返回搜索结果
Analista de Pentest Sr
地区 São Paulo, Avenida Francisco Matarazzo Ground Floor
发布 2 几天前
职位类型 Regular
参考 R098313
四个女人在一起笑。从左边开始:第一个女人有长长的棕色头发,前面有粉红色的条纹。她穿着棕色和橙色的粗花呢夹克。下一个女人穿着粉红色的衬衫,有长长的棕色头发,戴着金色的耳环。她在看第一个女人。第三个女人穿着白色的上衣和粉红色的开衫。她有长长的棕色卷发,戴着眼镜。最后一个女人有长长的金色头发,穿着短袖黑色上衣。

Certifique-se de anexar seu currículo atualizado e a ciência de seu gestor no ato da candidatura!

#Ibope Media

#LI-MV1

#Remote

Role Overview 

We are seeking a skilled Senior Pentesting Analyst to join our cybersecurity team. This role is responsible for leading and executing penetration tests and red team engagements to test and validate vulnerabilities across our digital infrastructure. This role will work closely with security engineers, developers, and business stakeholders to assess risk, improve defenses, and ensure the resilience of systems against evolving threats. 

 

Key Responsibilities 

  • Plan, execute, and report on penetration tests (web applications, APIs, networks, cloud environments, IoT, etc.) 

  • Conduct red team/blue team exercises and simulate real-world attack scenarios 

  • Identify and exploit vulnerabilities using both automated tools and manual techniques 

  • Develop and maintain custom scripts and tools to support testing activities 

  • Collaborate with development and infrastructure teams to validate findings and recommend remediation strategies 

  • Stay current with emerging threats, vulnerabilities, and offensive security techniques 

  • Assist in compliance assessments (e.g., PCI-DSS, ISO 27001, SOC 2) 

 

Required Skills & Experience 

  • 5+ years of experience in penetration testing, ethical hacking, or offensive security 

  • Strong understanding of network protocols, operating systems, and application security 

  • Proficiency with tools such as Burp Suite, Metasploit, Nmap, Wireshark, and custom scripting (Python, Bash, PowerShell) 

  • Experience with cloud security testing (AWS, Azure, GCP) 

  • Familiarity with MITRE ATT&CK, OWASP Top 10, and CVSS 

  • Relevant certifications (e.g., OSCP, OSCE, GPEN, GWAPT, CISSP) are highly desirable 

  • Excellent communication skills, with the ability to clearly articulate findings and recommendations to technical and non-technical audiences 

  • Fluent in English 

 

Preferred Qualifications 

  • Experience with threat modeling and risk assessments 

  • Knowledge of secure software development lifecycle (SSDLC) 

  • Background in incident response or digital forensics 

  • Experience with CI/CD pipeline security and DevSecOps practices 

  • Spanish language is a plus. 

Candidaturas até 28/11/2025.

立即申请
返回搜索结果