> DOU
junior
TechMagicSecurity Engineer
format:Remotetype:Full-timecompany:Outsource
burp suitelinuxwindowsjavascripttypescriptpython
awsazuregoogle cloud
> full description
We are looking for a Junior Penetration Tester / Associate Security Engineer with 1-2 years of commercial experience in web and network penetration testing to join our security team and help embed security across the full delivery process.
JOB REQUIREMENTS:
Must have:
- 1–2 years of commercial experience in web/network penetration testing
- Cybersecurity certification: CEH, eJPT, BSCP, eWPT, PJPT or equivalent
- Familiarity with OWASP projects: API Security Top 10, Web Top 10, WSTG, ASVS, Cheat Sheet Series
- Knowledge of AI/LLM-specific attack vectors — prompt injection, indirect injection, jailbreaking, data leakage, excessive agency (OWASP Top 10 for GenAI Applications 2025)
- Hands-on experience with security tooling: Burp Suite, OWASP ZAP, SonarQube, Snyk, OpenVAS or similar
- Proven experience administrating Linux and Windows operating systems
- Solid understanding of how the web works: HTTP(S), HTML, CSS, AJAX
- Hands-on knowledge of at least two programming languages (JS, TS, Python, Java, Go) plus bash scripting
- Practical use of AI assistants (Claude, ChatGPT, Gemini) in testing workflows, payload generation and report drafting
- Strong self-management, attention to detail and report-writing skills
- English — at least Intermediate
- Strong motivation and a genuine drive to learn new technologies and techniques
Nice to have:
- AI red teaming tools — Garak, PyRIT
- Participation in AI-focused CTFs or bug bounty programmes
- Secure code review skills
- Cloud experience with AWS, GCP or Azure
- Mobile and cloud pentesting skills
KEY RESPONSIBILITIES:
- Conduct penetration tests of web applications, networks, AI-powered applications, mobile applications and cloud workloads
- Perform manual security testing of new and existing application functionality
- Write detailed penetration test reports based on testing results
- Maintain and run automated vulnerability scans of web applications and networks (Burp Suite, OWASP ZAP, Nuclei, SonarQube, Snyk, OpenVAS)
- Help project teams build a Secure SDLC and integrate security testing into their delivery process
- Drive and advocate security across the full SDLC
- Work closely with development teams so that detected vulnerabilities are correctly understood, prioritised and mitigated
- Ensure vulnerabilities are properly escalated and communicated between team members
- Raise security awareness through internal training and knowledge sharing
WORK SCHEDULE: Full-time working day, full remote is available (Lviv, Kyiv or remote in Ukraine)
INTERVIEW STAGES:
- Intro call with a recruiter
- Technical interview with our security engineer
OUR BENEFITS:
- Work from anywhere (fully remotely or in our office)
- Paid vacations and sick-leaves, additional days-off, relocation bonus
- Wellness: Medical insurance/ sport compensation/ health check-up+flu vaccination at your choice
- Education: regular tech-talks, educational courses, paid certifications, English classes
- Fun: own football team, budget for team-lunches, branded gifts
- One of the best IT employers in Lviv (or IT service companies in Ukraine) based on DOU rating
*Some elements of our recruitment process are supported by AI tools, while all candidate evaluations remain the responsibility of our recruitment team.
Відгукнутись на вакансію