TL;DR
Senior Security Engineer (Offensive Security): Enhancing security maturity through attack simulation to identify and mitigate security threats with an accent on performing infrastructure, web, and mobile/API pentests and crafting red team operations. Focus on strengthening security posture, evolving defense strategies, and embedding security into products and services from the ground up.
Location: Hybrid in São Paulo, Brazil (2-3 times/week)
Company
hirify.global is a leading global digital banking platform founded in 2013, redefining financial relationships across Latin America through innovative technology and outstanding customer service.
What you will do
- Perform infrastructure, web, and mobile/API pentests.
- Craft and execute red team operations.
- Help with vulnerability management.
- Code tools to assist with offensive security reviews.
- Support operations to fix vulnerabilities and assist development squads.
- Assist in architectural/logical reviews of different software.
Requirements
- Offensive Security background, with a focus on Red Team activities.
- Experience with pentesting aspects: reconnaissance, enumeration, exploitation, post-exploitation, lateral movement.
- Strong knowledge of recent and past attack vectors and their fixes.
- Ability to reproduce Advanced Persistent Threat (APT) group behaviors.
- Experience with security frameworks like OWASP.
- General knowledge in all security scopes, including Operating Systems, Networks, Databases, and Infrastructure Architecture.
Nice to have
- Active participation in CTF or Bug Bounty programs.
- Experience with security assessment tools (e.g., Burp Suite, Nmap, Metasploit, SQLmap, Nessus, Censys, Shodan, Frida.re).
Culture & Benefits
- Chance to earn equity.
- Comprehensive benefits: Food/Meal Card, Public Transportation Commuting Benefit, Life, Medical, and Dental Plans.
- NuCare program for Psychological, Financial, and Legal Assistance.
- Learning and development opportunities: NuLanguage and Nucleo platforms.
- Family support: Extended Parental Leave, Daycare Allowance, Parental Consultancy.
- Work-life balance: Work-from-home Allowance, Gym Partnerships, 30 days of paid vacation.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →