About the team Join our Network Information Security (NIS) team and help clients address some of their most critical application and data protection challenges. As part of the Application Penetration Testing team, you will work on complex engagements across web, mobile, API, and cloud-native environments. We combine deep technical expertise with strong client advisory skills to help organizations understand and reduce real-world security risks. You will also contribute to innovation through automation and AI-enhanced security testing. About your manager You will work closely with senior cybersecurity leaders and experienced penetration testing professionals who support both technical excellence and career growth. The leadership team promotes knowledge sharing, mentoring, and continuous development while maintaining a collaborative and inclusive environment. Job description & summary PwC Professional skills and responsibilities for this management level include but are not limited to: Lead multiple, concurrent application penetration testing engagements from planning to reporting, ensuring quality, timeliness, and internal client satisfaction. Scope and design testing approaches for complex applications (web, mobile, APIs, microservices, cloud‑native), balancing risk coverage, effort, and client constraints. Assist EMEA CISO/BISO teams on number of AppSec initiatives within EMEA; Apply advanced manual testing techniques ( e.g. business logic abuse, multi‑step workflows, chained exploits [must have] ) alongside targeted use of automated tools and AI‑assisted capabilities. Review and challenge technical findings produced by the team, ensuring accuracy, clear risk articulation, and practical remediation guidance for engineering audiences. Translate technical results into business‑relevant impact for senior stakeholders ( e.g. data exposure, fraud risk, compliance impact), and lead readouts with client security and product leadership. [ must have] Coach and mentor junior and senior penetration testers, providing structured feedback, on‑the‑job training, and stretch opportunities to develop their tradecraft and consulting skills. [ must have] U se engagement reviews as an opportunity to systematically uplift team capability, standardize good practices, and drive consistency in testing depth and reporting quality. Contribute to service development by enhancing methodologies, checklists, and tooling approaches (including AI‑augmented testing workflows) and embedding them across the team. Collaborate with account teams and leadership to identify follow‑on or adjacent opportunities ( e.g. secure SDLC, threat modelling, code review, developer training) based on identified weaknesses. S upport shaping up service-related challenges on complex technical approaches, effort estimates, and risk mitigations for application security assessments. Foster a positive and inclusive team environment by effectively managing workloads, supporting work-life balance, and demonstrating open, respectful communication. Use feedback and reflection to continuously refine your leadership, technical, and commercial skills, and uphold the firm’s code of ethics and business conduct. What matters to us Bachelor’s Degree ( Computer and Information Science, Computer Applications, Computer Engineering, Information CyberSecurity, Information Technology, Management Information Systems or equivalent experience.) 5+ years of experience in application security / penetration testing, including significant hands‑on testing and at least 1–2 years in a lead or supervisory role. What will help you stand out Demonstrates extensive knowledge and/or a proven record of success in the following areas: In‑depth understanding of web applications, APIs, and services, including platforms and stacks such as IIS, Apache variants, Nginx, Java,.NET, Node.js, modern front‑end frameworks, and common API technologies (REST, SOAP, GraphQL ). Strong understanding of web and application security frameworks and guidance, including OWASP Top 10, OWASP API Top 10, OWASP MASVS, and SANS/CWE Top 25. Proven ability to identify and exploit application vulnerabilities such as SQL injection, XSS, CSRF, SSTI, IDOR, authN / authZ flaws, and logic issues, and to demonstrate realistic business impact. Hands‑on use of industry‑standard testing tools ( e.g. Burp Suite Pro, ZAP, proxy tools, interception frameworks) and familiarity with SAST/DAST/IAST and API security testing tools. Solid understanding of application hosting environments: Windows and Linux web servers, application servers, databases, WAFs, load balancers, reverse