Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Klarna is building an everyday finance network that helps over 120 million consumers across 26 countries save time and money and worry less about their finances.
задачи
Run white-box and black-box penetration tests against internal systems and public-facing applications;
Manage, triage, and investigate Bug Bounty submissions and external pentest findings;
Perform variant analysis on issues surfaced through any channel and trace where else the same class of bug might exist;
Research and assess the security of Klarna's third-party solutions and integrations;
Build tooling for reconnaissance, automation, and metrics collection;
Guide developers, product security teams, and SOC investigations with hands-on expertise;
Run demos, workshops, and training to spread offensive security practices across Klarna;
Assess the security of Klarna's tech stack and help mature the security program overall.
требования
5+ Years of experience running penetration tests and technical security assessments against production systems;
Ability to read code and find real vulnerabilities, particularly in Java and Node.js;
Experience operating in AWS and reviewing microservice architectures for security gaps;
Ability to document findings clearly with concrete remediation steps;
Ability to script tooling in Python rather than relying only on off-the-shelf scanners;
Ability to independently advance offensive security initiatives;
Nice to have: OSCP, OSWE, CREST, GIAC, or AWS security certification; active participation in CTFs or the broader security research community; public security research such as CVEs, conference talks, or published tooling.
условия
The position is based in Klarna's Milan office; most teams currently meet in person 2–3 days per week, and this varies by team and can change over time;
Final compensation will be based on the candidate's qualifications, skills, and experience.