Cookies & analytics consent
We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.
Read how we use data in our Privacy Policy and Terms of Service.
🤖 15+ AI Agents working for you. Find jobs, score and update resumes, cover letter, interview questions, missing keywords, and lots more.

Euroclear • Krakow, Lesser Poland Voivodeship, Poland
Role & seniority: Penetration Testing Analyst (mid-level) within the Offensive Security Tribe, part of CISO.
Stack/tools: Application- and infrastructure-focused testing; offensive security tools; static/dynamic code analysis; vulnerability management; familiarity with OWASP Top 10; knowledge of security design principles and ISO27002; agile/automation and AI-enabled processes.
Prepare, execute, and deliver penetration tests for regulatory/project needs (applications and infrastructure);
Support remediation activities, retesting, and validation of fixes;
Coordinate third-party testing engagements, document roadmaps, and advise stakeholders on offensive security strategy.
Experience in penetration testing, ideally in a regulated environment
Proficiency with offensive security tools and techniques, including static/dynamic analysis and vulnerability management
Strong understanding of application security (OWASP Top 10, common attack vectors) and good communication/collaboration skills
Remediation consulting experience or alternative testing methods
Knowledge of ISO27002; experience with red/purple teaming, code analysis, or broader offensive security domains
Experience with automation, AI-assisted testing, or cross-functional testing discussions
Location & work type: Hybrid work model (office + remote); full-time position within Euroclear’s global infrastructu
Job Description
Division: CISO
Security is at the core of Euroclear’s services, embedded in every system and process across the organization. As part of the Chief Information Security Office (CISO), you will join the Offensive Security Tribe, a team dedicated to proactively identifying vulnerabilities and strengthening our cyber resilience.
This role focuses on penetration testing and remediation support, with opportunities to grow across a broad range of offensive security domains including red/purple team exercises, code analysis, and vulnerability management.
Your role
As a Penetration Testing Analyst, You Will
Prepare, execute, and deliver penetration tests for regulatory and project needs, primarily focused on applications but also covering infrastructure. Support remediation activities and retesting to validate fixes. Coordinate third-party testing engagements, including scoping, stakeholder alignment, and result dissemination. Maintain documentation and roadmaps for ongoing testing and remediation. Advise application owners and project leads on offensive security strategy and testing techniques. Contribute to the evolution of offensive security frameworks and processes. Represent the Offensive Security team in cross-functional testing discussions and act as a center of competence. Support Agile practices, reporting, and continuous improvement initiatives using automation and AI.
You’ll encounter the full spectrum of the attack chain—from web applications to binary exploitation and infrastructure—requiring a strong grasp of security policies and creative testing approaches.
Your profile
Experience in penetration testing, ideally within a regulated environment. Familiarity with offensive security tools and techniques, including static/dynamic code analysis and vulnerability management. Strong understanding of application security principles, including OWASP Top 10 and common attack vectors (e.g., SQLi, XSS, DLL hijacking). Knowledge of security design principles (confidentiality, integrity, availability) and ISO27002 standards is a plus. Experience with remediation consulting and alternative testing methods is an advantage. Detail-oriented, analytical, and eager to learn. Strong communication skills and ability to collaborate across technical and business teams.
About Us
Why join us
Embark on your new adventure at Euroclear, and work at the heart of the global capital markets. We connect over 2,000 financial institutions across the globe. As an open and resilient infrastructure, we contribute to the stability of the financial markets. We help clients cut through complexity, lower costs, and mitigate risks of financial transactions. At Euroclear, we have the clear ambition to use our key role to facilitate and accelerate a sustainable global financial system.
What We Offer
Work closely with inspiring, supportive and engaged colleagues from more than 80 different countries. Practice your talents in a highly professional international environment. Join a learning and development environment with an emphasis on knowledge sharing and training. Competitive salary and comprehensive benefits.
New ways of working
Find your own optimal balance within our hybrid working model, where you can connect at the office and also benefit from remote working.
Great Place to Work for All
We are committed to creating an inclusive culture that celebrates diversity and strives to be a Great Place to Work for All. All qualified applicants will be considered for employment, regardless of any aspect that makes them unique (including race, religion, national origin, gender, sexual orientation, age, marital status, pregnancy, disability, ...). If you need any specific accommodation due to disability or any other reason, you can let the recruiter know during your application process.
About The Team
As a global critical financial infrastructure, the protection of Euroclear information and assets is fundamental to the companys' business. Security is at the core of our services, firmly embedded in the management systems and processes of the company. You will be joining our Chief Information Security Office (CISO) in charge of putting in place the required controls to adequately and effectively protect our information assets.
Show more Show less