
Penetration Tester – Offensive Security, Red Team
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in Brazil.
• Independently plan and carry out intrusion/penetration tests within a specified scope, which includes web applications, APIs, cloud infrastructure, and internal networks.
• Develop and sustain an ongoing internal penetration testing program, focusing on cadence, rotating scopes, and prioritization based on business risks.
• Create comprehensive technical and executive reports that detail severity, business impact, and actionable recommendations.
• Validate and conduct further investigations on findings from external penetration testing vendors, cloud posture tools, and internal scans.
• Perform security evaluations on critical integrations and authentication processes both before and after remediation efforts.
• Execute security assessments on mobile applications and installers, identifying attack surfaces not covered by automated tools.
• Conduct social engineering and targeted phishing exercises, enhancing the awareness program and fostering a security-oriented culture.
• Monitor the remediation lifecycle, ensuring the effectiveness of implemented fixes through structured retesting.
• Extensive experience in penetration testing of web applications and APIs, including knowledge of OWASP Top 10, OWASP API Security Top 10, business logic, and authentication/authorization flows.
• Practical knowledge of security within AWS cloud environments, including IAM privilege escalation, S3 misconfigurations, Lambda, assumable roles, and policy analysis.
• Proficient with penetration testing tools such as Burp Suite Pro, Metasploit, Nmap, Nuclei, and cloud enumeration tools like Pacu and ScoutSuite.
• Capability to write Proof of Concepts (PoCs) and custom exploit scripts when existing tools do not adequately address the scenario.
• Experience in testing mobile applications and thick clients, including an analysis of communications, local storage, and client-side attack surfaces.
• Familiarity with social engineering techniques and the ability to design targeted phishing simulations with clear scope criteria and metrics.
• Production of detailed technical reports with clear reproduction steps, impact context, and actionable recommendations for implementation by the team.
• Demonstrated methodological autonomy: defining scope, prioritizing by risk, and documenting rationale without reliance on external scripts.
• Strong critical thinking skills and an adversarial mindset.
• Self-sufficiency and methodological independence.
• Proactiveness in anticipating potential attack surfaces.
• Ability to communicate risks effectively to both technical and non-technical audiences.
• Commitment to professional ethics and accountability.
• Collaboration with defensive/security teams.
• Attention to detail in the delivery and closure of findings, focusing on the quality of output and completion of remediation efforts.
• 30 days of paid vacation
• Health insurance with 100% of the monthly premium covered by the company
• Dental plan
• Life insurance
• Complete equipment kit
• Home office allowance of R$180.00 per month
• Day off during your birthday month
• Discount on Gympass
• No dress code — be yourself!
• Extended maternity and paternity leave
xCures Inc.
Paradigm Information Services, Inc.
Latitude IT Solutions | SDVOSB
ICF
Get handpicked remote jobs straight to your inbox weekly.