
Web & Application Penetration Tester @
2 weeks ago
- Core Web Security
- Strong understanding of HTTP, cookies, headers, sessions, CORS, and TLS.
- Expert with Burp Suite Pro and related tooling (Extender, Collaborator, custom extensions).
- Ability to manually identify and exploit injection flaws, race conditions, and logic bypasses.
- Modern Web Technologies
- Familiarity with single-page app frameworks (React, Angular, Vue) and their unique security issues.
- Hands-on experience testing OAuth2, OpenID Connect, SAML, and JWT implementations.
- Knowledge of SSO, MFA, and federation mechanisms and their common pitfalls.
- API Security
- Proficient in testing REST, GraphQL, SOAP, and gRPC endpoints.
- Experience with mass assignment, broken object-level authorization (BOLA), and broken function-level authorization (BFLA).
- Ability to assess rate limiting, replay attack defenses, and API abuse scenarios.
- Mobile Application Security
- Understanding of OWASP Mobile Top 10 risks.
- Familiarity with APK/IPA unpacking, dynamic instrumentation, and certificate pinning bypass.
- Scripting & Tooling
- Proficiency in Python, JavaScript, or Bash/PowerShell for exploit development and automation.
- Ability to create custom PoCs instead of relying solely on scanners.
- Familiarity with tools such as sqlmap, ffuf, nuclei, mitmproxy, Postman, Frida, and Objection.
- Motivated & Proactive – Self-starter who keeps up with modern attacker tradecraft.
- Team Player – Works effectively with developers, QA, and security engineers; values collaboration over silos.
- Problem Solver – Can take vague or incomplete application designs and still identify weak points.
- Clear Communicator – Explains technical findings in developer-friendly language with practical fix guidance.
Desirable (Not Required)
- Familiarity with cloud-native web services (serverless apps, API gateways, WAF bypasses).
- Knowledge of CI/CD security (secrets exposure, insecure build pipelines).
- Experience integrating pentesting results into bug bounty or SDLC workflows.
- Relevant certifications such as OSWE, OSCP, GWAPT, eWPTX.
For Digital Hub Warsaw, we are looking for:
Web/Application Penetration Tester with at least 5 years of solid, hands-on offensive security experience. This role requires deep technical knowledge of modern applications, creative vulnerability exploitation, and strong collaboration skills to help secure critical platforms and services.
,[Web & API Assessments, Perform detailed penetration tests against web applications, APIs, and microservices., Identify vulnerabilities in authentication, session management, authorization, and data validation., Exploit and demonstrate insecure direct object references, SQLi, XSS, SSRF, template injection, deserialization, CSRF, and business logic flaws., Test GraphQL, REST, and gRPC APIs for access control bypasses, injection flaws, and mass-assignment risks., Mobile Application Testing, Assess Android/iOS apps for insecure storage, traffic interception, SSL pinning, hardcoded secrets, and API misconfigurations., Reverse and analyze application logic using Frida, Objection, Burp Mobile Suite, JADX, or Hopper., Code & Dependency Security, Conduct static and dynamic analysis of application codebases where applicable., Identify risks in third-party dependencies, supply chain integrations, and open-source libraries., Reporting & Communication, Write clear, reproducible, and actionable reports with proof-of-concept exploit details., Communicate findings to developers and architects in a way that drives real remediation, not just documentation., Provide secure coding recommendations mapped to OWASP and industry best practices., Continuous Improvement, Develop scripts and custom tooling to automate test cases, payload generation, and reporting workflows., Stay ahead of emerging attack vectors in web frameworks, cloud-native apps, and modern authentication schemes (OAuth2, JWT, SAML)., Contribute to internal methodology updates and maintain a repository of test cases and payloads.] Requirements: Web security, HTTP, TLS, Burp Suite, Web technologies, React, Angular, Vue.js, Security, Testing, SAML, SSO, MFA, API, REST API, GraphQL, SOAP, gRPC, OWASP, Python, JavaScript, Bash, PowerShell, Postman, QA, Web services, API Gateway, WAF, SDLC, OSWE, OSCP Additionally: Sport subscription, Private healthcare, International projects, Canteen, Free parking.-
Automation Tester @
2 weeks ago
Warszawa, Mazovia, Czech Republic ITDS Full timeYou're ideal for this role if you have:Proven hands-on experience with Playwright in building and maintaining automated testsSolid knowledge of TypeScript to create clean and scalable test codeExperience working in CI/CD environments with tools such as JenkinsKnowledge of API testing with tools like Postman or SoapUIUnderstanding of version control systems...
