Skip to content

Open nowPosted 68 days ago

Penetration Tester - Offensive Security (Red Team)

Gupy (Portal de Vagas)74,621 open roles

Where
Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPenetration Tester - Offensive Security (Red Team)Gupy (Portal de Vagas) · Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Gupy (Portal de Vagas)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 68 days ago

The posting

Estamos em busca de uma nova pessoa para integrar nosso time de Tech atuando como Penetration Tester - Offensive Security (Red Team) ! 🐿️Já imaginou fazer parte de uma das maiores empresas de tecnologia para restaurantes do Brasil? Atendemos mais de 20 mil clientes em todo o país e somos líderes em software de gestão na nuvem para o setor gastronômico! Além disso, somos uma das Super Integradoras do iFood, entregando uma solução completa — do Ponto de Venda à Retaguarda. Incrível, né?E tem mais: o iFood é nosso investidor!Isso significa que estamos em crescimento exponencial e acelerado — por isso, queremos pessoas que compartilhem da nossa energia, da nossa vontade de inovar e de revolucionar o mercado de food service, para crescer junto com a gente! 💙🧡Responsabilidades e atribuiçõesO que vai fazer parte do seu dia a dia 💼Planejar e executar testes de intrusão com escopo definido de forma autônoma: aplicações web, APIs, infraestrutura cloud e rede interna.Construir e manter um programa interno de pentest contínuo - cadência, escopo rotativo e priorização por risco de negócio.Produzir relatórios técnicos e executivos de alta qualidade, com severidade, impacto de negócio e recomendações acionáveis.Validar e aprofundar findings oriundos de fornecedores externos de pentest, ferramentas de cloud posture e varreduras internas.Conduzir avaliações de segurança em integrações críticas e fluxos de autenticação antes e depois de remediações.Realizar testes de segurança em aplicações mobile e instaladores - mapeando superfícies de ataque que ferramentas automatizadas não cobrem.Executar exercícios de engenharia social e phishing dirigido, contribuindo com o programa de awareness e cultura de segurança.Acompanhar o ciclo de remediação - verificando a eficácia das correções implementadas via retests estruturados.Requisitos e qualificaçõesO que esperamos de você 👌Experiência sólida em testes de intrusão em aplicações web e APIs: OWASP Top 10, OWASP API Security Top 10, lógica de negócio e fluxos de autenticação e autorização.Conhecimento prático de segurança em ambientes cloud AWS: IAM privilege escalation, S3 misconfiguration, Lambda, roles assumíveis e análise de políticas.Proficiência em ferramentas de pentest: Burp Suite Pro, Metasploit, Nmap, Nuclei e ferramentas de enumeração cloud como Pacu e ScoutSuite.Capacidade de escrever PoCs e scripts de exploração customizados quando as ferramentas disponíveis não cobrem o cenário.Experiência na condução de testes em aplicações mobile e thick client, incluindo análise de comunicação, armazenamento local e superfícies de ataque do cliente.Conhecimento de técnicas de engenharia social e capacidade de estruturar simulações de phishing dirigido com critérios claros de escopo e métricas.Produção de relatórios técnicos de alta qualidade - com reprodução detalhada, contexto de impacto e recomendações que o time consegue executar.Autonomia metodológica real: define escopo, prioriza pelo risco e documenta o raciocínio sem depender de roteiro externo.Senso Crítico e Mentalidade Adversarial.Independência e Autonomia Metodológica.Proatividade: Antecipação de Superfícies de Ataque.Comunicação de Risco para Públicos Técnicos e Não Técnicos.Ética e Responsabilidade Profissional.Colaboração com Times de Defesa.Acabativa: Qualidade de Entrega e Fechamento de Findings.O que vai te destacar por aqui 💡Experiência com testes de segurança em pipelines de CI/CD e ambientes de build.Familiaridade com análise estática e reversão de binários para avaliação de instaladores e clientes desktop.Conhecimento de técnicas de movimentação lateral e persistência em ambientes cloud e híbridos.Experiência com purple team - atuação colaborativa com blue team para validar capacidade de detecção e resposta.Familiaridade com frameworks de threat intelligence e TTPs do MITRE ATT&CK aplicados ao planejamento de testes.Noções de segurança em ambientes serverless e containers.Certificações - DesejáveisOSCP - Offensive Security Certified ProfessionalOSWE - Offensive Security Web ExpertBSCP - Burp Suite Certified PractitionereWPTX - eLearnSecurity Web Application Penetration Tester eXtremeInformações adicionais ✨ Curtiu? Calma que tem mais! Aqui você ainda terá:

🌴Contratação PJ com 30 dias de descanso remunerado 🏥 Plano de saúde e odontológico com mensalidade 100% paga pela Saipos (Coparticipação em consultas e exames) 💰 Seguro de vida 🎂 Day off no mês do aniversário 🥊 Wellhub 💻 Kit completo de equipamentos 🚗 Auxílio deslocamento diário (Em caso de vinda presencial) — R$ 22 💵 Auxílio home office - R$180,00 (Para profissionais que atuem pelo menos 3x por semana remoto) 🍼 Licença maternidade estendida e paternidade estendida

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Gupy (Portal de Vagas)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Gupy (Portal de Vagas)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Gupy (Portal de Vagas)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.