A
Ethical Hacker
Aisle
Prague
Full-Time
Description
- Execute continuous security assessments and deep-dive penetration tests across our entire product suite and internal infrastructure.
- Proactively hunt for threats and architectural weaknesses that automated scanners might miss, ensuring our defenses stay ahead of evolving attack vectors.
- Collaborate with engineering teams to provide "remediation-ready" guidance, helping them squash bugs and implement secure coding patterns.
- Design and run Red Team exercises to test our detection and response capabilities, providing a feedback loop for our Blue Team operations.
- Advocate for a "security-first" culture by conducting internal workshops and helping developers understand how to think like an attacker.
- Help build the foundation of our offensive security program, influencing the tools, methodologies, and long-term security roadmap at Aisle.
Eligibility Criteria
- 5+ years of experience in offensive security, penetration testing, or red teaming, ideally within high-growth B2B SaaS or cloud-native ecosystems.
- Deep technical proficiency in identifying vulnerabilities across web applications, APIs, and cloud infrastructure (AWS, GCP, or Azure).
- Mastery of the attacker mindset; you should be an expert with industry-standard tools (Burp Suite, Metasploit, Kali Linux, etc.) but also capable of writing custom scripts to automate exploits.
- Strong understanding of modern architecture, including containerization (Kubernetes/Docker), CI/CD pipelines, and OAuth/SAML identity flows.
- Excellent communication skills, specifically the ability to translate complex technical exploits into actionable risk assessments for non-security stakeholders.
- Bonus points for recognized certifications (OSCP, OSCE, GPEN), a history of responsible bug bounty disclosures, or active participation in the CTF community.
About Aisle
-
