
Cyber Exploitation Analyst – Pentest
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in Brazil.
• Execute offensive security assessments on hosts utilizing a range of platforms and operating systems (Windows, UNIX, Linux);
• Carry out intrusion tests (penetration testing) on network infrastructures, cloud systems, mobile applications (Android, iOS), and web applications;
• Ethically and responsibly exploit vulnerabilities, whether they are documented or previously unknown;
• Examine log files from multiple sources (hosts, network traffic, firewalls, intrusion detection systems) to pinpoint potential security threats;
• Collaborate with the defensive team to implement controls and measures that prevent identified exploitations;
• Generate comprehensive reports on exploitation activities conducted and document actions taken during tests;
• Present penetration test results and operate in a consultative role, offering assistance to incident response teams;
• Function independently to conduct intrusion tests and pentests across various platforms and environments, following ethical and legal guidelines;
• Capable of proposing and recommending preventive and corrective measures to mitigate identified vulnerabilities;
• Authorized to guide and assist defensive teams in executing controls and modifications based on test outcomes.
• Bachelor’s degree in Information Technology, Information Security, or related fields is preferred;
• Knowledge of pentesting frameworks and offensive security methodologies is advantageous;
• Experience in penetration testing and vulnerability exploitation within operating systems, network infrastructures, cloud environments, and mobile applications;
• Practical understanding of security log analysis from diverse sources for threat detection and identification of potential vulnerabilities;
• Experience with automated vulnerability scanning tools is preferred;
• Practical experience in Bug Bounty programs, CTFs, or platforms such as Hack The Box and TryHackMe is a plus;
• Relevant certifications such as OSCP, DCPT, SYCP, CPTS, eJPT, or equivalents will be regarded as advantages;
• Basic understanding of networking, operating systems, web applications, and information security;
• Familiarity with Linux, Windows, the HTTP protocol, and the OWASP Top 10.
• 🩺 Bradesco Top National health plan;
• 🦷 Odontoprev dental plan;
• 🌱 Life insurance;
• 📱 Pipo Saúde: Digital broker for health and corporate benefits;
• 🏋️ TotalPass: Platform connecting you to multiple networks to support your well-being (and your family's);
• 🚌 Transportation voucher;
• 💳 Alelo Tudo: Food and meal benefits on a single card;
• 💰 Private pension: Double match — VISION contributes alongside you;
• 🎂 Birthday day off: Take a paid day off during your birthday month;
• 🤝 Referral program: Earn cash for successful referrals;
• 📚 Discounts at educational institutions;
• 🍼 Vision Baby kit: Because new beginnings deserve care and celebration;
• 🔅 Exclusive discounts with the SESC group: Leisure options for you and your family;
• 💻 Welcome kit: We prepare a comprehensive kit to support your day-to-day work;
• ☕ Breakfast and afternoon fruit on in-office days.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.