pracaon.plpracaon.pl

Lead APT & Automated Validation Engineer

Remote, Polska
EPAM
Partner
today
Salary to be agreed
Full-time • Remote • IT, Data & AI

Key offer highlights

  • Min. 5 years of experience

  • Backend: Java / .NET / Node / Python

  • Remote work - no commuting

  • Full-time

Description

We are seeking a Lead APT & Automated Validation Engineer who goes beyond traditional penetration testing. This role is for a developer at heart — someone who can orchestrate, script, and chain network and web application exploits to run autonomously, driving continuous and scalable security validation across complex environments. Responsibilities Design and sequence exploit chains that combine multiple vulnerabilities to achieve higher-impact outcomes (e.g., pairing information disclosure with SSRF to reach Remote Code Execution) Develop custom exploits and weaponized scripts to automate multi-stage attack scenarios Build and maintain automated authentication flows handling OAuth, TOTP, and MFA programmatically Configure, scale, and operate continuous automated security validation platforms Engineer exploit scripts capable of safely validating vulnerabilities in live production environments without disrupting services or corrupting data Analyze network and web application attack surfaces to identify opportunities for automated exploitation Collaborate with security and engineering teams to translate manual pentesting techniques into repeatable, automated workflows Continuously improve the organization's offensive automation framework and tooling Requirements 5+ years of experience in offensive security, penetration testing, or security engineering roles At least 1 year of relevant leadership experience Expertise in exploit chaining and attack logic, including sequencing low-severity findings into high-impact compromises Proficiency in Python for writing custom exploits and automating complex multi-stage attack scripts Experience configuring and scaling continuous automated security validation tools such as Pentera, Cymulate, or Picus, including custom Pentest Robots architectures In-depth knowledge of the OSI model and core network protocols (DNS, BGP, TCP/IP) Understanding of web application vulnerabilities, including the OWASP Top 10 and API flaws such as IDOR Proven capability to engineer automated exploit scripts that safely validate vulnerabilities without crashing network infrastructure or corrupting production databases English proficiency at B1+ level or above Nice to have Skills in Bash and/or Go for custom tooling and exploit development Familiarity with OAuth flows and programmatic handling of authentication Background in bypassing or automating Multi-Factor Authentication challenges

Requirements

  • 5+ years of experience in offensive security, penetration testing, or security engineering roles

  • At least 1 year of relevant leadership experience

  • Expertise in exploit chaining and attack logic, including sequencing low-severity findings into high-impact compromises

  • Proficiency in Python for writing custom exploits and automating complex multi-stage attack scripts

  • Experience configuring and scaling continuous automated security validation tools such as Pentera, Cymulate, or Picus, including custom Pentest Robots architectures

  • In-depth knowledge of the OSI model and core network protocols (DNS, BGP, TCP/IP)

  • Understanding of web application vulnerabilities, including the OWASP Top 10 and API flaws such as IDOR

  • Proven capability to engineer automated exploit scripts that safely validate vulnerabilities without crashing network infrastructure or corrupting production databases

  • English proficiency at B1+ level or above

Responsibilities

  • Design and sequence exploit chains that combine multiple vulnerabilities to achieve higher-impact outcomes (e.g., pairing information disclosure with SSRF to reach Remote Code Execution)

  • Develop custom exploits and weaponized scripts to automate multi-stage attack scenarios

  • Build and maintain automated authentication flows handling OAuth, TOTP, and MFA programmatically

  • Configure, scale, and operate continuous automated security validation platforms

  • Engineer exploit scripts capable of safely validating vulnerabilities in live production environments without disrupting services or corrupting data

  • Analyze network and web application attack surfaces to identify opportunities for automated exploitation

  • Collaborate with security and engineering teams to translate manual pentesting techniques into repeatable, automated workflows

  • Continuously improve the organization's offensive automation framework and tooling

Seniority

  • Lead

Nice to have

  • Skills in Bash and/or Go for custom tooling and exploit development

  • Familiarity with OAuth flows and programmatic handling of authentication

  • Background in bypassing or automating Multi-Factor Authentication challenges

Keywords / Skills

Security.Testing
Cyber Threat Intelligence
OWASP Top 10
Python
Threat Modeling
Vulnerability Management
Bash
Go Language
Multi-Factor Authentication
OAuth
This offer was imported from an external portal.Listing source

More similar listings