Join the team building an AI-first company 🚀 Hostinger serves more than 5.5 million clients across 150 countries, but we're still excited about what we're creating next. AI is changing how we build products, support customers, work together, and solve problems. It helps us move faster, spend less time on repetitive work, and focus on bigger ideas. If you want your work to influence both what we build and how we build it, we'd like to meet you. Our culture: Guided by 10 company principles.
🏢 About Hostinger
Hostinger serves more than 5.5 million clients across 150 countries, but we're still excited about what we're creating next. AI is changing how we build products, support customers, work together, and solve problems. It helps us move faster, spend less time on repetitive work, and focus on bigger ideas.
🎯 The Role
As an Offensive Cyber Security Engineer, you will help safeguard Hostinger’s infrastructure, applications, and customer data against evolving cyber threats. You'll think like an attacker across our hosting platform, customer control panel, APIs, cloud infrastructure, and the AI products we're shipping. You'll break things on purpose, prove the impact, and work with engineers until the fix is in production. You'll chain findings, write the exploit, and help engineers understand why it matters.
✅ Key Responsibilities
Run penetration tests and targeted attack simulations against web apps, APIs, and Linux-based hosting infrastructure.
Hunt for multi-tenant risks: privilege escalations, isolation breakouts, and account takeover paths that could affect many customers at once.
Triage and reproduce external vulnerability reports (responsible disclosure/bug bounty) and turn them into clear, prioritized fixes.
Automate repetitive tasks with custom tooling, recon pipelines, and regression checks, so the same bug isn't found twice.
Test new features before launch, including AI-powered products (prompt injection, data leakage, agent abuse), so security ships with the product instead of after it.
Write reports that engineers actually want to read, and share attacker-mindset knowledge through walkthroughs, internal CTFs, and code reviews.
📌 Required Qualifications
Knowledge in penetration testing, application security, or red teaming. Demonstrable CTF, HackTheBox, TryHackMe, or bug bounty experience also counts.
A grasp of web and API vulnerabilities (OWASP Top 10 and beyond).
Linux and networking fundamentals.
An ethical, curious mindset. You've broken something on your own time and learned from it.
Clear written English. A finding only counts if someone understands it and fixes it.
🎁 Benefits
360 Growth: Access to platforms like Reforge and CoachHub, global conferences, physical and digital libraries, feedback culture, and mentoring through TesoXchange.
Freedom & responsibility: Work from modern offices in Kaunas and Vilnius, home, or anywhere in the world with flexibility in managing your schedule.
Wellness simplified: Insurance from Day 1, gym memberships, recharge leave, Headspace subscriptions, and regular health checks.
Work hard – play hard: Company events like Summerfest & Winterfest, Town Hall, Meet the Client initiatives, team-buildings, and workations.
Compensation starts from €3600 gross/month, depending on your experience and skills.
🛂 Visa & Eligibility
No specific visa or eligibility information provided.
Please let Hostinger know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.