top of page
courage is a decision.png
blank.png

Penetration Tester


Our client is one of the leading technology hubs in Bucharest, where tech pros across various disciplines (security, infrastructure, cloud or software development) are delivering and owning services and processes for the group's subsidiaries.


The employer is a worldwide leading services and payments organization, supporting employee benefits administration, fleet&mobility solutions and Corporate payment services across 40+ countries. The Group brings together a unique network of 47 million employee users, 900.000 corporate clients and 1.7 million partner merchants.


In order to protect and further develop the business, the company is implementing a worldwide Security strategy meant to strenghten its portfolio of products and applications and to drive a culture of increased security awareness of ownership.


The Pentester role will be part of the Central Application Security team and will work with development teams across the board to do penetration testing, dynamic application security testing and security UAT. 


The company has a plan to move from a fully outsourced pentesting model (600 apps & sites) to a hybrid model where the internal pentesting team partners with the development teams and application owners to reduce security risks and drive security by design principles.   


Your main responsibilities will revolve around the following:


  • Perform penetration tests on varying missions - primarily focused on mobile & web app testing, and growing to include 5-10% of infrastructure testing;


  • Support the Security Testing Lead to build the processes, tools and standards for the internal penetsting practice;


  • Support the business units in the remediation of vulnerabilities;


  • Run specific security testing activities, such as validation of the efficiency of WAF rules, or validation of the strength on internal policies and security mechanisms;


  • Support the rest of the security team, both central and regional, for expertise questions related to application security and secure coding;


  • You'll have the time and freedom to pick up on any pentesting opportunities to further explore or test new concepts - this can turn into an excellent development opportunity.



This role is for you if:


  • You have hands on knowledge in IT security or software development and have developed a passion for application security;


  • You've been part of formal or informal pentesting assignments - you're familiar with the tools, standards and metholodies to apply in pentesting;  


  • OSCP certification would be a nice to have, but not mandatory;


  • Curious and willing to dive deeper into business & technical matters;


  • Any familiarity with Azure cloud or any other public cloud solution would be a plus;


  • Ability to communicate and work in a transversal manner with different IT teams, including IT operations, IT security and Developers. 


  • Fluent in English.



Why you should consider this role?


  • You'll work in a global center of expertise, get exposure to a diverse range of cultures, technologies and best practices;


  • Competitive salary | Meal vouchers | Holiday vouchers | Benefit budget | Medical subscription | Life insurance | Extra days off


  • Budget for learning and certifications.


If you feel you still need to fill some gaps for this position don't give up, let's talk first.


If interested: send your resume to recruitment@itworx.roand we'll reach out to you shortly.


Else: you can refer an interested friend or acquaintance.

Hybrid Bucharest

How can we help? Send us a note.

Email: recruitment@itworx.ro  

Phone: 00 40 725351268

 

  • LinkedIn Social Icon
  • Facebook

Continutul acestui website este publicat exclusiv de Itworx International SRL. Preluarea integrală sau parțială a oricarui text, reformularea minoră ori republicarea acestuia pe alte site-uri/platforme fără acord scris este interzisă.

The content of this website is published exclusively by Itworx International SRL. The full or partial copying of any text, minor rewording, or republication of this content on other websites/platforms without written permission is prohibited.

bottom of page