-
Senior Web Applications Developer
18 hours ago
Warszawa, Mazovia, Czech Republic beBeeFullstack Full time €60,000 - €80,000Job DescriptionWe're seeking a seasoned Full Stack Developer to join our team. As a key member, you will play a crucial role in designing, developing, and maintaining web applications using .NET.You will collaborate with cross-functional teams, contribute to system architecture, and ensure the highest performance standards in our fintech solutions.This is a...
-
Senior Web Application Specialist
2 weeks ago
Warszawa, Mazovia, Czech Republic beBeeFrontendDeveloper Full time 900,000 - 1,200,000Job OverviewWe are seeking a skilled Frontend Developer to join our team.Key Responsibilities:Design and develop modern, responsive, and user-friendly front-end interfaces that meet the application's functional and technical requirements.Enhance and fine-tune the user experience, ensuring optimal usability, accessibility, and performance across devices and...
-
Key Player in Automated Testing Roles
2 weeks ago
Warszawa, Mazovia, Czech Republic beBeeTester Full time €45,000 - €60,000Automation TesterThis is a career opportunity to work in an Automation Tester role for a leading financial institution, contributing to the development of a high-traffic web application used daily by millions of customers.You will be part of a dedicated Test Automation Team focused on ensuring the reliability, stability, and security of digital banking...
-
Web Engineer @
2 weeks ago
Warszawa, Mazovia, Czech Republic Mindbox S.A. Full timeIn-depth knowledge of React, JavaScript/TypeScript and the DOMDemonstrated delivery of web applications• Comfortable working with REST APIs using asynchronous patterns• Experience with Git, including understanding of branching and merging workflows• Experience with optimising code for performance and quality• Experience working in a Test...
-
Dispute Systems Software Developer
18 hours ago
Warszawa, Mazovia, Czech Republic beBeeSoftwareEngineer Full time €63,000 - €78,000Software Engineer - Dispute SystemsWe are looking for a talented software engineer to join our global team developing and maintaining Visa Resolve Online, a web-based application that enables clients to manage their disputes and chargebacks.This is a hybrid position requiring collaboration with multiple teams including vendor partner teams. The successful...
-
Lead Frontend Developer
2 weeks ago
Warszawa, Mazovia, Czech Republic beBeeWebEngineer Full time 600,000 - 1,000,000Job Overview:The primary responsibility of the Web Engineer will be to design and develop high-quality web applications using cutting-edge technologies.Key tasks include:Delivering exceptional web applications that meet client expectationsUtilizing REST APIs with asynchronous patterns to ensure seamless data exchangeFamiliarity with Git, including...
-
Senior .NET Developer @
1 day ago
Warszawa, Mazovia, Czech Republic EcoVadis Full timeAt least 6 years of working experience as a .NET developer in C#, T-SQL and building HTTP Web APIs.Attention to code quality presented by understanding of Clean Code, Code metrics, TDD and/or BDD.Experience with Microservice architecture.Knowledge of DDD, CQRS and Docker.Excellent knowledge of Microsoft environment.Experience securing web applications, web...
-
Junior Software Engineer
1 day ago
Warszawa, Mazovia, Czech Republic VISA Full timePreferred QualificationsBachelor's degree in computer science or a related field is required1-2 years of relevant experience in Java/J2EE enterprise applications, Spring framework and Web ServicesStrong Core Java skillsDemonstrated ability to build and understand object-oriented designsStrong SQL skills and knowledge of RDBMS conceptsStrong problem solving...
-
FullStack Developer
1 day ago
Warszawa, Mazovia, Czech Republic Meniga Full timeMinimum 5 years of experience as a Full Stack .NET Developer.Experience with ReactExcellent problem-solving skills with the ability to troubleshoot issues efficiently in a distributed application environment.Experience with databases, particularly SQL Server and Entity Framework.Solid understanding of RESTful APIs and web services integration.Experience with...