cover
Full Time

Offensive Security Engineer / Penetration Tester/ 1 week ago

Genesis
Attractive
Application ends: 2026-09-21

Quick Summary

Full-time remote Offensive Security Engineer at Genesis (Poland) responsible for delivering end-to-end penetration testing across Web, Mobile, Active Directory, and cloud infrastructures, while developing automated tooling and workflows. Requires 2.5+ years of commercial pentesting experience, Python/Bash scripting, B2+ English, and a relevant practical certification (e.g., OSCP, CPTS, GPEN, CWEE).

About Genesis

Genesis is an ecosystem of product IT companies that build global innovative products. Products within the Genesis ecosystem have achieved over 1 billion total downloads. Genesis is recognized as one of Europe's leading tech teams, ranked the best employer by Forbes in 2023 and 2026, and the top IT employer by the DOU community in 2024 and 2025.

About the Team and the Role

Our Offensive Security Team, part of [TO FILL: name of the ecosystem company / service brand the candidate is joining], consists of five engineers who deliver penetration testing services to external clients. These services include Application Security, Infrastructure Security, and Dark Web Monitoring. As an Offensive Security Engineer, you will own engagements end-to-end, covering scoping, testing, reporting, and client communication. Your findings will be reviewed by the Team Lead and fellow engineers, allowing you to focus on technical delivery. The demand for our penetration testing services is growing, and we are committed to raising the technical bar across all four platforms, moving beyond reliance on individual specialists. In your initial months, you will deliver client engagements and develop our internal methodology for AWS cloud security assessment. Within a year, you will become the team's subject matter expert on at least one platform, and the AI agents you build will handle the reconnaissance and enumeration phases of our tests.

What You'll Be Doing:

  • Deliver end-to-end penetration tests for Web and Mobile applications, Active Directory, and cloud environments. This includes scoping, reconnaissance, exploitation, post-exploitation, evidence collection, and retesting.
  • Validate findings from our Application Security and Infrastructure Security services and triage automated scan outputs. This involves eliminating false positives, confirming exploitability and real business impact, and assigning accurate risk ratings.
  • Write client-facing technical reports in English, detailing reproduction steps, evidence, business impact framing, and practical remediation guidance.
  • Communicate directly with clients through kick-off calls, status updates, report walkthroughs, remediation Q&A, and retest agreements.
  • Build automation and internal tooling to streamline reconnaissance, enumeration, and active scanning phases, including AI-agent-based workflows.
  • Create and maintain the internal methodology, testing checklists, and knowledge base for our Offensive Security service lines.
  • Research new attack techniques, evaluate security tooling, and share findings with the team.

What We Expect From You:

  • 2.5+ years of hands-on commercial penetration testing experience, with a track record of delivering multiple end-to-end engagements and authoring reports.
  • Possession of at least one practical certification such as OSCP, CPTS, GPEN, CWEE, or a proven equivalent.
  • Proficiency in Web application testing following the OWASP Web Security Testing Guide and beyond, including authentication and authorization flaws, IDOR, injection, SSRF, insecure deserialization, and business-logic abuse, utilizing Burp Suite Professional daily.
  • Expertise in Mobile application testing based on OWASP MASTG for Android and/or iOS, covering static and dynamic analysis, traffic interception, certificate pinning bypass, insecure local storage, IPC, and platform misuse.
  • Working knowledge of Active Directory and internal network attacks, including enumeration, Kerberos abuse, credential relaying, lateral movement, and privilege escalation paths.
  • Scripting skills in Python and/or Bash, with the ability to read application source code and identify vulnerable patterns in at least one of PHP, Java, C#, JS/TS, or Python.
  • English language proficiency at B2 level or above, sufficient for client calls, writing structured evidence-based reports, and justifying severity ratings to technical clients.

Nice to Have:

  • A second practical certification such as BSCP, CWEE, CAPE, GWAPT, OSWE, CRTO, eWPTX, or eMAPT.
  • Experience in Cloud security testing across AWS, Azure, or GCP, including misconfiguration review, identity and privilege-escalation paths, and attacks on managed services.
  • Hands-on experience or genuine interest in AI and LLM security, covering OWASP Top 10 for LLM Applications, prompt injection, agent abuse, and integrating AI agents into offensive workflows.
  • Public technical contributions such as CVEs, open-source tooling, research write-ups, conference talks, or high-quality bug bounty reports.

What We Offer:

  • Flexible hours and the option to work remotely from anywhere.
  • Medical insurance.
  • 20 paid vacation days per year and unlimited sick leave.
  • All necessary equipment for work.
  • Compensation for professional training, access to our internal learning platform, and lectures.
  • Corporate events and networking opportunities.
  • Free sports training, corporate discounts, and office massage services.
  • Support for colleagues and their families serving in the Defence Forces.
  • Support for veterans.
  • Assistance in case of harm to health or property caused by the war.

Hiring Process:

  • Intro call with the recruiter.
  • Interview with the Offensive Security Team Lead.
  • Test task and a walkthrough of your solution.
  • Bar-raising interview.
  • Offer.

Supporting Ukraine:

The Genesis for Ukraine foundation was established in April 2022 in response to the full-scale invasion, focusing on systematic and long-term support. Its mission includes assisting Genesis employees and their families in the military, contributing to the country's defense, and developing educational and veteran projects to support reintegration into civilian life. Key partnership initiatives include Ukraine's first Veteran Master's Programme, an innovation space with a 3D-printing farm at Kyiv Polytechnic Institute, and entrepreneurship training and grant programs for veterans.

As of early 2026:

  • UAH 650+ million — total aid to Ukraine from Genesis and its partners.
  • UAH 26+ million — targeted assistance to employees and their families serving in the military.

If this opportunity aligns with your skills and aspirations, please send your CV along with any public write-ups, CVEs, or tooling you wish to share. We review every application.

Share

Genesis

Genesis

  • Address
    Home Office
View Profile
Your experience on this site will be improved by allowing cookies Cookie Policy