Application Security Tester

  • Philip Morris International SCE
  • Krakow
  • Employment contract

Philip Morris International SCE

  • Krakow

Requirements

Experience level: Senior

Who we’re looking for

  • Minimum 5 years of experience in ethical hacking/penetration testing/vulnerability assessment, preferably in professional services or consulting companies
  • Professional certifications in ethical hacking (e.g. OSCP, GIAC Penetration Tester, GIAC Web Application Penetration Tester, GIAC Mobile Device Security Analyst)
  • Proven track record in performing web/mobile application security testing using well-known methodologies (OWASP, OSMMT or CREST) and techniques (SAST, DAST, IAST, SCA)
  • Demonstrated experience with both automated and manual penetration testing using open source and/or commercial tools
  • Knowledge of common web/mobile technologies (e.g. ASP.NET, C#, Java, JavaScript, Ruby, Python)
  • Strong understanding of modern application architectures including microservices, containers, APIs and serverless technologies
  • Sound knowledge of impact and remediation techniques for vulnerabilities from and outside of OWASP Top 10
  • Considerable technical writing proficiency and oral presentation skills, in English
  • Practical experience in Agile/DevOps organizations and cultures

Technologies

Necessary on this position:
  • ASP.NET or C# or Java or JavaScript or Ruby or Python

Project you can join

Join us in this role and you’ll be part of our IT Information Security & Data Privacy international team in the beautiful city of Krakow, Poland.

Your “day to day”

  • Identify cybersecurity vulnerabilities in PMI applications and systems using a wide variety of methods, e.g. static code analysis, dynamic/interactive testing, manual penetration testing and code review
  • Describe identified issues in the form of reports and ensure that relevant stakeholders understand the risk that those vulnerabilities pose to the Company
  • Analyze the scope, methodology and results of ethical hacking activities performed by third parties around the presence of vulnerabilities in systems used or to be used by PMI
  • Follow up with third parties on any inconsistency and ambiguity in the reports to have a reasonable level of assurance over security testing deliverables provided by vendors
  • Advise IT teams on how to replicate identified cybersecurity issues and remediate them in the most effective and cost-efficient way
  • Partner with other Information Security leaders to ensure that PMI follows best practices in the application security testing domain by continuously optimizing tools, techniques and methodologies
  • Keep up to date with the constantly evolving cyber threat landscape and the latest developments in ethical hacking techniques

What we offer

Our success depends on the men and women who come to work every single day with a sense of purpose and an appetite for progress. Join PMI and you too can:

  • Seize the freedom to define your future and ours – we’ll empower you to take risks, experiment and explore
  • Be part of an inclusive, diverse culture, where everyone’s contribution is respected; collaborate with some of the world’s best people and feel like you belong
  • Pursue your ambitions and develop your skills with a global business – our staggering size and scale provides endless opportunities to progress
  • Take pride in delivering our promise to society: to improve the lives of a billion smokers

Bonuses

  • Healthcare package
  • Healthcare package for families
  • Cold beverages
  • Hot beverages
  • Fruits
  • Snacks
  • Lunches
  • Adaptation tips
  • Language courses
  • Temporary housing
  • Help finding an apartment
  • Visa Services
  • Sign up bonus
  • Flight ticket
  • Money for moving expenses
  • Conferences
  • Trainings
  • Books
  • Car parking
  • Bicycle parking
  • Shower
  • Chill room
  • Playroom for children
  • Integration events

Contact this employer

Philip Morris International SCE is a Data Controller ...