Penetration Tester – Offensive Security, Red Team

🕒 July 27

🇧🇷 Brazil – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔧 QA Engineer (Quality Assurance)

👻 Ghost score 11%

infoinfo

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Saipos | Sistema para Restaurante

Saipos | Sistema para Restaurante

51 - 200 employees

Founded 2017

🍽️ Food & Beverage

📦 Logistics

💼 Consulting

Food & Beverage • Logistics • Consulting

Saipos is a comprehensive restaurant management system that offers solutions for various types of food establishments, including delivery services, pizzerias, sushi bars, and franchises. With features like digital menus, automated delivery routing, and financial control, Saipos aims to enhance operational efficiency and improve customer service for its users. The software integrates with major delivery apps and is designed to streamline business processes within the food service industry, making it an ideal choice for over 10,000 restaurants looking to optimize their management practices.

📋 Description

• Plan and execute intrusion/penetration tests autonomously within a defined scope: web applications, APIs, cloud infrastructure, and internal networks. • Build and maintain an internal continuous pentest program — cadence, rotating scope, and prioritization based on business risk. • Produce high-quality technical and executive reports, including severity, business impact, and actionable recommendations. • Validate and further investigate findings from external pentest vendors, cloud posture tools, and internal scans. • Conduct security assessments of critical integrations and authentication flows before and after remediation. • Perform security testing on mobile applications and installers — mapping attack surfaces that automated tools do not cover. • Execute social engineering and targeted phishing exercises, contributing to the awareness program and security culture. • Track the remediation lifecycle — verifying the effectiveness of implemented fixes through structured retests.

🎯 Requirements

• Strong experience in penetration testing of web applications and APIs: OWASP Top 10, OWASP API Security Top 10, business logic, and authentication/authorization flows. • Hands-on knowledge of security in AWS cloud environments: IAM privilege escalation, S3 misconfigurations, Lambda, assumable roles, and policy analysis. • Proficiency with pentest tools: Burp Suite Pro, Metasploit, Nmap, Nuclei, and cloud enumeration tools such as Pacu and ScoutSuite. • Ability to write PoCs and custom exploit scripts when available tools do not cover the scenario. • Experience testing mobile applications and thick clients, including analysis of communications, local storage, and client-side attack surfaces. • Knowledge of social engineering techniques and ability to structure targeted phishing simulations with clear scope criteria and metrics. • Production of high-quality technical reports — with detailed reproduction steps, impact context, and actionable recommendations the team can implement. • True methodological autonomy: defines scope, prioritizes by risk, and documents reasoning without relying on external scripts. • Critical thinking and an adversarial mindset. • Independence and methodological autonomy. • Proactivity: anticipating attack surfaces. • Risk communication for technical and non-technical audiences. • Professional ethics and responsibility. • Collaboration with defensive/security teams. • Attention to delivery and closure of findings: quality of output and completion of remediation.

🏖️ Benefits

• 30 days paid vacation • Health insurance with 100% of the monthly premium paid by the company • Dental plan • Life insurance • Full equipment kit • Home office allowance - R$180.00/month • Day off during your birthday month • Gympass discount • No dress code — be yourself! • Extended maternity and paternity leave

Apply Now

Similar Jobs

🕒 July 27

Combine | Global Recruitment

11 - 50

🎯 Recruiter

🤝 B2B

Data QA Engineer responsible for building and maintaining automated tests for data pipelines. Collaborating with engineers and testers in a fully remote environment focusing on data ingestion and processing.

Kafka

Python

SQL

🕒 July 24

Multipedidos

51 - 200

🍽️ Food & Beverage

📦 Logistics

💼 Consulting

Analista de Testes QA garantindo qualidade no SaaS de delivery da Multi Pedidos. Automatizando testes, prevenindo defeitos e evoluindo processos de qualidade.

🗣️🇧🇷🇵🇹 Portuguese Required

Cypress

SQL

🕒 July 23

CI&T

5001 - 10000

💼 Consulting

🏥 Healthcare

📣 Marketing

Senior QA Automation ensuring software quality for CI&T’s AI transformation solutions. Automating tests with Cypress and JavaScript while implementing Azure DevOps CI/CD processes.

🗣️🇧🇷🇵🇹 Portuguese Required

Azure

Cypress

JavaScript

🕒 July 23

Blend IT Consulting

501 - 1000

🤝 B2B

🏢 Enterprise

QA Automation Analyst building E2E tests with Cypress for storefront critical flows. Join Blend IT, focused on innovative solutions for SAP and Mobile platforms.

🗣️🇧🇷🇵🇹 Portuguese Required

Cypress

JavaScript

Next.js

React

🕒 July 23

Cresol Cooperativa

5001 - 10000

🌾 Agriculture

💸 Finance

Quality Analyst for Cresol's systems ensuring quality in testing and automated solutions. Collaborating with agile teams to deliver effective system implementations.

🗣️🇧🇷🇵🇹 Portuguese Required

Azure

Cypress

Docker

Java

JMeter

SQL