O pozici
Who we are and what we do The Cyber Testing Center (CTC) is an international team of security professionals and ethical hackers who thrive on discovering how things work - and how they can be made safer. Every day we put web, mobile applications and infrastructure under the microscope, while also delivering hands-on training and workshops for our internal customers. As cyber-threats evolve, so do we. To keep NN’s digital landscape secure, we’re searching for a mid level Penetration Tester to join our team. In this role you’ll hunt for vulnerabilities, champion secure-by-design practices across all NN countries, establish testing standards, share cutting-edge tools, and teach development teams how to build resilient applications. Hop on, grow with us, and help safeguard the digital world for millions of NN users.
Co budeš dělat
- Perform DAST/SAST/IAST assessments against OWASP ASVS and MASVS standards to keep our apps secure.
- Perform infrastructure security assessments for our clients, including configuration reviews.
- Share your expertise: deliver workshops to app developers and infrastructure teams on security best practices.
- Support our clients and give them recommendations on the fixes.
- Make things safer with your own ideas, research, and innovative solutions.
- Assist with responsible disclosure program that NN Group runs.
- Build new tools and contribute to projects that expand and improve our pentesting service.
- Contribute to our internal project that includes LLM and will increase our testing coverage.
Koho hledáme
- Strong IT background and 2-5 years of experience in the penetration testing.
- Hands-on experience with web development (.NET, Java, Python, shell scripting, etc.), penetration testing, and system administration.
- Experience with penetration testing of mobile applications (iOS and Android)
- Experience with penetration testing of AI/LLM solutions and developing projects that use LLMs
- Excellent communication skills - you’re great at teaching, writing guidelines and able to explain to developers what and why needs to be fixed
- Staying up to date with the latest security trends and techniques, performing CTF labs and always working on your pentesting skills.
Benefity
- Real Cybersecurity: You’ll break into real systems to find real weaknesses, not just pretend threats or lab simulations.
- Learn & Grow: We support your certifications (including providers like OffSec, HTB etc.), training, conferences and continuous development.
- Hybrid & Flexible: Enjoy a strong home office culture, flexible time off, and a hybrid setup - most of the time you can work from home, in the office you will be needed ad-hoc only, as we do not have mandatory office days.
- People-First Culture: Down-to-earth, open team with no unnecessary formalities (no ego, no blame, just real support).
- Modern Tools: Get a company laptop and iPhone with a fully paid plan.
- Great Benefits: Cafeteria up to 20,000 CZK, pension contributions, MultiSport card, meal allowance, discount on life insurance, contribution to HO expenses
- Care for Your Well-being: You can take advantage of the Mojra psychological counselling, Health Days every autumn, and an increased cafeteria allowance of CZK 12,000 per year for employees with disabilities.
- Referral Bonus: Get up to 60,000 CZK for referring new colleagues.
- Personalized Onboarding: During your probation, we’ll help you settle in with more in-person support