Offensive Security Engineer / Penetration Tester
✨ AI Summary
Genesis, a top European product IT ecosystem with 1B+ downloads and Forbes best employer recognition, is hiring an Offensive Security Engineer/Penetration Tester for its Offensive Security Team. You'll deliver end-to-end penetration tests on web, mobile, Active Directory, and cloud environments, with a focus on AWS security methodology and AI-agent automation. Requires 2.5+ years of commercial pentesting, a practical cert (OSCP, CPTS, GPEN, or CWEE), and B2+ English. Offers flexible remote work, medical insurance, 20 vacation days, and training support.
About Genesis
Genesis is an ecosystem of product IT companies building global innovative products. Products created within the Genesis ecosystem have been downloaded over 1 billion times in total. Genesis is one of Europe's leading tech teams: ranked the best employer by Forbes in 2023 and 2026, and the top IT employer by the DOU community in 2024 and 2025.
About the team and the role
Our Offensive Security Team — part of [TO FILL: name of the ecosystem company / service brand the candidate is joining] — is five engineers delivering penetration testing to external clients, alongside our Application Security, Infrastructure Security and Dark Web Monitoring service lines. You'll own engagements yourself: scoping, testing, reporting and the client conversation that follows, with the Team Lead and fellow engineers reviewing your findings rather than managing your calendar. Demand for our testing services keeps growing, and we're raising the technical bar across all four platforms instead of depending on individual specialists. In your first months you'll deliver client engagements end to end and build our internal methodology for AWS cloud security assessment. Within a year you'll be the team's reference point on at least one platform, and the AI agents you build will be covering the recon and enumeration phases of our tests.
What you'll be doing:
- Deliver end-to-end penetration tests of Web and Mobile applications, Active Directory and cloud environments — from scoping and recon through exploitation and post-exploitation to evidence collection and retest;
- Validate findings from our Application Security and Infrastructure Security services and triage automated scan output: eliminate false positives, confirm exploitability and real business impact, assign accurate risk ratings;
- Write client-facing technical reports in English — reproduction steps, evidence, business-impact framing and practical remediation guidance;
- Communicate directly with clients: kick-off calls, status updates, report walkthroughs, remediation Q&A and retest agreement;
- Build automation and internal tooling that shortens the recon, enumeration and active scanning phases, including AI-agent-based workflows;
- Create and maintain the internal methodology, testing checklists and knowledge base for our Offensive Security service lines;
- Research new attack techniques, evaluate tooling and share what you find with the team.
What we expect from you:
- 2.5+ years of hands-on commercial penetration testing, with several engagements delivered end to end and reports written by you, plus at least one practical certification — OSCP, CPTS, GPEN or CWEE, or a proven equivalent;
- Web application testing to the OWASP Web Security Testing Guide and beyond it: authentication and authorisation flaws, IDOR, injection, SSRF, insecure deserialization and business-logic abuse, with Burp Suite Professional as a daily tool;
- Mobile application testing based on OWASP MASTG for Android and/or iOS: static and dynamic analysis, traffic interception, certificate pinning bypass, insecure local storage, IPC and platform misuse;
- Working knowledge of Active Directory and internal network attacks: enumeration, Kerberos abuse, credential relaying, lateral movement and privilege escalation paths;
- Scripting in Python and/or Bash, and the ability to read application source code and trace vulnerable patterns in at least one of PHP, Java, C#, JS/TS or Python;
- English at B2 or above — enough to run client calls, write structured evidence-based reports and justify a severity rating to a technical client.
Nice to have:
- A second practical certification: BSCP, CWEE, CAPE, GWAPT, OSWE, CRTO, eWPTX or eMAPT;
- Cloud security testing in AWS, Azure or GCP: misconfiguration review, identity and privilege-escalation paths, attacks on managed services;
- Hands-on experience or genuine interest in AI and LLM security — OWASP Top 10 for LLM Applications, prompt injection, agent abuse — and in using AI agents inside offensive workflows;
- Public technical contribution: CVEs, open-source tooling, research write-ups, conference talks, or bug bounty with high-quality reports.
