logo[мetahunt]
> DOU
junior

Security Engineer

TechMagic
format:Remotetype:Full-timecompany:Outsource
burp suitelinuxwindowsjavascripttypescriptpython
awsazuregoogle cloud
englishB1
experience1+ years
locationUkraine (Lviv, Kyiv)
> full description

We are looking for a Junior Penetration Tester / Associate Security Engineer with 1-2 years of commercial experience in web and network penetration testing to join our security team and help embed security across the full delivery process.

JOB REQUIREMENTS:

Must have:

  • 1–2 years of commercial experience in web/network penetration testing
  • Cybersecurity certification: CEH, eJPT, BSCP, eWPT, PJPT or equivalent
  • Familiarity with OWASP projects: API Security Top 10, Web Top 10, WSTG, ASVS, Cheat Sheet Series
  • Knowledge of AI/LLM-specific attack vectors — prompt injection, indirect injection, jailbreaking, data leakage, excessive agency (OWASP Top 10 for GenAI Applications 2025)
  • Hands-on experience with security tooling: Burp Suite, OWASP ZAP, SonarQube, Snyk, OpenVAS or similar
  • Proven experience administrating Linux and Windows operating systems
  • Solid understanding of how the web works: HTTP(S), HTML, CSS, AJAX
  • Hands-on knowledge of at least two programming languages (JS, TS, Python, Java, Go) plus bash scripting
  • Practical use of AI assistants (Claude, ChatGPT, Gemini) in testing workflows, payload generation and report drafting
  • Strong self-management, attention to detail and report-writing skills
  • English — at least Intermediate
  • Strong motivation and a genuine drive to learn new technologies and techniques

Nice to have:

  • AI red teaming tools — Garak, PyRIT
  • Participation in AI-focused CTFs or bug bounty programmes
  • Secure code review skills
  • Cloud experience with AWS, GCP or Azure
  • Mobile and cloud pentesting skills

KEY RESPONSIBILITIES:

  • Conduct penetration tests of web applications, networks, AI-powered applications, mobile applications and cloud workloads
  • Perform manual security testing of new and existing application functionality
  • Write detailed penetration test reports based on testing results
  • Maintain and run automated vulnerability scans of web applications and networks (Burp Suite, OWASP ZAP, Nuclei, SonarQube, Snyk, OpenVAS)
  • Help project teams build a Secure SDLC and integrate security testing into their delivery process
  • Drive and advocate security across the full SDLC
  • Work closely with development teams so that detected vulnerabilities are correctly understood, prioritised and mitigated
  • Ensure vulnerabilities are properly escalated and communicated between team members
  • Raise security awareness through internal training and knowledge sharing

WORK SCHEDULE: Full-time working day, full remote is available (Lviv, Kyiv or remote in Ukraine)

INTERVIEW STAGES:

  1. Intro call with a recruiter
  2. Technical interview with our security engineer

OUR BENEFITS:

  • Work from anywhere (fully remotely or in our office)
  • Paid vacations and sick-leaves, additional days-off, relocation bonus
  • Wellness: Medical insurance/ sport compensation/ health check-up+flu vaccination at your choice
  • Education: regular tech-talks, educational courses, paid certifications, English classes
  • Fun: own football team, budget for team-lunches, branded gifts
  • One of the best IT employers in Lviv (or IT service companies in Ukraine) based on DOU rating

*Some elements of our recruitment process are supported by AI tools, while all candidate evaluations remain the responsibility of our recruitment team.

Відгукнутись на вакансію