IGAMINGHUNT
Senior Penetration Tester
Serbia · Posted 3w ago
Job Description
We are looking for a Senior Penetration Tester to strengthen the security of high-load products by identifying vulnerabilities across applications, infrastructure, cloud environments, and payment flows. In this role, you will work closely with engineering, product, fraud, and compliance teams to improve security posture through offensive security assessments and practical remediation.
Responsibilities
Plan and execute penetration testing activities across web applications, APIs, mobile applications, internal and external infrastructure, and AWS cloud environments
Perform offensive security exercises, including red team and assumed-breach scenarios covering privilege escalation, lateral movement, persistence, and data exfiltration
Assess the security of cloud-native services, Kubernetes environments, microservices, and CI/CD pipelines
Identify vulnerabilities affecting payment systems, wallets, KYC/AML processes, bonus mechanisms, affiliate tracking, and other business-critical workflows
Work with Product, Engineering, AppSec, Payments, and Fraud teams to prioritize findings and support remediation efforts
Develop custom scripts and internal tools to improve testing capabilities where standard solutions are insufficient
Contribute to threat modeling activities and support secure-by-design initiatives
Review penetration testing plans, reports, and provide technical guidance to junior and middle security specialists
Research emerging vulnerabilities, MITRE ATT&CK techniques, security advisories, and translate them into actionable improvements
Support security assessments for new products, releases, and market launches, including effort estimation and pre-certification activities
Act as a security advisor for technical and business stakeholders on offensive security matters
Requirements
4+ years of hands-on experience in penetration testing or offensive security
Proven practical experience in at least three of the following areas:
Web applications / APIs
Internal networks
External infrastructure
Cloud environments (AWS/GCP)
Mobile applications (iOS/Android)
OSCP or an equivalent offensive security certification
Strong knowledge of SAST, SCA, DAST, AWS/GCP, MITRE ATT&CK, OWASP ASVS, OWASP WSTG, and PTES
Good understanding of application architecture, including MVC and data flow principles
Knowledge of supply chain attack techniques
Experience writing scripts in Python and Bash
Understanding of IAM models within at least one major cloud provider
Hands-on experience testing Kubernetes-based environments, cloud-native applications, CI/CD pipelines (GitLab, GitHub Actions, Jenkins) and Infrastructure as Code solutions (Terraform, Helm, CloudFormation)
Strong reporting, documentation, and communication skills
Ability to balance security priorities with business and release deadlines
Solid understanding of security frameworks and compliance standards, including PCI DSS, ISO 27001, NIST, and GDPR
At least Upper-Intermediate level of English
Would be a plus
Advanced offensive security certifications such as OSWE, OSEP, OSED, CRTO, BSCP, ARTE, or GRTE
Experience designing secure architectures for Kubernetes and AWS environments
Previous background in iGaming, fintech, or payment products
Public security research, CVEs, advisories, technical publications, or conference presentations
Completion of HTB Pro Labs or strong CTF achievements
Contributions to open-source offensive or defensive security projects
What's in it for you
Generous annual leave plus paid sick leave
Comprehensive benefits package including private medical and dental insurance, sports allowance, and food vouchers
Professional development support with an education budget and learning opportunities
Modern office with complimentary meals, snacks, and employee wellness initiatives
Recognition programs, regular team events, and gifts for personal milestones