implementation and coordination of penetration tests (white-box, black-box) including scope planning, technique selection, and findings evaluation
security testing of internally developed and supplier applications with a focus on secure SDLC, application security, access rights control, and architectural weaknesses
technical participation in tests – independent execution of selected techniques (e.g., OWASP tests, vulnerability analysis, configuration checks, IAM tests)
testing and verification of business continuity plans (BCM, DRP), failure simulations, verification of recovery from backups, and incident response
analysis of test outputs, classification of vulnerabilities by risk, proposal of mitigations, and their communication to IT teams and management
creation and updating of testing scenarios, methodologies, and reporting in accordance with regulatory requirements of the banking sector
cooperation with IT, cybersecurity, operations, and risk management teams in managing operational and cyber risks
participation in the development of security standards and increasing security awareness across the organization
Requirements
Advanced experience with:
penetration testing of systems and applications (min. 3 years of practice), management and evaluation of security tests
Experience with:
practical execution of technical security tests, vulnerability analysis, testing of access rights and application security
Advanced knowledge of:
security frameworks and methodologies such as OWASP, MITRE ATT&CK, PTES, OSSTMM, NIST SP 800-115, TIBER-EU
Knowledge of:
business continuity testing (BCM/DRP), incident response, data backup and recovery
regulatory requirements and standards in the field of security (NIS2, DORA, ISO/IEC 27001)
Czech language at a level that enables work in a Czech environment
English language at a technical level for communication with suppliers
Advantageous:
certifications such as OSCP, CEH, CISA, ISO 27001 LA/LI
experience from the banking or other highly regulated environment
Are you interested in this offer?
Recommendan IT specialistDo you know anyone who could usethis project? Recommend him
and get a reward!
Hirean IT specialistDo you need a similarIT freelancer for your project?
Hire a specialist