About Genesis
Genesis is an ecosystem of product IT companies building global innovative products. Products created within the Genesis ecosystem have been downloaded over 1 billion times in total. Genesis is one of Europe’s leading tech teams: ranked the best employer by Forbes in 2023 and 2026, and the top IT employer by the DOU community in 2024 and 2025.
About the team and the role
Our Offensive Security Team — part of [TO FILL: name of the ecosystem company / service brand the candidate is joining] — is five engineers delivering penetration testing to external clients, alongside our Application Security, Infrastructure Security and Dark Web Monitoring service lines. You’ll own engagements yourself: scoping, testing, reporting and the client conversation that follows, with the Team Lead and fellow engineers reviewing your findings rather than managing your calendar. Demand for our testing services keeps growing, and we’re raising the technical bar across all four platforms instead of depending on individual specialists. In your first months you’ll deliver client engagements end to end and build our internal methodology for AWS cloud security assessment. Within a year you’ll be the team’s reference point on at least one platform, and the AI agents you build will be covering the recon and enumeration phases of our tests.
What you’ll be doing:
Deliver end-to-end penetration tests of Web and Mobile applications, Active Directory and cloud environments — from scoping and recon through exploitation and post-exploitation to evidence collection and retest;
Validate findings from our Application Security and Infrastructure Security services and triage automated scan output: eliminate false positives, confirm exploitability and real business impact, assign accurate risk ratings;
Write client-facing technical reports in English — reproduction steps, evidence, business-impact framing and practical remediation guidance;
Communicate directly with clients: kick-off calls, status updates, report walkthroughs, remediation Q&A and retest agreement;
Build automation and internal tooling that shortens the recon, enumeration and active scanning phases, including AI-agent-based workflows;
Create and maintain the internal methodology, testing checklists and knowledge base for our Offensive Security service lines;
Research new attack techniques, evaluate tooling and share what you find with the team.
What we expect from you:
2.5+ years of hands-on commercial penetration testing, with several engagements delivered end to end and reports written by you, plus at least one practical certification — OSCP, CPTS, GPEN or CWEE, or a proven equivalent;
Web application testing to the OWASP Web Security Testing Guide and beyond it: authentication and authorisation flaws, IDOR, injection, SSRF, insecure deserialization and business-logic abuse, with Burp Suite Professional as a daily tool;
Mobile application testing based on OWASP MASTG for Android and/or iOS: static and dynamic analysis, traffic interception, certificate pinning bypass, insecure local storage, IPC and platform misuse;
Working knowledge of Active Directory and internal network attacks: enumeration, Kerberos abuse, credential relaying, lateral movement and privilege escalation paths;
Scripting in Python and/or Bash, and the ability to read application source code and trace vulnerable patterns in at least one of PHP, Java, C#, JS/TS or Python;
English at B2 or above — enough to run client calls, write structured evidence-based reports and justify a severity rating to a technical client.
Nice to have:
A second practical certification: BSCP, CWEE, CAPE, GWAPT, OSWE, CRTO, eWPTX or eMAPT;
Cloud security testing in AWS, Azure or GCP: misconfiguration review, identity and privilege-escalation paths, attacks on managed services;
Hands-on experience or genuine interest in AI and LLM security — OWASP Top 10 for LLM Applications, prompt injection, agent abuse — and in using AI agen


