Senior Penetration Tester

Where exceptional talents scale what matters.

Swicon Minds is a curated community of 450+ senior top talents working on complex enterprise challenges, while operating within a stable, structured, and supportive ecosystem.

Talent Pool

Please provide your information!


Close

LEAP WITH CONFIDENCE.

SCALE THROUGH COMPETENCE.

Senior Penetration Tester

2025.10.16.

Summary

Bucharest, ROU

Remote

Senior

Introduction

Swicon Group is one of the leading members of the IT arena for almost a decade, since 2017 present also in Romania. Our wide range of services and highly trained professionals give us the opportunity to shape our solutions to fully meet the ideas and wishes of our clients. We are proud to have leading banks, insurance and telecommunication companies, as well as large FMCG corporations and SSCs amongst our highly prestigious partners.

Description

● Plan and execute manual and automated penetration tests from black/white/grey-box perspectives, including delineation, reconnaissance and mapping, deployment and post-deployment services, technical and executive report generation, followed by retesting and cleanup.

● Testing of web applications and APIs against OWASP standards (WSTG, ASVS, Top 10 APIs), with a focus on critical mechanisms such as authentication, authorization, session management, input validation, and encryption.

● Testing of mobile applications (native, hybrid, cross-platform) according to OWASP MASTG/MASVS, including reverse engineering activities, static and dynamic analysis, testing of encryption and data storage mechanisms, and application resistance to jailbreak/rooting techniques.

● Perform code review for various technology packages (PHP, .NET, Android, Kotlin, Swift, NodeJS, JavaScript, TypeScript), identifying CWEs, logical and design vulnerabilities, cryptographic implementation errors, authentication and authorization issues, and using recognized standards and frameworks (e.g., OWASP ASVS/MASVS, CWE Top 25) as a basis for verification.

● Perform vulnerability assessments at the application, infrastructure, and network level, conduct security architecture reviews for complex systems (including cloud, microservices), and organize threat modeling exercises (e.g., STRIDE, OWASP SAMM/ASVS) to identify attack scenarios and mitigation measures.

Write structured technical reports, classify vulnerabilities using CVSS standard, including business impact and remediation recommendations and present results to shareholders and technical teams.

● Solid knowledge of the cloud (AWS, Azure, GCP), ability to identify incorrect configurations and recommend measures to secure the cloud infrastructure.

● Planning and executing penetration tests on Active Directory/Windows infrastructures: enumeration and mapping, configuration, identification and deployment (Kerberoasting, AS-REP roasting, NTLM relay), lateral movement and privilege escalation, followed by hardening recommendations and retesting.




Tasks

● Plan and execute manual and automated penetration tests from black/white/grey-box perspectives, including delineation, reconnaissance and mapping, deployment and post-deployment services, technical and executive report generation, followed by retesting and cleanup.

● Testing of web applications and APIs against OWASP standards (WSTG, ASVS, Top 10 APIs), with a focus on critical mechanisms such as authentication, authorization, session management, input validation, and encryption.

● Testing of mobile applications (native, hybrid, cross-platform) according to OWASP MASTG/MASVS, including reverse engineering activities, static and dynamic analysis, testing of encryption and data storage mechanisms, and application resistance to jailbreak/rooting techniques.

● Perform code review for various technology packages (PHP, .NET, Android, Kotlin, Swift, NodeJS, JavaScript, TypeScript), identifying CWEs, logical and design vulnerabilities, cryptographic implementation errors, authentication and authorization issues, and using recognized standards and frameworks (e.g., OWASP ASVS/MASVS, CWE Top 25) as a basis for verification.

● Perform vulnerability assessments at the application, infrastructure, and network level, conduct security architecture reviews for complex systems (including cloud, microservices), and organize threat modeling exercises (e.g., STRIDE, OWASP SAMM/ASVS) to identify attack scenarios and mitigation measures.

Write structured technical reports, classify vulnerabilities using CVSS standard, including business impact and remediation recommendations and present results to shareholders and technical teams.

● Solid knowledge of the cloud (AWS, Azure, GCP), ability to identify incorrect configurations and recommend measures to secure the cloud infrastructure.

● Planning and executing penetration tests on Active Directory/Windows infrastructures: enumeration and mapping, configuration, identification and deployment (Kerberoasting, AS-REP roasting, NTLM relay), lateral movement and privilege escalation, followed by hardening recommendations and retesting.





