Lead APT & Automated Validation Engineer
Remote, PolskaKey offer highlights
Min. 5 years of experience
Backend: Java / .NET / Node / Python
Remote work - no commuting
Full-time
Description
We are seeking a Lead APT & Automated Validation Engineer who goes beyond traditional penetration testing. This role is for a developer at heart — someone who can orchestrate, script, and chain network and web application exploits to run autonomously, driving continuous and scalable security validation across complex environments. Responsibilities Design and sequence exploit chains that combine multiple vulnerabilities to achieve higher-impact outcomes (e.g., pairing information disclosure with SSRF to reach Remote Code Execution) Develop custom exploits and weaponized scripts to automate multi-stage attack scenarios Build and maintain automated authentication flows handling OAuth, TOTP, and MFA programmatically Configure, scale, and operate continuous automated security validation platforms Engineer exploit scripts capable of safely validating vulnerabilities in live production environments without disrupting services or corrupting data Analyze network and web application attack surfaces to identify opportunities for automated exploitation Collaborate with security and engineering teams to translate manual pentesting techniques into repeatable, automated workflows Continuously improve the organization's offensive automation framework and tooling Requirements 5+ years of experience in offensive security, penetration testing, or security engineering roles At least 1 year of relevant leadership experience Expertise in exploit chaining and attack logic, including sequencing low-severity findings into high-impact compromises Proficiency in Python for writing custom exploits and automating complex multi-stage attack scripts Experience configuring and scaling continuous automated security validation tools such as Pentera, Cymulate, or Picus, including custom Pentest Robots architectures In-depth knowledge of the OSI model and core network protocols (DNS, BGP, TCP/IP) Understanding of web application vulnerabilities, including the OWASP Top 10 and API flaws such as IDOR Proven capability to engineer automated exploit scripts that safely validate vulnerabilities without crashing network infrastructure or corrupting production databases English proficiency at B1+ level or above Nice to have Skills in Bash and/or Go for custom tooling and exploit development Familiarity with OAuth flows and programmatic handling of authentication Background in bypassing or automating Multi-Factor Authentication challenges
Requirements
5+ years of experience in offensive security, penetration testing, or security engineering roles
At least 1 year of relevant leadership experience
Expertise in exploit chaining and attack logic, including sequencing low-severity findings into high-impact compromises
Proficiency in Python for writing custom exploits and automating complex multi-stage attack scripts
Experience configuring and scaling continuous automated security validation tools such as Pentera, Cymulate, or Picus, including custom Pentest Robots architectures
In-depth knowledge of the OSI model and core network protocols (DNS, BGP, TCP/IP)
Understanding of web application vulnerabilities, including the OWASP Top 10 and API flaws such as IDOR
Proven capability to engineer automated exploit scripts that safely validate vulnerabilities without crashing network infrastructure or corrupting production databases
English proficiency at B1+ level or above
Responsibilities
Design and sequence exploit chains that combine multiple vulnerabilities to achieve higher-impact outcomes (e.g., pairing information disclosure with SSRF to reach Remote Code Execution)
Develop custom exploits and weaponized scripts to automate multi-stage attack scenarios
Build and maintain automated authentication flows handling OAuth, TOTP, and MFA programmatically
Configure, scale, and operate continuous automated security validation platforms
Engineer exploit scripts capable of safely validating vulnerabilities in live production environments without disrupting services or corrupting data
Analyze network and web application attack surfaces to identify opportunities for automated exploitation
Collaborate with security and engineering teams to translate manual pentesting techniques into repeatable, automated workflows
Continuously improve the organization's offensive automation framework and tooling
Seniority
Lead
Nice to have
Skills in Bash and/or Go for custom tooling and exploit development
Familiarity with OAuth flows and programmatic handling of authentication
Background in bypassing or automating Multi-Factor Authentication challenges
Keywords / Skills