proxies, and common cloud platforms (AWS, Azure, GCP). Experience designing and executing tests for modern architectures (microservices, containers, serverless, CI/CD‑driven deployments) and integrating findings into secure SDLC practices. Experience using or evaluating AI‑assisted techniques in security testing ( e.g. AI‑aided recon, test idea generation, or report support) with appropriate validation and risk controls. Experience designing and executing tests for modern architectures (microservices, containers, serverless, CI/CD‑driven deployments) and integrating findings into secure SDLC practices. Experience using or evaluating AI‑assisted techniques in security testing ( e.g. AI‑aided recon, test idea generation, or report support) with appropriate validation and risk controls. Required Professional Skills and Abilities Demonstrates abilities and/or a proven record of success in the following areas: Leading end‑to‑end application penetration testing engagements, including scoping, planning, execution oversight, issue escalation, and stakeholder communication. Managing small to medium‑sized teams of testers, delegating effectively, and ensuring consistent test coverage and quality. Reviewing and refining technical reports for clarity, accuracy, risk rating, and actionable remediation steps tailored to developers and architects. Communicating complex technical concepts clearly and succinctly to both technical and non‑technical stakeholders, adapting depth and style as appropriate. Building and maintaining strong client relationships, participating actively in discussions, and positioning relevant add‑on services aligned to client needs. Balancing project economics (budget, effort, and scope) while maintaining agreed quality standards and addressing unanticipated issues constructively. Creating a positive team climate by monitoring workloads, providing timely feedback, and supporting the growth and well‑being of team members. Proactively seeking and incorporating guidance, clarification, and feedback from leadership, and keeping stakeholders informed of progress, risks, and issues. Why you’ll love working here Professional growth that matches your ambitions and pace. Gain in months the kind of experience that can take years to build elsewhere. Fair pay with no gaps. We are among the few companies in the Czech Republic certified for Equal Pay. A flexible benefits programme with 5 5,000 points to spend on what matters most to you. 35 days of paid time off, including three well-being days and two additional days off at the end of the year. An opportunity to give back to the community with one paid volunteering day every year. The chance to work from one of PwC’s international offices (available from the Senior Associate level). We support your learning and development journey: We offer training in business, soft, and digital skills (e.g. Alteryx, Power BI, and more), along with a wide range of additional courses and workshops designed to help you further develop your professional expertise and personal skills. A buddy programme, regular feedback, and access to a coach who can support your professional development and career path. Extensive well‑being support and initiatives promoting a healthy lifestyle, from Dr. Digital and Human Dynamic programmes to workplace yoga and running events. An ultrabook…
Manažer pro penetrační testování aplikací
PricewaterhouseCoopers Česká republika, s.r.o. · Poradenství
Shrnutí
Tato pozice zahrnuje vedení zakázek penetračního testování aplikací, vymezování a navrhování testovacích přístupů pro komplexní aplikace a mentorování juniorních testerů. Pozice vyžaduje revizi technických zjištění, překlad výsledků do obchodního dopadu pro vyšší management a přispívání k rozvoji služeb.
Klíčové údaje
- Stav
- Dostupná
- Lokalita
- Praha
- Typ smlouvy
- Plný úvazek
- Úroveň
- Vedoucí
- Zkušenosti
- 5+ let
- Vzdělání
- Bakalářské
- Datum nástupu
- Okamžitě
- Benefity
- Spravedlivé odměňování bez mezer · flexibilní program benefitů s 55 000 body · 35 dní placené dovolené · tři dny pro pohodu · dva dny volna navíc na konci roku · jeden placený den dobrovolnictví ročně · možnost pracovat z některé z mezinárodních poboček PwC · školení v oblasti obchodních, měkkých a digitálních dovedností · široká škála dalších kurzů a workshopů · buddy program · pravidelná zpětná vazba · přístup ke kouči · rozsáhlá podpora well-beingu a iniciativy · programy Dr. Digital a Human Dynamic · jóga na pracovišti a běžecké akce · ultrabook
Požadované dovednosti
webové aplikaceAPImikroslužbycloud-nativeOWASP Top 10OWASP API Top 10Burp Suite ProZAP
