Senior Offensive Security Engineer

Apply now

Active job offers

Senior Offensive Security Engineer

  • Security

Join our team in Warsaw, where we’re collaborating on a cutting-edge fintech venture with a global industry leader. Together with our Partner – Klarna, we’re building an IT hub designed to drive innovation in digital payment solutions. We’re on the lookout for top-tier engineers who thrive in dynamic, forward-thinking environments. Spyrosoft is leading the recruitment process, facilitating a seamless experience for candidates who are ready to shape the future of online shopping and payments.

This opportunity is ideal for engineers who value independence, proactiveness, and flexibility. Our engagement begins with a B2B contract through Spyrosoft, transitioning to a direct contract with our Partner.

We offer a hybrid work model in Warsaw’s vibrant Wola district. English fluency and eligibility to work in Poland are essential, as is the successful completion of a background check to meet the rigorous standards of the financial domain.

Our process:

  • CV selection
  • Initial recruitment screening
  • Technical interview
  • Online logic test
  • Cultural fit interview

Job description:

  • Core Penetration Testing and Offensive Security
  1. Conduct both white-box and black-box penetration tests on internal and public-facing applications and assets.
  2. Manage, triage, and investigate Bug Bounty submissions and external penetration testing findings.
  3. Perform variant analysis on vulnerabilities identified through different channels.
  • Security Analysis and Research
  1. Perform in-depth security analyses of third-party solutions.
  2. Develop tools to improve reconnaissance, automation, and metrics collection.
  • Collaboration and Guidance
  1. Provide expert guidance to developers, product security teams, and the SOC to ensure effective issue remediation.
  2. Share knowledge by delivering demos, workshops, and training sessions on offensive security practices.
  • Technical Proficiency and Skills
  1. Identify and address security issues in code, with a strong focus on Java and Node.js environments.
  2. Work proficiently within cloud environments like AWS, leveraging modern microservices design principles.
  3. Demonstrate strong scripting skills and contribute to larger Python projects.
  • Security Program Development
  1. Assess and enhance the security of the technology stack through appropriate measures.
  2. Lead projects to promote a strong security culture and improve the organization’s overall security posture.
  • Qualifications and Community Engagement
  1. Possess industry-recognized certifications (e.g., OSCP, OSWE, CREST, GIAC).
  2. Actively participate in Capture The Flag (CTF) competitions and contribute to the cybersecurity community.
  • Communication and Initiative
  1. Clearly and effectively communicate findings, providing actionable remediation recommendations beyond basic reports.
  2. Take initiative to lead impactful projects that elevate the organization’s security culture. Educational Background
  3. Candidates should have a strong educational background in Computer Science, Information Technology, or a related field, ensuring a solid foundation in technical principles essential for the position.
  • Language Requirement
  1. Strong English proficiency is essential, both written and spoken, to ensure effective collaboration and communication across teams.

About Spyrosoft

Spyrosoft is an authentic, cutting-edge software engineering company, established in 2016. In 2021 and 2022, we were among the fastest growing technology companies in Europe, according to the Financial Times. We were founded by a group of tech experts with established backgrounds in software engineering, who created an ‘engineer-to-engineer’ workplace, powered by enthusiasm, fairness and authentic relationships. Having a unique offering, which bridge the gap between technology and business, we specialise in technology solutions for industry 4.0, automotive, geospatial, healthcare & life sciences, employee experience & education and financial services industries.

Meet the recruiter

Ola Surmińska Spyrosoft

Building a new team is a puzzle, there’s no room for mistakes.

Aleksandra Surminska

Senior Recruitment Specialist

CONTACT OUR RECRUITMENT TEAM

Apply for
Senior Offensive Security Engineer

If this offer seems to be perfect for you - don't wait, send us your CV

    Please note that we accept PDF, .doc, .docx or .odt format only.

    By agreeing to one of the following statements, I confirm that I provide my data voluntarily and accept the information contained in the Communication.
    See Communication text

    We would like to inform you that, in accordance with Directive (EU) 2019/1937 on whistleblower protection and relevant national laws, the Spyrosoft Group has implemented a whistleblower policy, enabling reports through an internal channel from the recruitment stage. If you observe any irregularities, we encourage you to use one of the contact options listed in the Policy.
    For more details, including the Policy's content, whistleblower rights, obligations, and data protection, please visit: Whistleblowing Policy.

    At the same time, I declare that I voluntarily provide my personal data and I acknowledge that the Controller of my personal data is Spyrosoft S.A. with its registered office in Wrocław, Plac Nowy Targ 28, the recipients of my data can be companies related with the Data Controller: in particular:
    a) dominant companies within the meaning of art. 4 § 1 point 4 of the Commercial Companies Code of 15 September 2000,
    b) affiliated companies within the meaning of art. provisions of the Commercial Companies Code of 15 September 2000,
    c) companies associated personally with the Administrator, i.e. those in which persons discharging functions in the Administrator's bodies hold at least 20% of votes or shares,
    as well as the Customers of these companies or the entities providing services in favour of the Data Controller who may act as data controllers and processors and my personal data shall be processed pursuant to the Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC, pursuant to Art. 6 (1) (a) of this Regulation, during the period not exceeding 6 months

    At the same time, I acknowledge that I have the right to access and rectify my personal data, its erasure, limitation of processing, the right to object to the processing of data, the right to transfer data, the right to withdraw the consent at any time (without impact on the lawfulness of the processing carried out before the withdrawal), as well as the right to lodge a complaint to a supervisory body. Withdrawal of the consent and willingness to exercise other rights can be reported via e-mail: rodo@spyro-soft.com or by post to the following address: Spyrosoft S.A., Plac Nowy Targ 28, 50-141 Wrocław.

    I acknowledge that personal data is not subject to the automated decision making, including profiling.