What we offer
- Flexible hours and the option to work from anywhere that suits you;
- Medical insurance;
- 20 paid vacation days per year and unlimited sick leave;
- All the equipment you need for work;
- Compensation for professional training, access to our internal learning platform and lectures;
- Corporate events and networking;
- Free sports training, corporate discounts, and massage when you visit the office;
- Support for colleagues and their families serving in the Defence Forces;
- Support for veterans;
- Assistance in case of harm to health or property caused by the war.
Hiring process
- Intro call with the recruiter;
- Interview with the Offensive Security Team Lead;
- Test task and a walkthrough of your solution;
- Bar-raising interview;
- Offer.
Supporting Ukraine 🇺🇦
The Genesis for Ukraine foundation was created in April 2022 in response to the full-scale invasion and the need to act systematically and for the long term. Its focus is supporting Genesis employees and their families in the military, helping the country, and developing educational and veteran projects that support reintegration into civilian life. Its large-scale partnership initiatives include Ukraine's first Veteran Master's Programme, an innovation space with a 3D-printing farm at Kyiv Polytechnic Institute, entrepreneurship training and grant programmes for veterans.
As of early 2026:
- UAH 650+ million — total aid to Ukraine from Genesis and its partners;
- UAH 26+ million — targeted assistance to employees and their families serving in the military.
If this sounds like you, send us your CV along with any public write-ups, CVEs or tooling you'd like us to see. We review every application.
About the Company
Genesis — це українська кофаундингова IT-компанія та один із найбільших глобальних паблішерів неігрових застосунків. Як кофаундингова компанія, Genesis спочатку надає перспективним стартапам необхідні ресурси та експертизу для розвитку, а потім супроводжує проєкт, поки він не стане самостійним бізнесом. Повний список компаній екосистеми й партнерів, шукайте на нашому сайті.
Genesis неодноразово визнавали одним із найкращих ІТ-роботодавців країни у різних рейтингах. У 2024 році компанія посіла перше місце у рейтингу ІТ-роботодавців від DOU. У 2023 році компанія стала найкращим роботодавцем України воєнного часу за версією Forbes.
25+ проєктів
3000+ співробітників
1 млрд завантажень застосунків по всьому світу
Genesis засуджує збройну агресію росії, долучається до зміцнення України та наймає ветеранів і ветеранок.
Переваги роботи для генезійців
💻 Робочі умови
- Гнучкий графік роботи. Робочі умови варіюються в залежності від вашої позиції та / або проєкту з екосистеми Genesis.
- За потреби — допомога з релокацією в безпечні місця та пошуком житла.
- 20 робочих днів оплачуваної відпустки на рік, необмежена кількість лікарняних.
- Уся необхідна для роботи техніка.
- Комфортні офіси на київському Подолі з надійними укриттями. В офісах можна не турбуватися про рутину: тут на вас чекають сніданки, обіди, безліч снеків та фруктів, лаунжзони, масаж та інші переваги офісного життя 🙂
🩺 Здоров’я генезійців
- Послуги корпоративного лікаря, а після випробного терміну — медичне страхування в Україні.
- Безкоштовні тренування з бігу, волейболу, боксу та йоги. Корпоративні знижки на абонементи в спортзали.
🚀 Кар’єрний розвиток
- Компенсація найкращих на ринку курсів, корпоративні онлайн-мітапи та лекції, велика бібліотека, бізнес- та менеджмент школи для співробітників.
- 11 професійних внутрішніх ком’юніті для твого кар’єрного розвитку (DevOps, Front-end, Back-end, QA, Product, Analytics, Marketing, Design, PR та Recruiting)
More jobs at Genesis Tech
-
Senior/Lead Product QA Engineer (AI Product)
remote, Ukraine · remote · Sep 2, 2026
-
Middle Data Analyst (Boosters)
Київ, Україна · remote · Aug 18, 2026
-
AI Full-Stack Engineer
Kyiv, Ukraine · remote · Aug 18, 2026
-
Product Data Analyst (Boosters)
Київ, Україна · remote · Aug 18, 2026
-
Middle Data Analyst (Findies)
Ukraine · remote · Aug 18, 2026