IGAMINGHUNT

Senior Penetration Tester

Serbia · Posted 3w ago

salary not listedsenior
AWSKubernetesCI/CD

Job Description

We are looking for a Senior Penetration Tester to strengthen the security of high-load products by identifying vulnerabilities across applications, infrastructure, cloud environments, and payment flows. In this role, you will work closely with engineering, product, fraud, and compliance teams to improve security posture through offensive security assessments and practical remediation.

Responsibilities

  • Plan and execute penetration testing activities across web applications, APIs, mobile applications, internal and external infrastructure, and AWS cloud environments

  • Perform offensive security exercises, including red team and assumed-breach scenarios covering privilege escalation, lateral movement, persistence, and data exfiltration

  • Assess the security of cloud-native services, Kubernetes environments, microservices, and CI/CD pipelines

  • Identify vulnerabilities affecting payment systems, wallets, KYC/AML processes, bonus mechanisms, affiliate tracking, and other business-critical workflows

  • Work with Product, Engineering, AppSec, Payments, and Fraud teams to prioritize findings and support remediation efforts

  • Develop custom scripts and internal tools to improve testing capabilities where standard solutions are insufficient

  • Contribute to threat modeling activities and support secure-by-design initiatives

  • Review penetration testing plans, reports, and provide technical guidance to junior and middle security specialists

  • Research emerging vulnerabilities, MITRE ATT&CK techniques, security advisories, and translate them into actionable improvements

  • Support security assessments for new products, releases, and market launches, including effort estimation and pre-certification activities

  • Act as a security advisor for technical and business stakeholders on offensive security matters

Requirements

  • 4+ years of hands-on experience in penetration testing or offensive security

  • Proven practical experience in at least three of the following areas:

    • Web applications / APIs

    • Internal networks

    • External infrastructure

    • Cloud environments (AWS/GCP)

    • Mobile applications (iOS/Android)

  • OSCP or an equivalent offensive security certification

  • Strong knowledge of SAST, SCA, DAST, AWS/GCP, MITRE ATT&CK, OWASP ASVS, OWASP WSTG, and PTES

  • Good understanding of application architecture, including MVC and data flow principles

  • Knowledge of supply chain attack techniques

  • Experience writing scripts in Python and Bash

  • Understanding of IAM models within at least one major cloud provider

  • Hands-on experience testing Kubernetes-based environments, cloud-native applications, CI/CD pipelines (GitLab, GitHub Actions, Jenkins) and Infrastructure as Code solutions (Terraform, Helm, CloudFormation)

  • Strong reporting, documentation, and communication skills

  • Ability to balance security priorities with business and release deadlines

  • Solid understanding of security frameworks and compliance standards, including PCI DSS, ISO 27001, NIST, and GDPR

  • At least Upper-Intermediate level of English

Would be a plus

  • Advanced offensive security certifications such as OSWE, OSEP, OSED, CRTO, BSCP, ARTE, or GRTE

  • Experience designing secure architectures for Kubernetes and AWS environments

  • Previous background in iGaming, fintech, or payment products

  • Public security research, CVEs, advisories, technical publications, or conference presentations

  • Completion of HTB Pro Labs or strong CTF achievements

  • Contributions to open-source offensive or defensive security projects

What's in it for you

  • Generous annual leave plus paid sick leave

  • Comprehensive benefits package including private medical and dental insurance, sports allowance, and food vouchers

  • Professional development support with an education budget and learning opportunities

  • Modern office with complimentary meals, snacks, and employee wellness initiatives

  • Recognition programs, regular team events, and gifts for personal milestones