Expectations

Requirements:

 

●      Network scanning: Nmap, masscan, Shodan, Censys

●      Vulnerability scanning: Nessus, OpenVAS, nuclei

●      Web testing: Burp Suite Pro, OWASP ZAP, sqlmap, ffuf, dirsearch, Nikto, wpscan, XSStrike

●      Recon subdomains: subfinder, findomain

●      Post-deployment: Metasploit Framework, Impacket, BloodHound

●      Reverse engineering: jadx, Ghidra, r2

●      Mobile device: MobSF, Drozer, adb, Frida, Objection

●      Password cracking: John, Hashcat

●      Supply chain scanning: trivy, OWASP Dependency Check

●      SAST si secret scanning: Semgrep, SonarCloud, gitleaks, truffleHog

●      API si HTTP: Postman

●      Scripting usage: jq, Python, Bash, PowerShell

Advantages

  • Excellent learning opportunities! Variety in your work and a fantastic, informal work atmosphere. 
  • A challenging environment that will stimulate you to grow as a professional! 
  • A great foundation for your career! 
  • Grow with us! Your role will develop over time, so you can increase your experience and responsibilities. So, you can advance faster and further in your future career. 
  • A friendly and welcoming work environment with an international working atmosphere where you can practice and learn new language skills with a diverse mix of colleagues and clients. 
  • A dynamic work environment with a culture that is open, innovative, and performance orientated. 

Employer's offer

Remote position and B2B opportunity

Apply for this position

Are you suitable for this positon? Click on the apply button and upload your CV!

Share this position

Share this position on your social media platform to help a friend to find his/her dreamjob!

Senior Penetration Tester

Please provide your information!


Close

Similar Positions

Senior Dynamics 365 F&O Consultant

Remote2026.08.27.
ROU Bucharest remote senior Swicon Group is…

DCE Lead Engineer — Microsoft Dynamics 365 CE

Remote2026.08.27.
ROU Bucharest remote senior Swicon Group is…

Data Analyst

Hybrid2026.08.27.
ROU Bucharest hybrid medior Swicon Group is…

Mid-level Java Developers

Hybrid2026.08.27.
ROU Bucharest hybrid medior Swicon Group is…

Inginer Sisteme de Securitate

Hybrid2026.08.27.
ROU Bucharest hybrid medior Swicon Group is…

Junior BMS Engineer

OnSite2026.08.27.
ROU Bucharest onSite medior Swicon Group is…

Site Coordinator

OnSite2026.08.27.
ROU Bucharest onSite senior Swicon Group is…

Business Analyst (Claims)

Hybrid2026.08.26.
HUN Budapest hybrid medior Our partner provides…

Swicon Stories

Real people. Real challenges. Real impact.

„The whole hiring process was a really positive experience for me. I was given the opportunity to move forward professionally and to test myself in a new, more senior role. I was trusted from the start, and I had all the support I needed to take the next step in my career with confidence. They connected me with the right technical contact, and every question I had was answered quickly and clearly, so I never felt left on my own. Communication was smooth, each step built on the one before, and the whole process moved surprisingly fast and without a hitch.”

K. R. – Solution Architect

“Looking back over more than 15 years, Swicon gets top marks from me: it has built itself into a fast-growing multinational, and all the while it has backed its people professionally across the board — it even supported my PMP certification with a proper training course.”

B. T. – Sr. Projectmanager

“I’ve been working with SWICON for almost a year and a half now, and it’s been a positive experience from start to finish. Both the hiring process and the admin side of things ran smoothly, and whenever I had a question, help came quickly. I particularly appreciate how kind and helpful my colleagues are, and the fact that the company genuinely invests in building a community — there are regular programmes and events.
I’ve grown a lot professionally in my time here, too. My tasks and my responsibilities have kept widening, I’ve been able to take on more complex challenges, and I’ve also had the chance to support and mentor others. On the IT side I’ve been given opportunities that made a real difference to where I am professionally, so on the whole I see SWICON as a supportive place that gives you genuine room to grow.”

