Submeter
Offensive Security Specialist
Porto
Descrição da posição
Responsibilities:
- Perform penetration testing (pentesting) and technical security assessments on web applications, APIs, cloud environments, and internal/external infrastructure (including Active Directory / Entra ID).
- Go beyond automated scanning tools, through manual investigation, vulnerability validation, and attack-path chaining.
- Integrate AI-assisted tools (LLMs, coding assistants, and agent-based tools) into offensive security processes, accelerating research, script development, payload creation, and report writing.
- Develop or adapt custom scripts and offensive security tools to support specific assessment scenarios.
- Produce clear, technically rigorous, and actionable documentation detailing identified vulnerabilities, business impact, and mitigation recommendations.
- Collaborate closely with development, infrastructure, and security teams to communicate technical security issues and support remediation efforts.
- Contribute to the continuous improvement of internal methodologies, knowledge sharing, research, and offensive security capabilities.
Requirements
- Solid hands-on experience in penetration testing and technical security assessments.
- Practical knowledge of offensive security tools (such as Burp Suite, Nmap, Metasploit, or equivalent frameworks).
- In-depth knowledge of web application security (OWASP Top 10, WSTG), API security, network infrastructure, and Active Directory / Entra ID environments.
- Demonstrated fluency in using AI tools, knowing how to use them as productivity accelerators without compromising critical thinking, independent technical judgment, and validation of results.
- Scripting or programming skills to adapt tools, automate repetitive tasks, and develop custom payloads.
- High level of autonomy, proactivity, critical thinking, and problem-solving ability in complex security assessment scenarios.
- Command of the English language to effectively communicate technical concepts with both technical and non-technical stakeholders.
Nice to Have:
- Relevant offensive security certifications, such as OSCP, OSWA, OSWE, CRTO, eWPT, or equivalent.
- Active participation in CTFs (Capture The Flag), Bug Bounty programs, cybersecurity research, or open-source offensive tool development.
Quer se candidatar?
Cargo
Nome*
Email*
Telefone*
País*
Cidade*
Linkedin
Upload your CV*
(máx. 4MB)
Faça upload da sua foto ou video
(máx. 4MB)


