Application Penetration Testing Manager
- PwC
- Prague, Czechia
- CZK 1,000,000 – CZK 1,500,000
Job Description & Summary
About the team
Join our Network Information Security (NIS) team and help clients address some of their most critical application and data protection challenges. As part of the Application Penetration Testing team, you will work on complex engagements across web, mobile, API, and cloud-native environments. We combine deep technical expertise with strong client advisory skills to help organizations understand and reduce real-world security risks. You will also contribute to innovation through automation and AI-enhanced security testing.
About your manager
You will work closely with senior cybersecurity leaders and experienced penetration testing professionals who support both technical excellence and career growth. The leadership team promotes knowledge sharing, mentoring, and continuous development while maintaining a collaborative and inclusive environment.
Job description & summary
PwC Professional skills and responsibilities for this management level include but are not limited to:
Lead multiple, concurrent application penetration testing engagements from planning to reporting, ensuring quality, timeliness, and internal client satisfaction.
Scope and design testing approaches for complex applications (web, mobile, APIs, microservices, cloud‑native), balancing risk coverage, effort, and client constraints.
Assist EMEA CISO/BISO teams on number of AppSec initiatives within EMEA ;
Apply advanced manual testing techniques (e.g. business logic abuse, multi‑step workflows, chained exploits [must have]) alongside targeted use of automated tools and AI‑assisted capabilities.
Review and challenge technical findings produced by the team, ensuring accuracy, clear risk articulation, and practical remediation guidance for engineering audiences.
Translate technical results into business‑relevant impact for senior stakeholders (e.g. data exposure, fraud risk, compliance impact), and lead readouts with client security and product leadership. [ must have]
Coach and mentor junior and senior penetration testers, providing structured feedback, on‑the‑job training, and stretch opportunities to develop their tradecraft and consulting skills. [must have]
Use engagement reviews as an opportunity to systematically uplift team capability, standardize good practices, and drive consistency in testing depth and reporting quality.
Contribute to service development by enhancing methodologies, checklists, and tooling approaches (including AI‑augmented testing workflows) and embedding them across the team.
Collaborate with account teams and leadership to identify follow‑on or adjacent opportunities (e.g. secure SDLC, threat modelling, code review, developer training) based on identified weaknesses.
Support shaping up service-related challenges on complex technical approaches, effort estimates, and risk mitigations for application security assessments.
Foster a positive and inclusive team environment by effectively managing workloads, supporting work-life balance, and demonstrating open, respectful communication.
Use feedback and reflection to continuously refine your leadership, technical, and commercial skills, and uphold the firm’s code of ethics and business conduct.
What matters to us
- Bachelor’s Degree (Computer and Information Science, Computer Applications, Computer Engineering, Information CyberSecurity, Information Technology, Management Information Systems or equivalent experience.)
- 5+ years of experience in application security / penetration testing, including significant hands‑on testing and at least 1–2 years in a lead or supervisory role. [Good to have]
What will help you stand out
Demonstrates extensive knowledge and/or a proven record of success in the following areas:
In‑depth understanding of web applications, APIs, and services, including platforms and stacks such as IIS, Apache variants, Nginx, Java, .NET, Node.js, modern front‑end frameworks, and common API technologies (REST, SOAP, GraphQL). [must have]
Strong understanding of web and application security frameworks and guidance, including OWASP Top 10, OWASP API Top 10, OWASP MASVS, and SANS/CWE Top 25. [must have]
Proven ability to identify and exploit application vulnerabilities such as SQL injection, XSS, CSRF, SSTI, IDOR, authN/authZ flaws, and logic issues, and to demonstrate realistic business impact. [must have]
Hands‑on use of industry‑standard testing tools (e.g. Burp Suite Pro, ZAP, proxy tools, interception frameworks) and familiarity with SAST/DAST/IAST and API security testing tools. [must have]
Solid understanding of application hosting environments: Windows and Linux web servers, application servers, databases, WAFs, load balancers, reverse proxies, and common cloud platforms (AWS, Azure, GCP). - [Good to have]
Experience designing and executing tests for modern architectures (microservices, containers, serverless, CI/CD‑driven deployments) and integrating findings into secure SDLC practices. [Good to have]
Experience using or evaluating AI‑assisted techniques in security testing (e.g. AI‑aided recon, test idea generation, or report support) with appropriate validation and risk controls. [Good to have]
Required Professional Skills and Abilities
Demonstrates abilities and/or a proven record of success in the following areas:
Leading end‑to‑end application penetration testing engagements, including scoping, planning, execution oversight, issue escalation, and stakeholder communication.
Managing small to medium‑sized teams of testers, delegating effectively, and ensuring consistent test coverage and quality.
Reviewing and refining technical reports for clarity, accuracy, risk rating, and actionable remediation steps tailored to developers and architects.
Communicating complex technical concepts clearly and succinctly to both technical and non‑technical stakeholders, adapting depth and style as appropriate.
Building and maintaining strong client relationships, participating actively in discussions, and positioning relevant add‑on services aligned to client needs.
Balancing project economics (budget, effort, and scope) while maintaining agreed quality standards and addressing unanticipated issues constructively.
Creating a positive team climate by monitoring workloads, providing timely feedback, and supporting the growth and well‑being of team members.
Proactively seeking and incorporating guidance, clarification, and feedback from leadership, and keeping stakeholders informed of progress, risks, and issues.
Why you’ll love working here
- Professional growth that matches your ambitions and pace. Gain in months the kind of experience that can take years to build elsewhere.
- Fair pay with no gaps. We are among the few companies in the Czech Republic certified for Equal Pay.
- A flexible benefits programme with 55,000 points to spend on what matters most to you.
- 35 days of paid time off, including three well-being days and two additional days off at the end of the year.
- An opportunity to give back to the community with one paid volunteering day every year.
- The chance to work from one of PwC’s international offices (available from the Senior Associate level).
- We support your learning and development journey: We offer a wide range of professional and personal development opportunities, including training focused on business, soft, and digital skills (e.g. Alteryx, Power BI). You'll get access to educational programs, such as our internal Tax Academy, accounting and tax workshops, and support preparing for the Czech Tax Advisor Exam, including a financial bonus upon successful completion. And it doesn’t stop there. We provide many other learning and development opportunities to help you grow both professionally and personally.
- A buddy programme, regular feedback, and access to a coach who can support your professional development and career path.
- Extensive well-being support and initiatives promoting a healthy lifestyle, from Dr. Digital and Human Dynamic programmes to workplace yoga and running events.
- An ultrabook and an iPhone with unlimited data.
- Social events: https://www.pwc.com/cz/cs/kariera/proc-pwc.html and Away Days: https://www.instagram.com/s/aGlnaGxpZ2h0OjE4MDc3NDkwMjgxNDg4NTU1.
At PwC, we help clients solve today’s and tomorrow’s challenges across audit, consulting, tax, legal, technology, and data. We create an environment where people can learn, grow, and build a career in their own way. We believe the best results come from diverse experiences and perspectives. That’s why we foster an inclusive culture where everyone can be themselves, build on their strengths, and contribute to work that makes a real impact.
Interested in joining us? We’d love to hear from you and tell you more about this opportunity.
Ochrana osobních údajů pro žadatele o zaměstnání / Privacy Statement for Recruitment Applicants
#LI-PN
Skills
- Penetration Testing
- Application Security
- OWASP
- Burp Suite
- API Security
- Cloud Security
- Security Automation