M. L. – Software developer

Powering mission – critical operations across Europe

200+

successful transformation programs

$1.5B

business value created

50M

secure transactions every month

20+

years of enterprise expertise

450+

senior experts

Trusted by enterprise leaders across the world

ROU Bucharest remote senior Swicon Group is one of the leading members of the IT arena for almost a decade, since 2017 present also in Romania. Our wide range of services and highly trained professionals give us the opportunity to shape our solutions to fully meet the ideas and wishes of our clients. We are proud to have leading banks, insurance and telecommunication companies, as well as large FMCG corporations and SSCs amongst our highly prestigious partners. ● Plan and execute manual and automated penetration tests from black/white/grey-box perspectives, including delineation, reconnaissance and mapping, deployment and post-deployment services, technical and executive report generation, followed by retesting and cleanup.● Testing of web applications and APIs against OWASP standards (WSTG, ASVS, Top 10 APIs), with a focus on critical mechanisms such as authentication, authorization, session management, input validation, and encryption.● Testing of mobile applications (native, hybrid, cross-platform) according to OWASP MASTG/MASVS, including reverse engineering activities, static and dynamic analysis, testing of encryption and data storage mechanisms, and application resistance to jailbreak/rooting techniques.● Perform code review for various technology packages (PHP, .NET, Android, Kotlin, Swift, NodeJS, JavaScript, TypeScript), identifying CWEs, logical and design vulnerabilities, cryptographic implementation errors, authentication and authorization issues, and using recognized standards and frameworks (e.g., OWASP ASVS/MASVS, CWE Top 25) as a basis for verification.● Perform vulnerability assessments at the application, infrastructure, and network level, conduct security architecture reviews for complex systems (including cloud, microservices), and organize threat modeling exercises (e.g., STRIDE, OWASP SAMM/ASVS) to identify attack scenarios and mitigation measures.● Write structured technical reports, classify vulnerabilities using CVSS standard, including business impact and remediation recommendations and present results to shareholders and technical teams.● Solid knowledge of the cloud (AWS, Azure, GCP), ability to identify incorrect configurations and recommend measures to secure the cloud infrastructure.● Planning and executing penetration tests on Active Directory/Windows infrastructures: enumeration and mapping, configuration, identification and deployment (Kerberoasting, AS-REP roasting, NTLM relay), lateral movement and privilege escalation, followed by hardening recommendations and retesting. ● Plan and execute manual and automated penetration tests from black/white/grey-box perspectives, including delineation, reconnaissance and mapping, deployment and post-deployment services, technical and executive report generation, followed by retesting and cleanup.● Testing of web applications and APIs against OWASP standards (WSTG, ASVS, Top 10 APIs), with a focus on critical mechanisms such as authentication, authorization, session management, input validation, and encryption.● Testing of mobile applications (native, hybrid, cross-platform) according to OWASP MASTG/MASVS, including reverse engineering activities, static and dynamic analysis, testing of encryption and data storage mechanisms, and application resistance to jailbreak/rooting techniques.● Perform code review for various technology packages (PHP, .NET, Android, Kotlin, Swift, NodeJS, JavaScript, TypeScript), identifying CWEs, logical and design vulnerabilities, cryptographic implementation errors, authentication and authorization issues, and using recognized standards and frameworks (e.g., OWASP ASVS/MASVS, CWE Top 25) as a basis for verification.● Perform vulnerability assessments at the application, infrastructure, and network level, conduct security architecture reviews for complex systems (including cloud, microservices), and organize threat modeling exercises (e.g., STRIDE, OWASP SAMM/ASVS) to identify attack scenarios and mitigation measures.● Write structured technical reports, classify vulnerabilities using CVSS standard, including business impact and remediation recommendations and present results to shareholders and technical teams.● Solid knowledge of the cloud (AWS, Azure, GCP), ability to identify incorrect configurations and recommend measures to secure the cloud infrastructure.● Planning and executing penetration tests on Active Directory/Windows infrastructures: enumeration and mapping, configuration, identification and deployment (Kerberoasting, AS-REP roasting, NTLM relay), lateral movement and privilege escalation, followed by hardening recommendations and retesting. Requirements: ●      Network scanning: Nmap, masscan, Shodan, Censys●      Vulnerability scanning: Nessus, OpenVAS, nuclei●      Web testing: Burp Suite Pro, OWASP ZAP, sqlmap, ffuf, dirsearch, Nikto, wpscan, XSStrike●      Recon subdomains: subfinder, findomain●      Post-deployment: Metasploit Framework, Impacket, BloodHound●      Reverse engineering: jadx, Ghidra, r2●      Mobile device: MobSF, Drozer, adb, Frida, Objection●      Password cracking: John, Hashcat●      Supply chain scanning: trivy, OWASP Dependency Check●      SAST si secret scanning: Semgrep, SonarCloud, gitleaks, truffleHog●      API si HTTP: Postman●      Scripting usage: jq, Python, Bash, PowerShell Excellent learning opportunities! Variety in your work and a fantastic, informal work atmosphere. A challenging environment that will stimulate you to grow as a professional! A great foundation for your career! Grow with us! Your role will develop over time, so you can increase your experience and responsibilities. So, you can advance faster and further in your future career. A friendly and welcoming work environment with an international working atmosphere where you can practice and learn new language skills with a diverse mix of colleagues and clients. A dynamic work environment with a culture that is open, innovative, and performance orientated.  Remote position and B2B opportunity