Offensive Security Engineer

4 tygodni temu


Warsaw, Polska C.H. Robinson Pełny etat

C.H. Robinson is seeking an to join our Warsaw office/global team. In this role, you'll lead red team exercises, fortifying our applications' security. Your expertise will integrate offensive security practices into our SDLC, identifying vulnerabilities and bolstering our digital resilience against threats. You'll embody C.H. Robinson Technology's core values, exhibiting knowledge of our business, entrepreneurial spirit, teamwork, excellent customer service, passion, tech-savvy, effective communication, respect, accountability, strong work ethic, and work-life balance.

Responsibilities:

  • Plan, execute, and communicate red team exercises to simulate cyber threats, identify vulnerabilities, and evaluate security effectiveness.

  • Integrate Offensive Security into SDLC by collaborating with development teams to embed security practices, including threat modeling and proactive testing.

  • Conduct regular Vulnerability Assessment and Penetration Testing (VAPT) to discover and exploit security flaws, providing detailed findings and recommendations.

  • Develop and employ custom tools and techniques for threat simulation, enhancing preparedness against potential attacks.

  • Collaborate closely with defensive teams to improve security strategies based on insights from offensive operations.

  • Act as a security training expert, contributing to developer training programs and promoting a security-first mindset.

  • Stay updated on the latest cybersecurity trends and offensive techniques to ensure our practices remain effective and current.

Required Qualifications:

  • Minimum of 5 years of experience in offensive cybersecurity , with a strong focus on red teaming, penetration testing, or similar activities.

  • Expertise in multiple offensive security tools and frameworks, especially MITRE ATT&CK and MITRE ATLAS.

  • Solid understanding of OWASP top 10s (Web application, API, CI/CD, LLM, and more).

  • Proficiency in API security testing and exploitation.

  • Strong understanding of the software development lifecycle and application security.

  • Solid knowledge of programming/scripting languages; C# and Python knowledge are essential.

  • Strong analytical and problem-solving abilities, coupled with a proactive approach to identifying and mitigating security risks and an ability to think like an adversary.

  • On-call rotation (once every 7 weeks)

  • Team player with a growth mindset.

  • Ability to work independently and manage multiple tasks.

  • Strong ethical standards and understanding of the legal implications of penetration testing.

Preferred Qualifications:

  • Exposure to GenAI/LLM red team exercise.

  • OS security (Windows & Linux); Kubernetes Security; Cloud security – Azure.

  • Certifications such as OSCP, OSCE, or similar.

  • Knowledge of regulatory compliance and security standards – NIST-CSF.

  • Good understanding of NIST SP -, OSSTMM(Open Source Security Testing Manual).

  • Experience in DevSecOps practices.

  • Knowledge of mobile applications and device security testing (iOS/Android)

What does C.H. Robinson offer you? 

  • Contract of employment (umowa o pracę)

  • Package of benefits (private medical care - Medicover, sports card, cafeteria system, unlimited access to training platform Percipio and GoFluent, Employee Assistance Program ICAS)

  • Hybrid working model from our Technology office in Warsaw

  • Work office in Warsaw Spire (we are moving to a new, modern building - Studio), near to metro station Rondo Daszyńskiego 

  • An opportunity to use and develop your language skills in our international work environment 

Questioning if you meet the mark? Studies have shown that women, people of color, and individuals with disabilities may be less likely to apply unless they match the job description exactly. Here at C.H. Robinson, we’re building a diverse and inclusive workplace where all employees feel they belong. If this position excites you, we welcome you to apply whether you check all the preferred qualifications or just a few. You may just be our next great fit


  • Penetration Tester

    4 tygodni temu


    Warsaw, Polska Siemens Healthcare Sp. z o.o. Pełny etat

    PenetrationTester - Offensive Security Specialist Location:Poland Doyou want to help create the future of healthcare? Siemens Healthineers is aplace for people who dedicate their energy and passion to this greater cause.It reflects their pioneering spirit combined with our long history ofengineering in the ever-evolving healthcare industry. Weoffer...

  • DevOps Security Engineer

    1 miesiąc temu


    Warsaw, Polska ING Pełny etat

    DevOps Security Engineer We are looking for you, if you have: Experience in security monitoring use cases development and hands-on experience with security technologies such as SIEM, endpoint or network security monitoring detection tooling, Strong security analytics or threat hunting skills, Experience with an enterprise SIEM solutions...

  • Senior Penetration Tester

    3 tygodni temu


    Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team. WHAT YOU NEED: You break things, and you want to break them anywhere, in any cloud - and you have solid 5-8 years of experience doing that. You eat and sleep offensive security research, bug bounties, CTFs, fuzzing, tools, and techniques. You find and exploit bugs in: C++, Java, JavaScript, Go,...

