Overview
In this role you will lead and perform penetration testing across Klarna’s internal and public systems, integrating bug bounty insights into the security program. You’ll work on a fast-moving offensive security team, covering code, infrastructure, and third-party integrations in a Java/Node.js/AWS environment. You’ll translate findings into actionable remediation and help elevate security across cross-functional teams. This is a hands-on, problem-solving position with a strong impact on product safety and incident readiness.
Responsibilities
- Run white-box and black-box penetration tests on internal systems and public-facing apps
- Triage, investigate, and validate Bug Bounty submissions and external pentest findings
- Perform variant analysis to locate related vulnerabilities across code and infrastructure
- Assess security of third-party solutions and integrations
- Build tooling for reconnaissance, automation, and metrics collection
- Guide developers, product security, and SOC investigations with concrete remediation steps
- Lead demos, workshops, and training to spread offensive security practices
- Assess and contribute to maturing Klarna’s security program and tech stack security posture
Key requirements
- 5+ years of practical penetration testing and security assessments on production systems
- Proficient in reading code and finding vulnerabilities in Java and Node.js
- Experience with AWS and microservice architectures
- Clear, remediation-focused vulnerability reports with actionable steps
- Python scripting for tooling and automation
- Self-motivated with initiative to advance offensive security beyond tickets
- Strong communication and collaboration
- Proactive problem-solving mindset
- Ability to lead training and share knowledge across teams
- Penetration testing (white-box/black-box)
- Java and Node.js security
- AWS security and cloud native architectures
…
