Cybersecurity Analyst

Indeed

Company

Job typeFull-time
Workplace typeOnsite
Experience levelNo experience limit
Education levelNo degree limit

Description

Job Summary: We are seeking a Pentester with strong technical maturity and systemic vision, capable of conducting end-to-end assessments and identifying attack chains in complex environments. Key Highlights: 1. Operating in complex scenarios with autonomy and adaptability 2. Conducting penetration tests and offensive assessments 3. Continuously contributing to the evolution of offensive practices **Description and Responsibilities:** **Working Hours:** Monday to Thursday, 9 AM to 7 PM with a 1-hour lunch break; Fridays, 9 AM to 7 PM with a 2-hour lunch break **Level:** Operational **Employment Type:** Full-time – CLT The Security Center maintains an offensive security team focused on validating, in practice, the resilience of applications, infrastructures, and corporate environments through advanced testing and business-context-aligned simulations. We seek a Pentester with strong technical maturity and systemic vision, capable of conducting end-to-end assessments, identifying attack chains, and transforming findings into concrete mitigation actions. This position requires autonomy and adaptability when operating in complex scenarios, collaboration with the Vulnerability Management team, and continuous contribution to the evolution of offensive practices.?? **Main Responsibilities:** * Conduct penetration tests and offensive assessments on applications, APIs, infrastructure, and hybrid environments * Identify complete attack paths by combining technical and logical flaws, excessive permissions, architectural exposures, and operational weaknesses * Plan and execute adversary simulations, offensive validation campaigns, and controlled compromise exercises * Serve as a technical reference and support defining and elevating technical maturity. * Produce technical and executive reports with evidence, impact, and risk-oriented prioritization * Translate technical findings and offensive activity results into actionable recommendations and defensive monitoring strategies (e.g., detection rules, hardening, etc.) for engineering, architecture, product, and security teams. * Validate remediations and support elimination of root causes—not just isolated symptoms * Develop, adapt, and maintain tools, scripts, automations, and lab environments supporting offensive practice * Contribute to applied research on techniques, attack vectors, attack surfaces, and abuse of emerging technologies * Support complex investigations and post-incident analyses with an offensive perspective * Collaborate with AppSec, Cloud Security, and Detection Engineering initiatives as needed * Perform penetration testing on mobile applications * Conduct static (SAST) and dynamic (DAST) analyses to identify logic and security flaws * Collaborate with DevSecOps teams to integrate security best practices into the development lifecycle. **Requirements:** * Intermediate English * Proficiency in operating systems, networks, protocols, and inter-system communication * Knowledge of offensive security across multiple layers * Experience with manual exploitation and critical analysis of attack surfaces * Experience in complex assessments with low reliance on automated tools * Familiarity with pentesting methodologies (OWASP, PTES, NIST, etc.) and application intrusion testing * Flexibility in operational scope * Strong written and verbal communication skills for engaging both technical and non-technical audiences. **Technical Knowledge:** * Application security (web, APIs, mobile) * Vulnerability exploitation (OWASP Top 10 and advanced) * Post-exploitation (lateral movement, privilege escalation, C2) * Cloud and modern environments (Kubernetes, CI/CD) * Offensive tools (Burp, Nmap, ffuf, etc.) * Traffic analysis and enumeration. **Desirable:** * Certifications: OSCP, OSCE, GPEN, GWAT, eJPT, or practical CEH * Knowledge of Active Directory, Windows, and corporate environments. ?? Apply now and join our team! ? **Benefits:** Birthday day off, Mobility (fuel and ride-hailing apps), Health insurance, Dental insurance, Total Pass, Meal allowance, Transportation allowance, Vittude (mental health)

Some content was automatically translated

Posted by

João Silva

Indeed · HR

Location

Similar jobs

Cybersecurity Analyst by Indeed in 2026 | ok.com