Job Overview
Job description
- Location:
- Brazil
- Work arrangement:
- On-site
Role Summary
The professional will be responsible for performing vulnerability tests and security validations on applications developed by Alterdata, ensuring that new systems and updates reach the production environment protected against cyberattacks.
What he will find: You will be part of a dynamic, collaborative and relaxed team, but with a non-negotiable commitment to our organization's resilience and cybersecurity posture.
Expected Experiences and Knowledge (Desirable/Required)
Education/Academic: Preferably completed or ongoing higher education in Cybersecurity, Computer Science, Systems Analysis and Development, Computer Engineering or related IT areas.
Operating Systems: Practical knowledge of using Linux and Windows via command line (CLI), in addition to understanding file permissions and directory structure.
Networks and Protocols: Understanding of the TCP/IP model, DNS, web protocols (HTTP/S) and notions of network architecture.
Offensive Security Fundamentals: Knowledge of basic Pentest methodologies, attack vectors, encryption concepts/secure protocols (SSL/TLS) and vulnerability patterns (OWASP Top 10, CWE).
Practical Tools (Practical Differential): Previous experience or familiarity with the use of essential security tools, such as:
Network scans and enumeration: Nmap, Nikto, DirBuster, Dirb.
Exploitation frameworks: Metasploit (helper modules and scanners).
Vulnerability Management: Nessus or OpenVAS.
Differential
Active participation in CTF (Capture The Flag) competitions will be considered a great advantage, as it demonstrates engagement with the community and practical validation of problem-solving and offensive security skills.
Fluent English.
Responsibilities
Responsibilities and Duties
- Executing Security Scans: Operate and interpret reports from automated vulnerability management tools (e.g. Nessus, OpenVAS) in controlled environments.
- Perform Intrusion Testing (Pentest): Use fundamental offensive security tools (such as Nmap, Nikto, DirBuster/Dirb and Metasploit Framework) to map assets, directories and attack vectors under the guidance of the senior team.
- Análise Técnica e Identificação de Falhas: Mapear e classificar potenciais vulnerabilidades comuns em sistemas e redes com base no OWASP Top 10 e CWE.
- Technical Documentation: Assist in recording evidence and preparing technical inputs for the construction of Pentest reports and security issues.
- Role:
- Information Security Analyst - Red Team
- Job Type:
- Full Time