Application Penetration Testing Manager
PwC · Prague, Czechia · 25d ago
Job Description & Summary
About the team
Join our Network Information Security (NIS) team and help clients address some of their most critical application and data protection challenges. As part of the Application Penetration Testing team, you will work on complex engagements across web, mobile, API, and cloud-native environments. We combine deep technical expertise with strong client advisory skills to help organizations understand and reduce real-world security risks. You will also contribute to innovation through automation and AI-enhanced security testing.
About your manager
You will work closely with senior cybersecurity leaders and experienced penetration testing professionals who support both technical excellence and career growth. The leadership team promotes knowledge sharing, mentoring, and continuous development while maintaining a collaborative and inclusive environment.
Job description & summary
PwC Professional skills and responsibilities for this management level include but are not limited to:
Lead multiple, concurrent application penetration testing engagements from planning to reporting, ensuring quality, timeliness, andinternalclient satisfaction.
Scope and design testing approaches for complex applications (web, mobile, APIs, microservices, cloud‑native), balancing risk coverage, effort, and client constraints.
Assist EMEA CISO/BISO teams on number of AppSecinitiativeswithinEMEA;
Apply advanced manual testing techniques (e.g.business logic abuse, multi‑step workflows, chained exploits[must have]) alongside targeted use of automated tools and AI‑assisted capabilities.
Review and challenge technical findings produced by theteam, ensuring accuracy, clear risk articulation, and practical remediation guidance for engineering audiences.
Translate technical results into business‑relevant impact for senior stakeholders (e.g.data exposure, fraud risk, compliance impact), and lead readouts with client security and product leadership.[ must have]
Coach and mentor junior and senior penetration testers, providing structured feedback, on‑the‑job training, and stretch opportunities to develop their tradecraft and consultingskills.[must have]
Use engagement reviews as an opportunity to systematically uplift team capability,standardizegood practices, and drive consistency in testing depth and reporting quality.
Contribute to service development by enhancing methodologies, checklists, and tooling approaches (including AI‑augmented testing workflows) and embedding them across the team.
Collaborate with account teams and leadership toidentifyfollow‑on or adjacent opportunities (e.g.secure SDLC, threat modelling, code review, developer training) based onidentifiedweaknesses.
Support shapingupservice-relatedchallenges on complextechnical approaches, effort estimates, and risk mitigations for application security assessments.
Foster a positive and inclusive team environment by effectively managing workloads, supporting work-life balance, anddemonstratingopen, respectful communication.
Use feedback and reflection to continuously refine your leadership, technical, and commercial skills, and uphold the firm’s code of ethics and business conduct.
What matters to us
Bachelor’s Degree (Computer and Information Science, Computer Applications, Computer Engineering, InformationCyberSecurity, Information Technology, Management InformationSystemsor equivalent experience.)
5+ years of experience in application security / penetration testing, including significant hands‑on testing and at least 1–2 years in a lead or supervisory role.
What will help you stand out
Demonstrates extensive knowledge and/or a proven record of success in the following areas:
In‑depth understanding of web applications, APIs, and services, including platforms and stacks such as IIS, Apache variants, Nginx, Java, .NET, Node.js, modern front‑end frameworks, and common API technologies (REST, SOAP,GraphQL).
Strong understanding of web and application security frameworks and guidance, including OWASP Top 10, OWASP API Top 10, OWASP MASVS, and SANS/CWE Top 25.
Proven ability toidentifyand exploit application vulnerabilities such as SQL injection, XSS, CSRF, SSTI, IDOR,authN/authZflaws, and logic issues, and todemonstraterealistic business impact.
Hands‑on use of industry‑standard testing tools (e.g.Burp Suite Pro, ZAP, proxy tools, interception frameworks) and familiarity with SAST/DAST/IAST and API security testing tools.
Solid understanding of application hosting environments: Windows and Linux web servers, application servers, databases, WAFs, load balancers, reverse proxies, and common cloud platforms (AWS, Azure, GCP).
Experience designing and executing tests for modern architectures (microservices, containers, serverless, CI/CD‑driven deployments) and integrating findings into secure SDLC practices.
Experience using or evaluating AI‑assisted techniques in security testing (e.g.AI‑aided recon, test idea generation, or report support) withappropriate validationand risk controls.
Required Professional Skills and Abilities
Demonstrates abilities and/or a proven record of success in the following areas:
Leading end‑to‑end application penetration testing engagements, including scoping, planning, execution oversight, issue escalation, and stakeholder communication.
Managing small to medium‑sized teams of testers, delegating effectively, and ensuring consistent test coverage and quality.
Reviewing and refining technical reports for clarity, accuracy, risk rating, and actionable remediation steps tailored to developers and architects.
Communicating complex technical concepts clearly and succinctly to both technical and non‑technical stakeholders, adapting depth and style asappropriate.
Building andmaintainingstrong client relationships,participatingactively in discussions, and positioning relevant add‑on services aligned to client needs.
Balancing project economics (budget, effort, and scope) whilemaintainingagreed quality standards and addressing unanticipated issues constructively.
Creating a positive team climate bymonitoringworkloads, providingtimelyfeedback, and supporting the growth and well‑being of team members.
Proactivelyseekingand incorporating guidance, clarification, and feedback from leadership, and keeping stakeholders informed of progress, risks, and issues.
Why you’ll love working here
Professional growththat matches your ambitions and pace. Gain in months the kind of experience that can take years to build elsewhere.
Fair paywith no gaps. We are among the few companies in the Czech Republic certified forEqual Pay.
A flexiblebenefits programmewith 55,000 pointsto spend on what matters most to you.
35 daysof paid time off, including three well-being days and twoadditionaldays off at the end of the year.
An opportunity to give back to the community withone paid volunteering dayevery year.
The chance to work from one ofPwC’s international offices(available from the Senior Associate level).
We support your learning and development journey:We offer training in business, soft, and digital skills (e.g. Alteryx, Power BI, and more), along with a wide range of additional courses and workshops designed to help you further develop your professional expertise and personal skills.
A buddyprogramme, regular feedback, and access to a coach who can support your professional development and career path.
Extensivewell-being supportand initiatives promoting a healthy lifestyle, from Dr. Digital and Human Dynamicprogrammesto workplace yoga and running events.
Anultrabookand an iPhone with unlimited data.
At PwC, we help clients solve today’s and tomorrow’s challenges across audit, consulting, tax, legal, technology, and data. We create an environment where people can learn, grow, and build a career in their own way. We believe the best results come from diverse experiences and perspectives. That’s why we foster an inclusive culture where everyone can be themselves, build on their strengths, and contribute to work that makes a real impact.
Interested in joining us? We’d love to hear from you and tell you more about this opportunity.
Ochrana osobních údajů pro žadatele o zaměstnání / Privacy Statement for Recruitment Applicants
#LI-PN