
HiQ · Stockholm
At HiQ, every challenge is an invitation to explore new possibilities. We’re looking for someone who thrives on the thrill of discovery, who sees every system a...
At HiQ, every challenge is an invitation to explore new possibilities. We’re looking for someone who thrives on the thrill of
discovery, who sees every system as a puzzle waiting to be solved, and who finds energy in the pursuit of safer, smarter digital
solutions.
As part of our Pentest team, you’ll be at the heart of our mission to build secure applications and environments for some of the
most exciting organizations in the Nordics. Your days will be filled with hands-on penetration testing, creative problem-solving,
and the freedom to dive deep into the latest tools and techniques. Whether you’re orchestrating a Red Team engagement or probing
the intricacies of cloud security, you’ll have the autonomy to shape your own approach, while always knowing that a team of
passionate experts has your back.
You’ll work with Burp Suite, Nmap, Wireshark, and a host of other tools, sometimes in the cloud, sometimes on-prem, always at the
cutting edge. Your experience with Active Directory and scripting will come to life as you navigate complex environments, uncover
vulnerabilities, and help our clients see their systems through a new lens. If you’ve cracked hashes, explored mobile app
security, or sharpened your skills in CTFs, you’ll find plenty of opportunities to push your expertise even further.
Here, learning is woven into the fabric of every project. Whether you’re pursuing new certifications, experimenting with the
latest exploits, or sharing insights with colleagues, you’ll find endless room to grow. We celebrate curiosity and initiative, if
you spot an opportunity to make something better, you’ll have the freedom and support to make it happen.
You’ll be trusted to run penetration tests independently, but you’ll never be alone. Collaboration is second nature here: ideas
bounce, knowledge flows, and everyone’s voice matters. You’ll document your findings with clarity, communicate risks with empathy,
and help guide clients toward stronger, more resilient solutions.
If you’re ready to join a team where your passion for security is matched only by your drive to learn and create, we’d love to
meet you.
Ready to take the next step? Apply now and let’s build something extraordinary together.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We invite a Senior Penetration Tester to join our team. Main Responsibilities: ✔️ Lead end-to-end penetration testing engagements across web applications, APIs, mobile, internal and external networks and cloud (primarily AWS). ✔️ Run red-team and assumed-breach operations - initial access, privilege escalation, lateral movement, persistence, exfiltration - including against fraud and detection stacks. ✔️ Perform security reviews of cloud-native services, Kubernetes workloads, CI/CD pipelines, and microservices. ✔️ Discover and exploit vulnerabilities across real-money flows - payments, deposits and withdrawals, wallets, KYC / AML, bonus systems, and affiliate tracking. ✔️ Partner with product, engineering, AppSec, payments, and fraud teams to translate findings into concrete fixes and durable controls. ✔️ Develop custom tooling, scripts, and methodology where no out-of-the-box approach exists. ✔️ Build and validate declarative threat models and contribute to "secure by design" practice. ✔️ Mentor mid and junior testers, review their engagement plans and reports. ✔️ Track new CVEs, TTPs, MITRE ATT&CK updates, and regulator advisories - translate them into concrete changes here. ✔️ Support pre-sales scoping, effort estimation, and pre-certification engagements for new products and jurisdictions. ✔️ Serve as a trusted offensive-security advisor to product, engineering, and compliance teams. Role Requirements: ✔️ Minimum 4 years of hands-on penetration testing or offensive-security experience. ✔️ Proven track record across at least three of: web / API, internal, external network, cloud (AWS / GCP), mobile (iOS / Android). ✔️ OSCP or an equivalent in-the-box certification. ✔️ Strong working knowledge of SAST/SCA/DAST tooling, AWS/GCP, MITRE ATT&CK, OWASP ASVS / WSTG, PTES. ✔️ Understanding of the data flow, MVC model. ✔️ Understanding of supply chain attacks. ✔️ Good reporting skills. ✔️ Comfortable scripting in Python plus Bash. ✔️ Knowledge at least one of major cloud provider's IAM model. ✔️ Experience pentesting cloud-native systems and Kubernetes environments, plus the CI/CD pipelines around them (GitLab, GitHub Actions, Jenkins) and IaC (Terraform, Helm, CloudFormation). ✔️ Strong written and verbal communication in English. ✔️ Experience balancing security and business demands under release pressure. ✔️ Familiarity with industry regulations, frameworks, and practices: PCI DSS, ISO 27001, NIST, GDPR. PREFERRED QUALIFICATIONS: ✔️ One of offensive-security certifications: OSWE, OSEP, OSED, CRTO, BSCP, ARTE, GRTE. ✔️ In-depth experience architecting secure services on Kubernetes and AWS. ✔️ Prior iGaming, fintech, or payments domain experience. ✔️ Public CVEs, advisories, write-ups, conference talks. ✔️ HTB Pro Lab completions, real CTF placements. ✔️ Open-source contributions to offensive or defensive tooling. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.
