Ethical Hacker / Pentester
Offer summary

(Summary generated by AI based on the full job description)

The project focuses on a multi-factor authentication (MFA) platform specializing in R&D of security and deploying passwordless MFA using WebAuthn/FIDO2. Key technologies include Windows Server, Active Directory (Azure AD), Kerberos, NTLM, OAuth 2.0, SAML and hardware-backed security like TPM 2.0 and U2F/FIDO2. Responsibilities cover threat modeling, cryptographic analysis, prototyping, attack monitoring, and leading red-team exercises. Offered benefits include private medical care and flexible working conditions.

newyou can start ASAP

Ethical Hacker / Pentester

Company: RUBLON sp. z o.o.

from: 27 August 2026
to: 26 September 2026
13 000 - 18 000gross/ mth.contract of employment (full-time)
Salary details
basic salary
Offer parameters
level:mid
working mode:remote
Zielona Góra, Lubusz
Zielona Góra, LubuszStanisława Wyspiańskiego 11View on map

Requirements

Expected technologies

Active Directory

Our requirements

  • Foundational penetration-testing experience on Microsoft platforms – you’ve performed security assessments of Windows 10/11 or Windows Server environments and can use common tools (e.g., Nmap, Responder, BloodHound) to spot basic mis­configurations.
  • Good understanding of authentication concepts – you know how MFA, Kerberos, and NTLM work at a high level and can explain typical attack paths such as pass-the-hash or credential relays.
  • Working knowledge of Active Directory security – you can review group-policy and privilege assignments, map trust relationships, and identify exposures that weaken MFA deployments.
  • Familiarity with modern MFA standards – you’ve read specifications or lab-tested solutions that use WebAuthn / FIDO2 passkeys, smartcards, or one-time codes, and understand their basic threat models.
  • Comfort with scripting and PoC creation – you can write small PowerShell or Python snippets to automate reconnaissance, parsing logs, or demonstrating a finding.
  • Clear written and verbal communication – you translate technical findings into concise, well-structured reports and enjoy explaining risk and remediation steps to engineers and non-technical stakeholders.
  • Continuous learner mindset – you track new CVEs, read security blogs, and are eager to dig into fresh attack techniques or defensive best practices.
  • Team-oriented approach – you collaborate well in remote, cross-functional groups, ask questions when stuck, and give constructive feedback during peer reviews and debriefs.

Optional

  • Hands-on experience testing or administering Azure AD / Entra ID environments.
  • Practical exposure to hardware-backed factors (TPM, YubiKey, or Bluetooth LE proximity) in authentication flows.
  • Familiarity with red-team frameworks (e.g., MITRE ATT&CK) and basic threat-modeling methodologies.
  • Industry certifications such as CompTIA Security+, eJPT, OSCP, or CRTP—proof of commitment to offensive-security skills.
  • Previous participation in security communities (CTFs, local meet-ups, or published blog posts/papers).

Your responsibilities

  • Research next-generation MFA technologies: Investigate Windows / Windows Server, Active Directory (on-prem & Azure AD), and emerging passwordless standards such as WebAuthn / FIDO2 passkeys, identifying secure integration paths and potential attack surfaces.
  • Deep-dive into authentication protocols: Analyze Kerberos, NTLM, OAuth 2.0, and SAML flows to uncover weaknesses, propose hardening strategies, and validate cryptographic soundness.
  • Explore hardware-backed security options: Prototype the use of TPM 2.0, security keys (U2F / FIDO2), biometrics, and Bluetooth LE proximity for frictionless, phishing-resistant login experiences.
  • Document and communicate findings: Produce clear, risk-ranked reports with reproduction steps, proof-of-concepts, and actionable remediation guidance tailored for product engineering and customer success teams.
  • Track emerging threats and bypass techniques: Create internal advisories and threat-model updates that inform roadmap and defensive controls.
  • Support incident simulation and response: Lead red-team scenarios and post-test debriefs, helping stakeholders understand impact and prioritize fixes.

About the project

Join Rublon to work with a team of cybersecurity enthusiasts who are building the future of enterprise user authentication. Rublon is a multi-factor authentication platform used by hundreds of customers across the globe to protect employee logins to networks, servers and applications.
We are looking for a long-term employee who will support us in the following area: R&D on Multi-Factor Authentication Security.
Rublon’s research & development activities on Multi-Factor Authentication security will enable us to develop new solutions for passwordless multi-factor authentication. Your responsibilities will include conducting in-depth threat-modelling and cryptographic analysis of Rublon’s authentication flows, prototyping and validating next-generation passwordless methods such as WebAuthn/FIDO2 passkeys, and continuously monitoring emerging attack vectors to keep our MFA stack one step ahead of attackers. Working hand-in-hand with product and engineering teams, you’ll translate research insights into production-ready features and publish security findings that reinforce Rublon’s position as a trusted leader in enterprise identity protection.

This is how we organize our work

This is how we work

in houseyou focus on a single project at a timeyou have influence on the choice of tools and technologiesyou have influence on the technological solutions appliedyou have influence on the productyou focus on product development

Team members

15 people:backend developerfullstack developermobile developertechnical leaderarchitectdevOpscybersecurity specialistsupportproduct ownerUI designerUX designersystem analystIT administrator

This is how we work on a project

  • code review
  • architect / technical leader support
  • Continuous Deployment
  • Continuous Integration
  • DevOps
  • team-level deployment
  • documentation
  • issue tracking tools
  • functional tests
  • integration tests
  • pen tests
  • performance tests
  • test automation
  • testing environments
  • unit tests
  • manual tests

Steps After You Apply

  • You’ll be invited to an online meeting with our recruiter
  • Afterwards, we’ll ask you to do a small assignment, which will then be discussed with one of our technical leads
  • If everything goes well, we will make you an offer and invite you to a final interview
Company

What we offer

  • Work on mission-critical security challenges – your findings will directly shape Rublon’s next-generation MFA products and protect millions of users from account takeover.
  • Learn from and with high-performing peers – collaborate daily with experienced penetration testers, cryptographers, and software engineers who enjoy sharing knowledge and sharpening each other’s skills.
  • Impact without bureaucracy – small, expert teams ship improvements quickly; your recommendations move from report to remediation in weeks, not quarters.

Development opportunities we offer

  • industry-specific e-learning platforms
  • intracompany training
  • space for experimenting
  • substantive support from technological leaders
  • technical knowledge exchange within the company

Benefits

  • private medical care
  • remote work opportunities
  • flexible working time
  • integration events
  • no dress code
  • coffee / tea

Recruitment stages

  • 1.
    online meeting with our recruiter
  • 2.
    a small assignment
  • 3.
    an offer and invite you to a final interview

RUBLON sp. z o.o.

Rublon Services provides consulting, custom software development, and cloud services. Since 1993, we’ve helped market leaders unlock their potential by delivering digital innovation across the automotive, energy, and telecommunications sectors. Our teams advise clients on innovation and design, build, maintain, and support compliant enterprise software solutions.

This is how we work

Ethical Hacker / Pentester
13k–18k zł / mth. (CoE)
I apply to:
RUBLON sp. z o.o.
Zielona Góra, Lubusz
Pracodawca zbiera zgłoszenia przez swój system.
Przejdziesz na zewnętrzny formularz.

By clicking "Aplikuj" you confirm that you've read and accepted our Terms and Conditions.


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Need more information?

  • Make sure the body of the offer doesn’t already include what you’re looking for.
  • Ask a question if you need more information you’re interested in.
  • We’ll forward your question to the employer and aim to provide a response within 3 business days.

Share this offer