Hello,
We are called People More because we treat our employees with respect, but also because the projects we work on are for people and should be easy and pleasant to use. We are technological, but we look at the bigger picture :)
The company is made up of people with a huge client base in the country and abroad, for whom we build projects from scratch (UX, UI, frontend, backend, mobile) or in part. We work directly for our clients and also support our partners in their own solutions. This ensures a wide range of projects and the ability to change! We work with clients all over the world.
For the project that we are working on with our partner, we are looking for Penetration Tester - WebAPP and API.
Your duties will include:
- Lead end-to-end penetration tests and remediation retests.
- Perform advanced Active Directory assessments, including privilege escalation, lateral movement, and attack path analysis.
- Develop custom scripts and PoC exploits using Python, PowerShell, or Bash.
- Manage engagements from scoping and estimation to reporting.
- Review technical findings and support pre-sales activities.
- Communicate risks and recommendations to technical and non-technical stakeholders.
Requirements that must be met:
- 4+ years of hands-on offensive security experience, preferably in a cybersecurity consultancy or multi-client environment.
- Strong expertise in at least three areas: web/API, network, mobile, or Active Directory testing.
- Ability to independently lead penetration testing engagements—from scoping and estimation to reporting and remediation retesting.
- Advanced proficiency with tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, NetExec, Cobalt Strike, and Frida.
- Experience developing scripts and PoC exploits using Python, PowerShell, or Bash.
- Strong client-facing, technical reporting, and stakeholder communication skills.
- At least one certification: OSCP, CRTP, CRTO, CREST CRT, CPSA, CCT App, or CCT Infra.
- Very good English and Polish