We are looking for a Senior Penetration Tester with CHECK to join our growing team. You will play a critical role in delivering high-quality penetration testing engagements across infrastructure, cloud, web, and mobile applications for a diverse range of clients, including software, fintech, manufacturing, engineering, legal, and public sector organisations. This is a hands-on role where your expertise will help identify and remediate security weaknesses, while contributing to the development of our methodologies and mentoring junior testers. If you’re passionate about offensive security and want to work on varied, challenging projects in a supportive environment, we’d love to hear from you. Essential Skills * CHECK Team Member (CTM) status * Current UK Security Clearance. * At least 2+ years of penetration testing experience. * Strong experience with web application and network penetration testing methodologies. * In-depth knowledge of operating systems (Linux, Windows, Active Directory). * Familiarity with cloud environments and ability to perform cloud security reviews. * Proficiency with tools such as BurpSuite Pro, Nmap, Nessus, and Kali Linux. * Knowledge of scripting languages (Python, Shell, etc.). Nice-to-Have * CHECK Team Lead (CTL) status (Infrastructure or Applications). * Relevant certifications (OSCP, Cyber Scheme). * Experience with Hack the Box or Capture the Flag simulations. Why Join Instil? At Instil, we believe great work starts with happy, motivated people. That’s why we’ve built a benefits package that supports your wellbeing, growth, and life outside of work, because when you thrive, so do we. * Recognition That Matters: A discretionary annual performance bonus that rewards your impact and contribution to our success. * Flexibility Built In: Flexible working arrangements and summer hours, because life isn’t 9 to 5, and balance matters. * Financial Security: A highly competitive pension scheme with generous employer contributions, private healthcare, and life assurance for peace of mind. * Health & Wellbeing: Employee Assistance Programme, mental health support, cycle-to-work scheme, and regular social events to keep our culture vibrant. * Time to Recharge: 35 days holiday, enhanced maternity pay, and family-first policies so you can focus on what matters most. * Learning Never Stops: From courses to certifications, we’ll invest in your development so you can keep growing and shaping what’s next. * Community & Culture: Opportunities to volunteer, give back, and be part of initiatives that make Instil a truly inclusive and connected workplace. And that’s just the start, drop us a note to find out more. Company Description Instil has been delivering world-class software engineering and technology solutions for over 20 years, trusted by global brands to solve complex challenges and drive innovation. From modernising legacy systems to building cutting-edge applications, we help our clients navigate an ever-changing digital landscape with confidence and agility. We’re proud to be an award-winning employer, reflecting how our people are at the heart of everything we do: * Recognised as a Great Place to Work® for three consecutive years, and in 2024 ranked in the Top 20 Best Workplaces in the UK for medium-sized companies. * Winner of Company of the Year at the Digital DNA Awards 2022, celebrating excellence in Northern Ireland’s tech sector. Driven by a love for technology and a commitment to excellence, we bring together people who want to make a difference. We’ll support your journey, because your success is part of ours. #LI-PR1 #InstilCareers
At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don’t just use tools; you possess an innate curiosity, treating AI as a high-trust collaborator that is core to how you solve problems and accelerate your impact. We look for low-ego individuals who thrive in dynamic and fast-moving environments and move with an experimental mindset — who rapidly test emerging capabilities to discover simpler, more powerful ways to deliver results. At Snowflake, your role isn't just to execute a function, but to help redefine the future of how work gets done. There is only one Data Cloud. Snowflake’s founders started from scratch and designed a data platform built for the cloud that is effective, affordable, and accessible to all data users. But it didn’t stop there. They engineered Snowflake to power the Data Cloud, where thousands of organizations unlock the value of their data with near-unlimited scale, concurrency, and performance. This is our vision: a world with endless insights to tackle the challenges and opportunities of today and reveal the possibilities of tomorrow. Snowflake started with a clear vision: develop a cloud data platform that is effective, affordable, and accessible to all data users. Snowflake developed an innovative new product with a built-for-the-cloud architecture that combines the power of data warehousing, the flexibility of big data platforms, and the elasticity of the cloud at a fraction of the cost of traditional solutions. We are now a global, world-class organization with offices in more than a dozen countries and serving many more. WHAT YOU NEED: * You break things, and you want to break them anywhere, in any cloud - and you have solid 5+ years of experience doing that. * You find and exploit bugs in: * Java, typescript, JavaScript, Go, Python or C++ * Kubernetes, AWS, Azure or GCP * Cloud Native Systems and Applications, AI Agents and Agentic workloads, Client Side Applications, Micro Services, Database Systems, Drivers, Connectors, Web Applications, and more * You will have a solid understanding of technologies supporting applications and systems to accurately assess the breadth and impact of risks and solutions. * You are not overly reliant on tools and can use your fundamental understanding of technologies to develop new attack methods. * You are a strong communicator, with a track record of delivering results, who wants to work closely with developers and security engineers on a daily basis. * You have prior experience balancing security and business demands as you perform penetration testing for products going to release. WHAT YOU WILL DO: * Perform penetration testing engagements against a diverse cloud environment and find vulnerabilities in software, systems, and networks. * Set scope, priority based test plans, and timelines for penetration testing engagements. * You will figure out how to test new applications, technologies, protocols, controls, and concepts where there is no out-of-the-box methodology. * Work with security and engineering teams to manage product releases, plan engagements, communicate findings and recommendations, and inform stakeholders. * Partner closely with security engineers in the Product Security program to drive reviews, designs, and controls from outcomes. * Focus primarily on penetration testing, but advocate for and support other processes in the SDLC as needed. * Develop automated security testing tools and security automation frameworks to enhance scalability and eliminate recurring vulnerabilities. WHY YOU SHOULD WORK WITH US: * We are laser focused on doing security better, and we do not tolerate the status quo. * Snowflake is constantly innovating, if you want to further yourself technically there is no better place to be exposed to a wide variety of new technologies. * Snowflake AppSec program is very innovative - think about Threat Modeling as Code, autonomous security champions and agentic driven security. * We have strong demand from our customers, and support from the business for security. * We are a great team that combines a diverse set of backgrounds and skills. * Did we mention we are one of the fastest-growing software companies, ever? The opportunity for impact is enormous. Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake. How do you want to make your impact? Snowflake is growing fast, and we’re scaling our team to help enable and accelerate our growth. We are looking for people who share our values, challenge ordinary thinking, and push the pace of innovation while building a future for themselves and Snowflake. How do you want to make your impact? For jobs located in the United States, please visit the job posting on the Snowflake Careers Site for salary and benefits information: careers.snowflake.com