Skip to content

Open nowPosted 31 days ago

Coordenador de Red Team

Gupy (Portal de Vagas)74,621 open roles

Where
São Paulo, Brazil
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCoordenador de Red TeamGupy (Portal de Vagas) · São Paulo, Brazil
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Gupy (Portal de Vagas)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 31 days ago

The posting

Estamos em busca de um(a) Coordenador(a) de Red Team para integrar o time de Segurança e Conformidade da PWS Cloud e liderar a operação, estratégia e evolução das disciplinas de AppSec e Pen Test da empresa. Trata-se de uma posição de liderança técnica, voltada para um profissional com domínio de segurança ofensiva, cobrindo desde a análise de aplicações (threat modeling e secure code review) até a simulação de ataques reais esse profissional deve atuar não apenas como gestor(a) de testes, mas como especialista capaz de pensar como um atacante, identificar falhas em baixo nível de código e infraestrutura, e estruturar a cultura de segurança ofensiva da empresa.Responsabilidades e atribuiçõesAppSec

Liderar iniciativas de threat modeling e secure code review em projetos críticos da empresa;Conduzir a integração e evolução de ferramentas de SAST/DAST/SCA nos pipelines de CI/CD;Estruturar e evoluir treinamentos de AppSec e o programa de Security Champions junto aos times de engenharia;Coordenar o ciclo de gestão de vulnerabilidades de aplicações, priorizando riscos com base em criticidade e exploração;Definir padrões seguros de desenvolvimento (secure coding guidelines) e apoiar sua adoção pelos times de produto;

Pen Test e Red Teaming

Planejar e conduzir testes de intrusão internos e externos, incluindo redes, aplicações e ambientes cloud;Conduzir exercícios de purple teaming em conjunto com a torre de Blue Team, validando a eficácia dos controles de detecção;Liderar exercícios de red team e simulação de adversários (adversary simulation), mapeados a frameworks como MITRE ATT&CK;

Liderança e Gestão

Liderar, desenvolver e estruturar o crescimento da equipe de AppSec e Pen Test;Definir e acompanhar indicadores de performance, maturidade e eficácia das operações ofensivas (KPIs/KRIs técnicos);Estabelecer processos, metodologias e documentação técnica (relatórios executivos e técnicos de testes);Colaborar com as demais torres de Segurança e Conformidade (Blue Team, GRC) para garantir aderência de controles técnicos aos frameworks de referência (ISO 27001, PCI-DSS, NIST CSF);Reportar status de maturidade ofensiva, riscos técnicos e investimentos necessários ao CISO.

Requisitos e qualificaçõesExperiência sólida (6+ anos) em Cyber, com foco em segurança ofensiva (Red Team/AppSec/Pen Test);Domínio profundo em testes de intrusão em redes, aplicações web/mobile e ambientes cloud;Experiência prática em threat modeling e secure code review em múltiplas linguagens de programação;Conhecimento sólido em técnicas de exploração (exploitation), escalonamento de privilégios e evasão de defesas;Experiência com ferramentas de SAST/DAST/SCA integradas a pipelines de CI/CD;Experiência conduzindo simulações de adversário e/ou exercícios de purple teaming;Experiência liderando equipes técnicas de segurança ofensiva;Boa capacidade analítica, visão estratégica de arquitetura e comunicação executiva;

Informações adicionaisCertificações de segurança ofensiva (OSCP, OSCE, OSWE, GPEN, GWAPT, CEH);Experiência em segurança de aplicações cloud-native, containers e Kubernetes;Vivência com programas de Security Champions e cultura de DevSecOps;Conhecimento de linguagens de scripting/programação para desenvolvimento de exploits e automação de testes (Python, Bash, PowerShell);

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Gupy (Portal de Vagas)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Gupy (Portal de Vagas)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Gupy (Portal de Vagas)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.