Sii Ukraine

SII POLAND

SII SWEDEN

Join us Contact us

Sii Ukraine

SII POLAND

SII SWEDEN

Back

Principal Penetration Tester - Mobile Application (f/m/x)

  • Senior
  • Hybrid, 
  • Office
  • Cracow
This offer base language is English. Translate into Ukrainian.
This translation is generic and may include errors. Show original text

Technologies & tools

We are looking for a Principal Mobile Application Penetration Tester to join a global cybersecurity organization and elevate the standards of mobile app security testing. In this hands-on role, you will lead complex mobile security assessments from start to finish, shaping our methodologies and helping stakeholders navigate the evolving threat landscape. This position is based in Cracow and offers a hybrid work mode, allowing for flexibility in your work environment.

Your tasks

  • Leading end-to-end mobile application penetration tests, including scoping, planning, execution, and reporting
  • Delivering clear, high-quality outputs with practical remediation guidance and well-articulated risk assessments
  • Acting as the go-to escalation point for complex technical challenges and high-impact findings
  • Setting and evolving mobile testing methodologies, playbooks, and quality standards across the team
  • Partnering with global penetration testing leads to aligning ways of working and sharing insights across regions
  • Contributing to the improvement of frameworks, tooling, automation, and best practices with a strong focus on mobile security
  • Building and maintaining an internal knowledge base of findings, trends, and lessons learned
  • Supporting the vulnerability management lifecycle, including tracking, remediation, and risk acceptance
  • Assisting in incident response and security investigations when needed
  • Staying ahead of emerging attack vectors, tools, and techniques, especially in the mobile space

Requirements

  • Minimum 5 years of hands-on penetration testing experience, with a strong focus on mobile application security
  • Practical experience testing iOS and Android applications, including common mobile attack paths and platform-specific risks
  • Strong expertise in mobile security plus at least one additional domain: web applications or infrastructure
  • Solid understanding of common vulnerabilities, attack techniques, and application security principles
  • Strong grasp of TCP/IP fundamentals and network security concepts
  • Confident using both manual and automated testing techniques
  • Ability to explain complex technical issues to non-technical audiences clearly and calmly
  • Strong analytical thinking and problem-solving skills
  • Experience with scripting or programming languages
  • Knowledge of OWASP mobile standards such as MASVS and MSTG
  • Advanced level of English

Nice to have

  • Experience in/or ability to run and deliver tests using the Corellium platform
  • Ability to operate within a secure mobile testing environment, including access to appropriate test devices and tooling, in line with client and organizational security requirements
  • Previous work with SAST, DAST, and IAST tools
  • Familiarity with modern architectures, including microservices, APIs, and cloud environments
  • Code review experience in Java, Kotlin, Swift, or Objective-C
  • Knowledge of authentication and security mechanisms like OAuth2, JWT, biometrics, and SSL pinning
  • Background in software development or secure SDLC
  • Experience in financial services or other regulated environments

Job no. JOB-UJREV

Sii ensures that all hiring decisions are made solely on the basis of qualifications and competence. We are committed to equal and fair treatment of all, regardless of legally protected characteristics. At Sii, we promote a diverse and inclusive work environment, in full compliance with applicable anti-discrimination laws.

Технології

Ми шукаємо Principal Mobile Application Penetration Tester для приєднання до глобальної організації з кібербезпеки та підвищення стандартів тестування безпеки мобільних додатків. У цій практичній ролі ви будете керувати складними оцінками безпеки мобільних додатків від початку до кінця, формувати наші методології та допомагати зацікавленим сторонам орієнтуватися у змінному ландшафті загроз. Ця позиція базується у Кракові та пропонує гібридний режим роботи, що забезпечує гнучкість у робочому середовищі.

