Submeter

Offensive Security Specialist

Porto

Descrição da posição

Responsibilities:

  • Perform penetration testing (pentesting) and technical security assessments on web applications, APIs, cloud environments, and internal/external infrastructure (including Active Directory / Entra ID).
  • Go beyond automated scanning tools, through manual investigation, vulnerability validation, and attack-path chaining.
  • Integrate AI-assisted tools (LLMs, coding assistants, and agent-based tools) into offensive security processes, accelerating research, script development, payload creation, and report writing.
  • Develop or adapt custom scripts and offensive security tools to support specific assessment scenarios.
  • Produce clear, technically rigorous, and actionable documentation detailing identified vulnerabilities, business impact, and mitigation recommendations.
  • Collaborate closely with development, infrastructure, and security teams to communicate technical security issues and support remediation efforts.
  • Contribute to the continuous improvement of internal methodologies, knowledge sharing, research, and offensive security capabilities.

Requirements

  • Solid hands-on experience in penetration testing and technical security assessments.
  • Practical knowledge of offensive security tools (such as Burp Suite, Nmap, Metasploit, or equivalent frameworks).
  • In-depth knowledge of web application security (OWASP Top 10, WSTG), API security, network infrastructure, and Active Directory / Entra ID environments.
  • Demonstrated fluency in using AI tools, knowing how to use them as productivity accelerators without compromising critical thinking, independent technical judgment, and validation of results.
  • Scripting or programming skills to adapt tools, automate repetitive tasks, and develop custom payloads.
  • High level of autonomy, proactivity, critical thinking, and problem-solving ability in complex security assessment scenarios.
  • Command of the English language to effectively communicate technical concepts with both technical and non-technical stakeholders.
Nice to Have:

  • Relevant offensive security certifications, such as OSCP, OSWA, OSWE, CRTO, eWPT, or equivalent.
  • Active participation in CTFs (Capture The Flag), Bug Bounty programs, cybersecurity research, or open-source offensive tool development.

Quer se candidatar?
Cargo
Nome*
Email*
Telefone*
País*
Cidade*
Linkedin
Upload your CV* (máx. 4MB)
Faça upload da sua foto ou video (máx. 4MB)
Submeter