5 часов назад
Mid-level Cyber Security Analyst - Pentester (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Mid-level Cyber Security Analyst - Pentester (Fintech): Performing penetration tests and simulating real-world attacks across networks, web and mobile applications, wireless systems, social engineering scenarios, and cloud infrastructure with an accent on vulnerability validation, malware analysis, and security assessments. Focus on identifying Indicators of Compromise, communicating remediation strategies, and improving the security posture of a global payments platform.
Location: Curitiba, Brazil — on-site
Company
is a fintech building global payment infrastructure that connects digital businesses with consumers across 21 markets.
What you will do
- Perform penetration tests across networks, web and mobile applications, wireless environments, and social engineering scenarios.
- Plan, execute, and continuously improve the external penetration testing program.
- Simulate real-world attacks against on-premises and cloud-hosted applications and infrastructure.
- Conduct malware analysis and reverse engineering to identify Indicators of Compromise and support threat hunting.
- Prepare technical reports, executive summaries, security recommendations, and remediation strategies for stakeholders.
- Use attacker tactics, techniques, and procedures to evaluate and improve the organization’s security posture.
Requirements
- Strong understanding of TCP/IP, networking protocols, operating systems, systems administration, and enterprise network architectures.
- Knowledge of cloud security, security protocols, encryption, authentication, authorization, and security controls.
- Experience with security incident analysis, threat analysis, and incident response.
- Hands-on web application penetration testing experience, including OWASP Top 10 vulnerabilities and web services security.
- Knowledge of ISO/IEC 27001, OWASP, the NIST Cybersecurity Framework, and the NIST Privacy Framework.
- Excellent written and verbal communication skills for technical and non-technical audiences.
Nice to have
- OSCP, CEH, CompTIA Security+, GWAPT, GPEN, cloud security, or equivalent certifications.
- Experience with malware reverse engineering, threat intelligence, or purple team exercises.
- Offensive security automation, scripting with Python, PowerShell, or Bash, or security tooling development.
- Experience in financial services, fintech, or highly regulated environments.
- Professional proficiency in English and Spanish.
Culture & Benefits
- Annual performance bonus based on company results.
- Monthly meal allowance and medical and dental plans with dependent coverage.
- Financial assistance for undergraduate, graduate, and MBA programs.
- Budget for courses, certifications, and workshops, plus language classes.
- Semi-flexible hours, a birthday day off, and a year-end break.
- Well-being programs supporting physical and mental health.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →