.
- Communicate directly with clients through kick-off calls, status updates, report walkthroughs, remediation Q&A, and retest agreement.
- Build automation and internal tooling that shortens the reconnaissance, enumeration, and active scanning phases, including AI-agent-based workflows.
- Create and maintain the internal methodology, testing checklists, and knowledge base for our Offensive Security service lines.
- Research new attack techniques, evaluate tooling, and share your findings with the team.
What We Expect From You
- 2.5+ years of hands-on commercial penetration testing experience, with several engagements delivered end-to-end and reports written by you.
- At least one practical certification such as OSCP, CPTS, GPEN, or CWEE, or a proven equivalent.
- Expertise in Web application testing following the OWASP Web Security Testing Guide and beyond, including authentication and authorization flaws, IDOR, injection, SSRF, insecure deserialization, and business-logic abuse, with Burp Suite Professional as a daily tool.
- Proficiency in Mobile application testing based on OWASP MASTG for Android and/or iOS, encompassing static and dynamic analysis, traffic interception, certificate pinning bypass, insecure local storage, IPC, and platform misuse.
- Working knowledge of Active Directory and internal network attacks, including enumeration, Kerberos abuse, credential relaying, lateral movement, and privilege escalation paths.
- Scripting skills in Python and/or Bash, and the ability to read application source code and trace vulnerable patterns in at least one of PHP, Java, C#, JS/TS, or Python.
- English language proficiency at B2 or above, sufficient for running client calls, writing structured evidence-based reports, and justifying severity ratings to technical clients.
Nice to Have
- A second practical certification: BSCP, CWEE, CAPE, GWAPT, OSWE, CRTO, eWPTX, or eMAPT.
- Experience with Cloud security testing in AWS, Azure, or GCP, including misconfiguration review, identity and privilege-escalation paths, and attacks on managed services.
- Hands-on experience or genuine interest in AI and LLM security (OWASP Top 10 for LLM Applications, prompt injection, agent abuse) and in using AI agents within offensive workflows.
- Public technical contributions such as CVEs, open-source tooling, research write-ups, conference talks, or bug bounty participation with high-quality reports.
What We Offer
- Flexible hours and the option to work from anywhere that suits you.
- Medical insurance.
- 20 paid vacation days per year and unlimited sick leave.
- All the equipment you need for work.
- Compensation for professional training, access to our internal learning platform, and lectures.
- Corporate events and networking opportunities.
- Free sports training, corporate discounts, and massage when you visit the office.
- Support for colleagues and their families serving in the Defence Forces.
- Support for veterans.
- Assistance in case of harm to health or property caused by the war.
Hiring Process
- Intro call with the recruiter.
- Interview with the Offensive Security Team Lead.
- Test task and a walkthrough of your solution.
- Bar-raising interview.
- Offer.
Supporting Ukraine
The Genesis for Ukraine foundation was created in April 2022 in response to the full-scale invasion and the need to act systematically and for the long term. Its focus is supporting Genesis employees and their families in the military, helping the country, and developing educational and veteran projects that support reintegration into civilian life. Its large-scale partnership initiatives include Ukraine's first Veteran Master's Programme, an innovation space with a 3D-printing farm at Kyiv Polytechnic Institute, and entrepreneurship training and grant programmes for veterans.
As of early 2026:
- UAH 650+ million — total aid to Ukraine from Genesis and its partners.
- UAH 26+ million — targeted assistance to employees and their families serving in the military.
If this sounds like you, send us your CV along with any public write-ups, CVEs, or tooling you'd like us to see. We review every application.