  • Security Lead Engineer

    3 tygodni temu


    Warsaw, Polska RELOUT sp. z o.o. Pełny etat

    technologies-expected : AWS Linux Docker Serverless technologies-optional : Python TypeScript Node.js about-project : We are currently looking for a Security Lead Engineer, willing to join a project for our strategic client – one of the largest manufacturing companies from Sweden, offering IoT solutions and assets management. In this role, you will be...


  • Warsaw, Polska Box Pełny etat

    WHAT IS BOX?Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish...

  • Cloud Security Engineer

    1 tydzień temu


    Warsaw, Polska Mindbox S.A. Pełny etat

    technologies-expected : AWS Google Cloud Platform Terraform Kubernetes about-project : We’re looking for a Cloud security engineer to join our Client's growing Technology team. Working within the security team you’ll play a key part in securing their cloud native IaaS and PaaS services. They have services across both AWS and GCP responsibilities...


  • Warsaw, Polska Box Pełny etat

    WHAT IS BOX?Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish...


  • Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team.We are actively hiring talented distributed systems developers from Europe and around the world for our European Engineering Center. Our office is located at Kasprzaka 4, in Warsaw. It is conveniently accessible by train, subway, bus, or bicycle – with a large number of restaurants, cafes, and shops...

  • IT System Engineer

    1 tydzień temu


    Warsaw, Polska Damovo Pełny etat

    IT System Engineer / Security professional (m/f/d) IT System Engineer / Security professional (m/f/d) Full Time Warsaw, PolandHybrid With Professional Experience 5/9/24 Damovo...


  • Warsaw, Polska Citi Pełny etat

    We are excited to announce an opening for a Software Supply Chain Security Senior Engineer empathetic with the challenges that development teams face in delivering software in large, heterogeneous organizations. If you are passionate about engineering excellence and building the best developer experience into your solutions, come and build a meaningful...


  • Warsaw, Polska Goldman Sachs Pełny etat

    Business Unit Overview Led by the Chief Information Security Officer (CISO), Technology Risk secures Goldman Sachs against hackers and other cyber threats. We are responsible for detecting and preventing attempted cyber intrusions against the firm, helping the firm develop more secure applications and infrastructure, developing software in support of our...

  • Cloud Security Engineer

    4 tygodni temu


    Warsaw, Polska Michael Page Pełny etat

    Work closely with the Cloud Security Architects to implement our cloud reference architectureWork with IT team, as well as with business owners of cloud applications to implement reference architecture to meet business requirementsIntegrate with cloud projects and verify that the required IS controls are properly implementedPrimarily responsible for cloud...


  • Warsaw, Polska Citi Pełny etat

    We are excited to announce an opening for a Software Supply Chain Security Senior Engineer empathetic with the challenges that development teams face in delivering software in large, heterogeneous organizations. If you are passionate about engineering excellence and building the best developer experience into your solutions, come and build a meaningful...


  • Warsaw, Polska Citi Pełny etat

    We are excited to announce an opening for a Software Supply Chain Security Expert Engineer empathetic with the challenges that development teams face in delivering software in large, heterogeneous organizations. If you are passionate about engineering excellence and building the best developer experience into your solutions, come and build a meaningful...


  • Warsaw, Polska F5 Pełny etat

    At F5, we strive to bring a better digital world to life. Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving digital world. We are passionate about cybersecurity, from protecting consumers from fraud to enabling companies to focus on innovation.    Everything we do centers...

  • IT System Engineer

    1 miesiąc temu


    Warsaw, Polska Damovo Polska Sp. z o.o. Pełny etat

    about-project : Damovo Poland is seeking a talented IT System Engineer / Security professional (m/f/d) to join our innovative Group IT team. As a leading provider of ICT solutions and services, Damovo places a strong emphasis on cybersecurity to protect our internal critical assets. This role focuses on internal IT security administering the MS Security...


  • Warsaw, Polska JPMorgan Chase & Co. Pełny etat

    We know that people want great value combined with an excellent experience from a bank they can trust, so we launched our digital bank, Chase, to revolutionise mobile banking with seamless journeys that our customers love. We're already trusted by millions in the US and we're quickly catching up in the United Kingdom – but how we do things here is a...


  • Warsaw, Polska Box Pełny etat

    WHAT IS BOX?Box is the market leader for Cloud Content Management. Our mission is to power how the world works together. Box is partnering with enterprise organizations to accelerate their digital transformation by creating a single platform for secure content management, collaboration and workflow. We have an amazing opportunity to further establish...


  • Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team. As a member of the , you’ll be responsible for maintaining (and raising) the security bar across our production cloud environments. We are looking for motivated, passionate experts in cloud security architecture and operations who can help us maintain highly defensible cloud infrastructure, and follow...


  • Warsaw, Polska Snowflake Pełny etat

    Build the future of data. Join the Snowflake team.As a member of the Cloud Security Assurance team, you’ll be responsible for maintaining (and raising) the security bar across our production cloud environments. We are looking for motivated, passionate experts in cloud security architecture and operations who can help us maintain highly defensible cloud...