368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$32k – $82k per year (Estimated)
Location
Remote (Poland)
Seniority
Junior
Employment
Full-Time
Overview
Company
Impact
Profile match
Terra Security runs agentic penetration testing that adapts to each customer's application instead of following a fixed script. Founded in 2024 in Tel Aviv, it keeps a human expert in the loop to validate what the agents find. The company targets continuous offensive testing for web-facing enterprise systems.

Description

Terra Security provides agentic AI-powered continuous penetration testing aligned to code changes and evolving attack surfaces, combining a swarm of trained AI agents with human supervision for safety and control. Fortune 500 organizations trust Terra to ensure every attack surface is covered across the web, AI, internal apps, APIs, mobile, networks, and the cloud.

Terra is on track to become the next breakout cybersecurity company with $38 million raised to date, including a $30 million Series A led by Felicis Ventures with participation from Dell Technologies Capital, Silicon Valley CISO Investments (SVCI), SYN Ventures, LAMA Partners, Underscore VC, and Capital One Ventures.

Summary

As a Junior Attack Surface Analyst, you will analyze customer web applications and build accurate attack surface models that power Terra’s automated security testing platform. You will study authentication flows, APIs, navigation structure, and role-based access across diverse applications, combining automated discovery with hands-on security analysis to ensure complete surface coverage before assessments begin. This is an internal delivery role based in Poland, ideal for someone with solid web fundamentals who wants to grow into application security and penetration testing.

What You’ll Do

  • Perform structured attack surface discovery - identifying endpoints, pages, API routes, and interactive functionality across authenticated and unauthenticated contexts.
  • Analyze authentication flows, session handling, and role-based access to ensure testing covers the full permission model.
  • Validate automated discovery output and apply reconnaissance methodology to achieve complete surface coverage.
  • Document security context for each application: auth prerequisites, critical business workflows, API behavior, navigation structure, and scope constraints.
  • Analyze API specifications (OpenAPI/Swagger) and traffic patterns to enrich endpoint models and parameter understanding.
  • Confirm application testing readiness - verifying asset models, domain scope, and credentials before assessments are launched.
  • Identify recurring architectural patterns (SPA behavior, custom auth, WAF interactions) and contribute insights that improve Terra’s discovery automation.

Requirements

  • 0-2 years of hands-on experience in web technologies, IT, or application security or equivalent self-driven learning through projects, bootcamps, or CTFs.
  • Strong understanding of how web applications work: HTTP methods, status codes, cookies, sessions, headers, and REST API fundamentals.
  • Solid knowledge of common authentication patterns form-based login, bearer tokens, session management, and role-based access.
  • Practical expertise with browser developer tools and an interest in proxy-based security analysis (Burp Suite, OWASP ZAP, or similar).
  • Exceptional attention to detail and methodical approach to analyzing complex application architectures.
  • High-level English proficiency fluent in reading, writing, and speaking.

Advantage

  • Familiarity with OpenAPI/Swagger specifications and API documentation.
  • Awareness of OWASP Top 10 vulnerability classes and basic offensive security concepts.
  • Experience with single-page applications (SPAs), GraphQL, or multi-tenant SaaS architectures.
  • Security-related degree, bootcamp completion, CTF participation, or personal AppSec projects.
  • Genuine motivation to build a career in penetration testing and offensive application security.

Please note that this position is for candidates based in Poland and is offered as an Independent Contractor (B2B) engagement.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$94k – $115k per year • Remote • Full-Time • 5+ years exp
JavaScript
TypeScript
Frontend
GraphQL
React.js
Mobile
React Native
State Management
DevOps
CI/CD
Apply
$98k – $195k per year (Estimated) • In office • Full-Time • 7+ years exp • Wellington
Java
Python
SQL
Java
Spring Boot
Databases
Apache Kafka
Databricks
Neo4j
AI/ML
Flink
Spark
Frontend
GraphQL
DevOps
Azure
CI/CD
Datadog
Dynatrace
Kibana
Kubernetes
OpenShift
Platform Engineering
Splunk
Amazon ECS
Apply
$42k – $107k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Mexico City
C#
Go
Java
Rust
AI/ML
AI Agents
LLM
Model Context Protocol
Cybersecurity
Delinea
Zero Trust
Apply
$118k – $258k per year (Estimated) • In office • Full-Time • 5+ years exp • Munich
Python
AI/ML
AI Agents
LLM
Apply
AI Engineer 1 day ago
$80k – $120k per year • In office • Full-Time • 5+ years exp • Stockholm
AI/ML
AI Agents
LLM
Apply
Product Designer 12 days ago
$58k – $178k per year (Estimated) • In office • 3+ years exp • Tel Aviv
JavaScript
AI/ML
AI Agents
Human-in-the-Loop
Frontend
React.js
Tailwind CSS
Cybersecurity
CVSS
Design
Figma
Apply
Penetration Tester 21 day ago
$43k – $90k per year (Estimated) • Remote • Full-Time • 3+ years exp
Python
AI/ML
AI Agents
Edge AI
Human-in-the-Loop
DevOps
AWS
Azure
GCP
Cybersecurity
Burp Suite
Caido
OWASP Top 10
Apply
Security Researcher 1 month ago
$103k – $234k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Tel Aviv
Python
AI/ML
AI Agents
Red Teaming
Apply
$64k – $116k per year (Estimated) • Remote • Full-Time • 5+ years exp
Python
AI/ML
AI Agents
Human-in-the-Loop
Cybersecurity
Burp Suite
Caido
OWASP Top 10
Apply
$84k – $237k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • Tel Aviv
Node JS
TypeScript
JavaScript
AI/ML
AI Agents
Frontend
React.js
DevOps
AWS
Docker
GCP
Kubernetes
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.