Job Overview
Job description
- Location:
- Brazil
- Work arrangement:
- On-site
Role Summary
We are looking for a new person to join our Tech team acting as Penetration Tester - Offensive Security (Red Team)! 🐿️
Have you ever imagined being part of one of the largest technology companies for restaurants in Brazil?
We serve more than 19 thousand customers across the country and are leaders in cloud management software for the gastronomic sector! Furthermore, we are one of iFood's Super Integrators, delivering a complete solution — from the Point of Sale to the Rear. Incredible, right?
And there's more: iFood is our investor!
This means that we are experiencing exponential and accelerated growth — that's why we want people who share our energy, our desire to innovate and revolutionize the food service market, to grow together with us!💙🧡
What will be part of your daily life 💼
Plan and execute intrusion tests with a defined scope autonomously: web applications, APIs, cloud infrastructure and internal network.
Build and maintain a continuous internal pentest program - cadence, rotating scope and prioritization by business risk.
Produce high-quality technical and executive reports, with severity, business impact and actionable recommendations.
Validate and deepen findings from external pentest providers, cloud posture tools and internal scans.
Conduct security assessments on critical integrations and authentication flows before and after remediations.
Perform security tests on mobile applications and installers - mapping attack surfaces that automated tools do not cover.
Carry out social engineering and targeted phishing exercises, contributing to the awareness and security culture program.
Monitor the remediation cycle - verifying the effectiveness of implemented corrections via structured retests.
Responsibilities
- Solid experience in intrusion testing of web applications and APIs: OWASP Top 10, OWASP API Security Top 10, business logic and authentication and authorization flows.
- Practical knowledge of security in AWS cloud environments: IAM privilege escalation, S3 misconfiguration, Lambda, assumed roles and policy analysis.
- Proficiency in pentest tools: Burp Suite Pro, Metasploit, Nmap, Nuclei and cloud enumeration tools such as Pacu and ScoutSuite.
- Ability to write custom PoCs and exploration scripts when available tools do not cover the scenario.
- Experience in conducting tests on mobile and thick client applications, including analysis of communication, local storage and client attack surfaces.
- Knowledge of social engineering techniques and ability to structure targeted phishing simulations with clear scope criteria and metrics.
- Production of high-quality technical reports - with detailed reproduction, impact context and recommendations that the team can execute.
- Real methodological autonomy: defines scope, prioritizes by risk and documents reasoning without depending on an external script.
- Critical Sense and Adversarial Mentality.
- Independence and Methodological Autonomy.
- Proactivity: Anticipation of Attack Surfaces.
- Risk Communication for Technical and Non-Technical Audiences.
- Ethics and Professional Responsibility.
- Collaboration with Defense Teams.
- Acabativa: Quality of Delivery and Closing of Findings.
What will make you stand out here 💡
- Experience with security testing in CI/CD pipelines and build environments.
- Familiarity with static analysis and binary rollback for evaluating installers and desktop clients.
- Knowledge of lateral movement and persistence techniques in cloud and hybrid environments.
- Experience with purple team - collaborative work with blue team to validate detection and response capabilities.
- Familiarity with threat intelligence frameworks and MITER ATT&CK TTPs applied to test planning.
- Understanding security in serverless and container environments.
- Certifications - Desirable
- OSCP - Offensive Security Certified Professional
- OSWE - Offensive Security Web Expert
- BSCP - Burp Suite Certified Practitioner
- eWPTX - eLearnSecurity Web Application Penetration Tester eXtreme
Benefits
- ✨ Did you like it? Don't worry, there's more! Here you also have:
- 🧾 PJ hiring with 30 days of paid rest
- ❤️ Health plan with monthly fee 100% paid by the company (for PJs after 6 months)
- 🦷 Dental plan (for PJ after 6 months)
- 💰 Life insurance
- 💻 Complete equipment kit
- 💻 Home Office Assistance - R$180.00/month
- 🎉 Day off in the month of your birthday
- 💪 Discount on Gympass
- 👕 No dress code — be you!
- 🍼 Extended maternity and paternity leave
- Role:
- Penetration Tester - Offensive Security (Red Team)
- Job Type:
- Contractor