Senior Offensive Security Analyst – Pentest, Red Team

Jobtailor

São Paulo

Presencial

BRL 150 000 - 270 000

Tempo integral

Há 3 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Destaca-te para esta função — gera um currículo e uma carta de apresentação personalizados em cerca de um minuto.

Ultrapassa os filtros ATS

Resumo da oferta

Jobtailor is seeking an experienced security professional to lead penetration testing, Red Team operations, and cloud security across multi-cloud environments. You will design testing strategies, mentor junior staff, and communicate findings to executives.

The role requires hands-on expertise with AD/Entra ID, Burp Suite, BloodHound, Python, and container security. You will produce actionable risk-based reports and drive improvements in detection and telemetry.

Qualificações

  • Solid experience in penetration testing and Red Team operations in enterprise environments.
  • Hands-on with manual business logic testing and vulnerability exploitation.
  • Advanced infra and cloud knowledge across Azure/AWS/GCP/OCI.
  • Proficient with Burp Suite and BloodHound for enumeration and exploitation.
  • Automation skills in Python/PowerShell/Go for tooling and scaling.
  • CI/CD, container security, secret scanning, and hardening practices.
  • Ability to translate findings into risk-based recommendations for executives.
  • Certifications such as OSCP, OSEP, OSWE, CRTO/CRTL/CRTE, GPEN are preferred.

Responsabilidades

  • Conduct advanced tests and complex scenarios across critical apps, APIs, and multi-cloud environments.
  • Design testing strategy and architecture, including evidence standards and retesting.
  • Plan and execute Red Team exercises with clear rules of engagement and evidence collection.
  • Apply realistic simulations to validate detection capabilities.
  • Provide technical leadership, mentoring, and standardization of deliverables.
  • Engage executive teams to support risk-based prioritization and governance.
  • Communicate operational and financial impact, with mitigation approaches.
  • Integrate offensive and defensive security via Purple Team activities to improve telemetry.

Conhecimentos

Penetration Testing
Red Team Operations
Active Directory/Entra ID
Burp Suite
Python
Threat Modeling
Cloud Security Posture
CI/CD Security
Kubernetes Security
PowerShell
Go

Ferramentas

BloodHound
Go
PowerShell

Descrição da oferta de emprego

  • Conduct advanced tests and complex scenarios across critical applications, APIs with sensitive workflows, integrations, multi-cloud environments, and infrastructure using AD/Entra ID
  • Design testing strategy and architecture, including methodology, evidence standards, severity criteria, retesting, and lessons learned
  • Plan and execute Red Team exercises using TTPs, objectives, scope control, rules of engagement, and evidence collection
  • Apply realistic simulation techniques and validate detection capabilities
  • Provide technical leadership by mentoring mid-level and junior professionals, reviewing reports, and standardizing deliverables
  • Engage with executive teams and technical leadership to support risk-based prioritization
  • Communicate operational and financial impact, along with mitigation approaches
  • Integrate offensive and defensive security through Purple Team activities, recommending improvements to detection and telemetry and validating control effectiveness
  • Produce program metrics and KPIs to support governance and decision-making
Requirements
  • Solid experience in penetration testing and Red Team operations, with a proven track record in enterprise environments
  • Strong command of manual business logic testing (e.g., BOLA/BFLA), complex vulnerability exploitation, and applied threat modeling
  • Advanced infrastructure and cloud expertise: Active Directory/Entra ID, Kerberos/NTLM, privilege escalation, IAM, and cloud security posture across Azure/AWS/GCP/OCI
  • Advanced proficiency with Burp Suite and BloodHound, as well as enumeration, exploitation, and post-exploitation techniques, plus simulation frameworks and labs
  • Python, PowerShell, and/or Go for automation, tooling, and scaling
  • Practical knowledge of CI/CD, container/Kubernetes security, secret scanning, SSRF/deserialization, attack chains, and hardening
  • Ability to produce executive and technical reports that connect finding → risk → recommendation → prioritization
  • Preferred or differentiating certifications: OSCP, OSEP, OSWE, CRTO/CRTL, CRTE, cloud security-focused certifications, and advanced GIAC certifications (e.g., GPEN)
  • Excellent communication skills with diverse audiences (Development, Infrastructure, Security, and Executive Leadership)
  • Strong ethics and responsibility regarding scope, evidence, operational security, and confidentiality
Core Competencies

Demonstrates expertise in penetration testing, Red Team operations, and cloud security across multiple platforms, with a strong ability to communicate technical findings and risk assessments to diverse audiences. Proven leadership in mentoring professionals and producing actionable metrics for governance and decision-making.

Highest-signal resume keywords
  • Penetration Testing
  • Red Team Operations
  • Active Directory/Entra ID
  • Burp Suite
  • Python
Hard Skills
  • Manual Business Logic Testing
  • Complex Vulnerability Exploitation
  • Threat Modeling
  • Cloud Security Posture
  • CI/CD Security
  • Container Security
  • Secret Scanning
  • Exploitation Techniques
  • Simulation Frameworks
  • Kubernetes Security
Soft Skills
  • Excellent Communication Skills
  • Mentoring
  • Ethics and Responsibility
Certifications & Qualifications
  • OSCP
  • OSEP
  • OSWE
  • CRTO
  • CRTL
  • CRTE
  • GPEN
Industry Keywords
  • Multi-Cloud Environments
  • Risk-Based Prioritization
  • Operational Security
  • Evidence Collection
  • Purple Team Activities
Tools & Technologies
  • Burp Suite
  • BloodHound
  • Python
  • PowerShell
  • Go
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Mid-Level Offensive Security Analyst – Pentest, Red Team
Mid-Level Offensive Security Analyst – Pentest, Red Team

Jobtailor • São Paulo

Presencial
BRL 120 000 - 180 000
Information Security Analyst
Information Security Analyst

Jobtailor • Maringá

Presencial
BRL 150 000 - 230 000
Senior Security Analyst
Senior Security Analyst

Jobtailor • São Paulo

Presencial
BRL 70 000 - 110 000
Senior Security Consultant, Red Team
Senior Security Consultant, Red Team

IOActive, Inc. • Brasil

Híbrido
BRL 380 000 - 761 000
Competitive compensation
Access to technical teams
Flexibility to work remotely
+1
Security Specialist
Security Specialist

Jobtailor • São Paulo

Presencial
BRL 180 000 - 240 000
Project Consultant – Mid-Level
Project Consultant – Mid-Level

Jobtailor • São Paulo

Presencial
BRL 120 000 - 180 000
Information Security Consultant – Mid-Level
Information Security Consultant – Mid-Level

Jobtailor • São Paulo

Presencial
BRL 100 000 - 167 000
Senior Security and Operations Analyst
Senior Security and Operations Analyst

Jobtailor • São Paulo

Presencial
BRL 90 000 - 150 000
Information Security Engineer, AppSec
Information Security Engineer, AppSec

Jobtailor • São Paulo

Presencial
BRL 90 000 - 180 000
Ethical Hacker/Pentester Mid Level (2+ Years) - LATAM
Ethical Hacker/Pentester Mid Level (2+ Years) - LATAM

Insight Assurance • Brasil

Híbrido
BRL 100 000 - 180 000