Terra Security provides agentic AI-powered continuous penetration testing aligned to code changes and evolving attack surfaces, combining a swarm of trained AI agents with human supervision for safety and control. Fortune 500 organizations trust Terra to ensure every attack surface is covered across the web, AI, internal apps, APIs, mobile, networks, and the cloud.
Terra is on track to become the next breakout cybersecurity company with $38 million raised to date, including a $30 million Series A led by Felicis Ventures with participation from Dell Technologies Capital, Silicon Valley CISO Investments (SVCI), SYN Ventures, LAMA Partners, Underscore VC, and Capital One Ventures.
Summary
As a Junior Attack Surface Analyst, you will analyze customer web applications and build accurate attack surface models that power Terra’s automated security testing platform. You will study authentication flows, APIs, navigation structure, and role-based access across diverse applications, combining automated discovery with hands-on security analysis to ensure complete surface coverage before assessments begin. This is an internal delivery role based in Poland, ideal for someone with solid web fundamentals who wants to grow into application security and penetration testing.
What You’ll Do
- Perform structured attack surface discovery - identifying endpoints, pages, API routes, and interactive functionality across authenticated and unauthenticated contexts.
- Analyze authentication flows, session handling, and role-based access to ensure testing covers the full permission model.
- Validate automated discovery output and apply reconnaissance methodology to achieve complete surface coverage.
- Document security context for each application: auth prerequisites, critical business workflows, API behavior, navigation structure, and scope constraints.
- Analyze API specifications (OpenAPI/Swagger) and traffic patterns to enrich endpoint models and parameter understanding.
- Confirm application testing readiness - verifying asset models, domain scope, and credentials before assessments are launched.
- Identify recurring architectural patterns (SPA behavior, custom auth, WAF interactions) and contribute insights that improve Terra’s discovery automation.
Requirements
- 0–2 years of hands-on experience in web technologies, IT, or application security or equivalent self-driven learning through projects, bootcamps, or CTFs.
- Strong understanding of how web applications work: HTTP methods, status codes, cookies, sessions, headers, and REST API fundamentals.
- Solid knowledge of common authentication patterns form-based login, bearer tokens, session management, and role-based access.
- Practical expertise with browser developer tools and an interest in proxy-based security analysis (Burp Suite, OWASP ZAP, or similar).
- Exceptional attention to detail and methodical approach to analyzing complex application architectures.
- High-level English proficiency fluent in reading, writing, and speaking.
Advantage
- Familiarity with OpenAPI/Swagger specifications and API documentation.
- Awareness of OWASP Top 10 vulnerability classes and basic offensive security concepts.
- Experience with single-page applications (SPAs), GraphQL, or multi-tenant SaaS architectures.
- Security-related degree, bootcamp completion, CTF participation, or personal AppSec projects.
- Genuine motivation to build a career in penetration testing and offensive application security.
Please note that this position is for candidates based in Poland and is offered as an Independent Contractor (B2B) engagement.