Cookies & analytics consent
We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.
Read how we use data in our Privacy Policy and Terms of Service.
🤖 15+ AI Agents working for you. Find jobs, score and update resumes, cover letter, interview questions, missing keywords, and lots more.
Thermo Fisher Scientific • Brno, Southeast, Czechia
Role & seniority: Senior Product Penetration Tester (Senior/Lead-level)
Stack/tools: Offensive security across software, hardware, cloud; Burp Suite Pro, Nmap, Metasploit; cloud-native assessment tools; scripting (Python, PowerShell, Go); familiarity with Windows/Linux internals; web apps, APIs, cloud, embedded/desktop, AI/ML workloads
Lead and independently perform complex, open-box penetration tests across diverse technologies
Prepare detailed, actionable security reports; communicate findings to technical and non-technical audiences
Mentor junior staff, collaborate with product engineering, security architecture, and incident response to drive remediation and secure-by-design practices; contribute to tooling and methodology improvements
Extensive hands-on offensive security experience (web, APIs, cloud, embedded/desktop)
Ability to develop and present clear technical reports; cross-functional collaboration
Knowledge of vulnerability classes (OWASP Top 10, MITRE ATT&CK), secure architecture, and testing methodologies
Bachelor's or Master’s in Cybersecurity/CS/Engineering (or equivalent experience); relevant certifications preferred (e.g., OSCP, GPEN, GWAPT)
Hardware testing experience; AI/ML/LLM security testing
Experience with CTF/HTB or security community involvement
Location: Not specified
Work type: Office environment, standard Mon-Fri s
Work Schedule Standard (Mon-Fri) Environmental Conditions Office Job Description As a Senior Product Penetration Tester, you will be part of a collaborative team passionate about identifying and reducing product risk across Thermo Fisher Scientific’s diverse portfolio. You’ll conduct comprehensive security assessments across software, hardware, and cloud environments to identify vulnerabilities and provide actionable recommendations that strengthen the security posture of our products. The ideal candidate will have a strong background in penetration testing and experience with a variety of technologies and tools. This position offers the opportunity to develop deep technical expertise while directly improving the security of the technologies advancing science and healthcare. A Day in the Life Lead and independently complete complex, open-box penetration tests across diverse technologies, including APIs, cloud environments, embedded systems, web applications, and AI/ML workloads. Serve as a technical leader for advanced security assessments, focusing on complex architectures and new technologies. Prepare detailed reports to effectively communicate findings and recommendations to technical and non-technical collaborators. Partner with cross-functional collaborators, including product engineering and management, security architecture, and incident response to drive remediation and strengthen product security throughout the development lifecycle. Mentor junior team members while encouraging a collaborative and knowledge-sharing environment. Contribute to internal tooling, automation, and methodology improvements to improve testing and technical precision. Stay informed on new technologies, attack techniques, and threat trends to proactively identify potential vulnerabilities. Keys to Success The Senior Product Security Researcher thrives by combining deep technical expertise with strategic insight. You’ll bring to bear your experience in offensive security to uncover and communicate meaningful risks across Thermo Fisher’s product portfolio. You’ll succeed by: Leading complex, full-scope testing engagements that uncover impactful vulnerabilities and drive secure build improvements. Translating technical findings into actionable security improvements that align with business priorities. Coordinating with product, architecture, and incident response teams to achieve timely remediation and incorporate secure-by-design principles. Mentoring colleagues and influencing security guidelines across engineering and product organizations. Supporting the development of internal tools, automation, and testing strategies to improve the team’s technical exactness. Staying curious and continuously exploring new technologies and attack vectors relevant to our diverse product portfolio. xperience Strong and proven years of hands-on experience in offensive security, passionate about penetration testing or vulnerability research. Demonstrated ability to independently perform advanced testing on various technologies including web applications, APIs, cloud infrastructure, and embedded or desktop platforms. Demonstrated expertise in modern attack methodologies, exploit development, and secure architecture principles. Proven ability to develop clear, actionable technical reports and clearly present results to audiences with varying technical backgrounds. Experience collaborating with cross-functional teams to support remediation and drive security improvements. Bachelor’s or Master’s Degree in Cybersecurity, Computer Science, Engineering, or related field. Equivalent professional experience considered. Certifications (preferred but not required): OSCP, OSWA, GPEN, GWAPT, CPTS, CWES, or similar. Knowledge, Skills, and Abilities Technical Expertise: Extensive knowledge of common and emerging vulnerability classes (e.g., OWASP Top 10, MITRE ATT&CK, cloud misconfigurations, supply chain risks). Proficiency with industry-standard tools (e.g., Burp Suite Pro, Nmap, Metasploit, and cloud-native assessment tools). Strong technical knowledge of standard network communication protocols and operating system internals in both Windows and Linux settings. Familiarity with common cybersecurity frameworks, regulatory requirements, and industry guidelines (e.g., OWASP, NIST, FDA, CRA). Experience identifying and mitigating security risks in cloud-native architectures. Experience with custom scripting or exploit development (Python, PowerShell, Go, etc.). Practical experience with compiled languages like C, C++, or C#, including the capability to examine and assess code for security concerns. Experience developing and maintaining testing methodologies and technical documentation. Analytical Skills: Strong analytical and problem-solving approach with the ability to apply testing methodologies to assess exploitability and inform remediation. Diligent approach to testing ensuring accuracy, consistency, and practical relevance. Communication Skills: Strong written and spoken communication skills, with the capability to articulate complex technical concepts clearly to audiences with varying technical backgrounds. Skilled at communicating technical risk in business-relevant terms to influence remediation and product build decisions. Ability to operate independently while collaborating effectively across multidisciplinary teams. Produce comprehensive reports and presentations that clearly communicate findings and recommendations to diverse collaborators. Nice-to-Have Skills: Experience with hardware testing, including debugging, chip identification, and common protocols. Experience testing AI/ML or LLM-integrated applications or products. Participation in Capture The Flag (CTF) competitions, Hack The Box (HTB), or similar technical challenges. Passion for security and community involvement (teaching, volunteering, presenting at conferences). Benefits We offer competitive remuneration, annual incentive plan bonus, healthcare, and a range of employee benefits. Thermo Fisher Scientific offers employment with an innovative, forward-thinking organization, and outstanding career and development prospects. We offer an exciting company culture that stands for integrity, intensity, involvement, and innovation! Thank you for your interest as you consider starting a new career journey with us. As the world leader in serving science, our colleagues develop critical solutions through innovation—and build rewarding careers. Discover their extraordinary stories and connection to our Mission to enable our customers to make the world healthier, cleaner and safer. Their work is a story of purpose. What story will you tell? Thermo Fisher Scientific Inc. is the world leader in serving science, with annual revenue of more than $40 billion. Our Mission is to enable our customers to make the world healthier, cleaner and safer. Whether our customers are accelerating life sciences research, solving complex analytical challenges, increasing productivity in their laboratories, improving patient health through diagnostics or the development and manufacture of life-changing therapies, we are here to support them. Our global team delivers an unrivaled combination of innovative technologies, purchasing convenience and pharmaceutical services through our industry-leading brands, including Thermo Scientific, Applied Biosystems, Invitrogen, Fisher Scientific, Unity Lab Services, Patheon and PPD. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation. Thermo Fisher Scientific is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, creed, religion, color, national or ethnic origin, citizenship, sex, sexual orientation, gender identity and expression, genetic information, veteran status, age or disability status.