Offensive Security Engineer (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
TL;DR
Offensive Security Engineer (Cybersecurity): Identifying and exploiting vulnerabilities across APIs, mobile apps, and infrastructure with an accent on security automation and red team operations. Focus on building offensive tooling and leveraging LLM-powered agents to detect and fix vulnerabilities in real time.
Location: Remote (SΓ£o Paulo, Brazil)
Company
is building a smarter, AI-driven future for payments and credit.
What you will do
- Conduct pentests on APIs, mobile apps (Android/iOS), and infrastructure to identify vulnerabilities.
- Execute red team operations, including phishing, social engineering, and privilege escalation to measure organizational resilience.
- Engineer security platforms, scanning pipelines, and automation to multiply team impact.
- Design and build LLM-powered agents that detect, classify, triage, and fix vulnerabilities in real time.
Requirements
- Strong knowledge of common vulnerabilities, exploitation techniques, and secure coding practices.
- Experience with web application and API pentesting; mobile pentesting is a strong plus.
- Daily coding proficiency in TypeScript, Go, or similar languages to build tools and services.
- Familiarity with cloud infrastructure security (GCP/AWS/Azure), Kubernetes, and service mesh concepts.
- Understanding of CI/CD pipelines and how to embed security checks into them.
- Experience leveraging LLMs or AI agents for security tasks.
Nice to have
- Experience with red team operations: phishing infrastructure, social engineering, and C2 frameworks.
- Familiarity with payment industry security, including PCI DSS and card tokenization.
- Experience building internal security platforms, dashboards, or vulnerability management systems.
- Contributions to open source security tools, published research, or CTF participation.
Culture & Benefits
- Fast-paced environment focused on solving hard problems and exploiting real weaknesses.
- Hybrid approach blending red teaming with defensive security engineering.
- Direct impact on how the company defends itself at scale.
- Opportunity to weaponize AI for defensive security purposes.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β