We are looking for a Junior Penetration Tester / Associate Security Engineer with 1-2 years of commercial experience in web and network penetration testing to join our security team and help embed security across the full delivery process. JOB REQUIREMENTS: Must have: * 1–2 years of commercial experience in web/network penetration testing * Cybersecurity certification: CEH, eJPT, BSCP, eWPT, PJPT or equivalent * Familiarity with OWASP projects: API Security Top 10, Web Top 10, WSTG, ASVS, Cheat Sheet Series * Knowledge of AI/LLM-specific attack vectors — prompt injection, indirect injection, jailbreaking, data leakage, excessive agency (OWASP Top 10 for GenAI Applications 2025) * Hands-on experience with security tooling: Burp Suite, OWASP ZAP, SonarQube, Snyk, OpenVAS or similar * Proven experience administrating Linux and Windows operating systems * Solid understanding of how the web works: HTTP(S), HTML, CSS, AJAX * Hands-on knowledge of at least two programming languages (JS, TS, Python, Java, Go) plus bash scripting * Practical use of AI assistants (Claude, ChatGPT, Gemini) in testing workflows, payload generation and report drafting * Strong self-management, attention to detail and report-writing skills * English — at least Intermediate * Strong motivation and a genuine drive to learn new technologies and techniques
Nice to have: * AI red teaming tools — Garak, PyRIT * Participation in AI-focused CTFs or bug bounty programmes * Secure code review skills * Cloud experience with AWS, GCP or Azure * Mobile and cloud pentesting skills
KEY RESPONSIBILITIES: * Conduct penetration tests of web applications, networks, AI-powered applications, mobile applications and cloud workloads * Perform manual security testing of new and existing application functionality * Write detailed penetration test reports based on testing results * Maintain and run automated vulnerability scans of web applications and networks (Burp Suite, OWASP ZAP, Nuclei, SonarQube, Snyk, OpenVAS) * Help project teams build a Secure SDLC and integrate security testing into their delivery process * Drive and advocate security across the full SDLC * Work closely with development teams so that detected vulnerabilities are correctly understood, prioritised and mitigated * Ensure vulnerabilities are properly escalated and communicated between team members * Raise security awareness through internal training and knowledge sharing
WORK SCHEDULE: Full-time working day, full remote is available (Lviv, Kyiv or remote in Ukraine) INTERVIEW STAGES: * Intro call with a recruiter * Technical interview with our security engineer
OUR BENEFITS: * Work from anywhere (fully remotely or in our office) * Paid vacations and sick-leaves, additional days-off, relocation bonus * Wellness: Medical insurance/ sport compensation/ health check-up+flu vaccination at your choice * Education: regular tech-talks, educational courses, paid certifications, English classes * Fun: own football team, budget for team-lunches, branded gifts * One of the best IT employers in Lviv (or IT service companies in Ukraine) based on DOU rating * ome elements of our recruitment process are supported by AI tools, while all candidate evaluations remain the responsibility of our recruitment team.