We are looking for a Cybersecurity Engineer to lead security audits for our clients and actively contribute to improving the security posture of both our clients and our internal environment. This role combines offensive security testing with remediation consulting and close collaboration with development and infrastructure teams.
Responsibilities
Plan and execute security audits for clients, including penetration testing (black-box, gray-box, and white-box), vulnerability assessments, configuration reviews and architecture assessments.
Prepare clear audit reports with risk prioritization and actionable remediation recommendations, tailored to both technical and management audiences.
Propose and implement security improvements, including system hardening, security policies, processes, and tooling.
Continuously monitor newly disclosed vulnerabilities (CVEs, security advisories, threat intelligence) and assess their impact on clients and internal infrastructure.
Collaborate with development and operations teams to remediate identified vulnerabilities, including verification of fixes through retesting.
Participate in client meetings to present audit findings and provide security consulting.
Requirements
Hands-on experience in penetration testing (web applications, infrastructure, APIs; mobile and cloud security experience is a plus).
Strong knowledge of offensive and defensive security, including OWASP Top 10, MITRE ATT&CK, and testing methodologies such as PTES and OSSTMM.
Experience with industry-standard security tools such as Burp Suite, Nmap, Metasploit, Nessus/OpenVAS, or equivalent.
Understanding of security risks specific to AI/LLM systems (e.g., OWASP Top 10 for LLM Applications, including prompt injection, insecure output handling, data poisoning, and related threats).
Practical experience using AI tools in day-to-day workflows, with the ability to critically assess and validate their outputs.
Ability to communicate technical findings clearly to non-technical stakeholders.
Scripting skills (Python, Bash, or similar) for automation.
Professional proficiency in English.
Nice to Have
Certifications such as OSCP, OSWE, CEH, eJPT/eCPPT, or CISSP.
Experience with cloud security (AWS, Azure, GCP).
Familiarity with security standards and regulations such as ISO 27001, NIS2, DORA, and GDPR.
Experience conducting security-focused code reviews.
Experience testing the security of LLM-based applications or AI agents.
Familiarity with emerging frameworks and guidance, including OWASP LLM Top 10, NIST AI RMF, and MITRE ATLAS.
Experience with security automation using scripting combined with AI model APIs.
Benefits
An extra day off for 3 years of seniority in the company
Certifications
Continuous professional development possibility
Gym subscription via 7Card
Christmas bonuses, etc.
Project and performance bonuses