Завдання

  • Проведення комплексних penetration тестів мобільних додатків від початку до кінця, включно з визначенням обсягу, плануванням, виконанням та звітуванням
  • Надання чітких, якісних результатів з практичними рекомендаціями щодо усунення вразливостей та детальними оцінками ризиків
  • Виступати як основна точка ескалації для складних технічних викликів та критичних знахідок
  • Встановлення та вдосконалення методологій тестування мобільних додатків, плейбуків та стандартів якості в команді
  • Співпраця з глобальними лідерами penetration testing для узгодження робочих процесів та обміну досвідом між регіонами
  • Внесок у покращення фреймворків, інструментів, автоматизації та найкращих практик з акцентом на мобільну безпеку
  • Створення та підтримка внутрішньої бази знань про знахідки, тенденції та уроки
  • Підтримка життєвого циклу управління вразливостями, включно з відстеженням, усуненням та прийняттям ризиків
  • Допомога у реагуванні на інциденти та розслідуваннях безпеки за потреби
  • Постійне відстеження нових векторів атак, інструментів та технік, особливо у мобільній сфері

Наші очікування

  • Мінімум 5 років практичного досвіду проведення penetration testing з акцентом на безпеку мобільних додатків
  • Практичний досвід тестування iOS та Android додатків, включно з типовими шляхами атак на мобільні пристрої та специфічними ризиками платформ
  • Глибокі знання мобільної безпеки та принаймні в одній додатковій сфері: веб-додатки або інфраструктура
  • Добре розуміння поширених вразливостей, технік атак та принципів безпеки додатків
  • Сильні знання основ TCP/IP та концепцій мережевої безпеки
  • Впевнене використання як ручних, так і автоматизованих методів тестування
  • Здатність чітко та спокійно пояснювати складні технічні питання не технічній аудиторії
  • Аналітичне мислення та навички розв’язання проблем
  • Досвід роботи зі скриптовими або програмними мовами
  • Знання стандартів OWASP для мобільних додатків, таких як MASVS та MSTG
  • Володіння англійською мовою на просунутому рівні

Буде перевагою

  • Досвід або здатність проводити тести з використанням платформи Corellium
  • Здатність працювати в безпечному мобільному тестовому середовищі, включно з доступом до відповідних тестових пристроїв та інструментів відповідно до вимог безпеки клієнта та організації
  • Попередній досвід роботи з інструментами SAST, DAST та IAST
  • Знайомство з сучасними архітектурами, включно з мікросервісами, API та хмарними середовищами
  • Досвід рев’ю коду на Java, Kotlin, Swift або Objective-C
  • Знання механізмів аутентифікації та безпеки, таких як OAuth2, JWT, біометрія та SSL pinning
  • Досвід у розробці програмного забезпечення або безпечному SDLC
  • Досвід роботи у фінансовому секторі або інших регульованих середовищах

Вакансія № JOB-UJREV

Sii ensures that all hiring decisions are made solely on the basis of qualifications and competence. We are committed to equal and fair treatment of all, regardless of legally protected characteristics. At Sii, we promote a diverse and inclusive work environment, in full compliance with applicable anti-discrimination laws.

Quick apply

Fill in the form in English please

Principal Penetration Tester - Mobile Application (f/m/x)

Work mode*

Choose at least one option

angle-down

Option was not selected

Attach CV*

Uploaded file:
  • file_icon Created with Sketch.

Acceptable files: doc, docx, pdf. (max 5MB)
Please submit your file in DOC, DOCX or PDF format
The upload size is limited to 5 MB
File is empty
File was not uploaded

At any time, you may withdraw your consent to the processing of personal data, but such withdrawal shall not affect the legal compliance of any processing of such data, which had occurred before you withdrew your consent. Detailed information on the processing of your personal data is specified in the Privacy Policy.

Sii Poland follows the Procedure for reporting law violations.

Create MySii account to follow your application's status
success

Your application has been submitted

We will contact you as soon as we review your CV

Processing...

Sorry, something went wrong and your message was not delivered

Refresh the page and try again. Contact us form, if problem occurs again

We’re sorry, but the selected file appears to be damaged and we can't process it.

Please try uploading a different copy or a new version of the file. Contact us wrong file, if problem occurs again.

Benefits for you

  • Great Place to Work
  • Solid financial situation
  • Contracts with the biggest brands
  • Centre of internal trainings
  • Many experts you can learn from
  • Open and accessible management team
  • Profit sharing
  • Passion Sponsorship program
  • Regular integration events and trips
  • Comfortable and well-equipped offices
  • MySii app
  • Medical care
Apply now Recommend a friend

Änderungen im Gange

Wir aktualisieren unsere deutsche Website. Wenn Sie die Sprache wechseln, wird Ihnen die vorherige Version angezeigt.

This content is available only in English version.

Are you sure you want to leave this page?

This content is available only in English version.

Are you sure you want to leave this page?