Where People Grow
Penetration Testing Specialist
Location
Latin America
Posted
19 days ago
Salary
0
Seniority
Senior
Job Description
Penetration Testing Specialist
Factorial
• Planificar y ejecutar pruebas de penetración en aplicaciones web, móviles (iOS/Android), API, infraestructura en la nube y redes internas, siguiendo PTES, OWASP WSTG, OWASP MASTG, OWASP API Security Top 10, OWASP ASVS y NIST. • Mantener listas de verificación versionadas, reproducibles y auditables por tipo de objetivo, cubriendo IAM, autorización basada en roles, idempotencia, limitación de tasa, manejo de errores y exposición de información. • Realizar revisiones de código de seguridad de aplicaciones en bases de código backend: validación de entrada, errores de autorización (BOLA/IDOR), errores lógicos financieros (precisión decimal, redondeo, conversiones), concurrencia, idempotencia, firmas de webhook y manejo de secretos. • Operar y ajustar la cadena de herramientas de AppSec integrada en el SDLC: SAST, DAST, SCA, escaneo de secretos y escaneo de IaC. • Diseñar y mantener un programa de modelado de amenazas (STRIDE / PASTA / LINDDUN) para características críticas del producto. • Auditar implementaciones de OAuth 2.0 / OIDC / JWT para confusión de algoritmo, ataques de repetición, rotación de tokens de actualización, PKCE y validación de reclamos (iss/aud/exp). • Realizar pruebas de seguridad de API profundas: BOLA/BFLA, asignación masiva, limitación de tasa, idempotencia, condiciones de carrera y webhooks firmados. • Asegurar integraciones de socios: CSP, frame-ancestors, postMessage, CORS, SameSite y sandboxing. • Buscar vulnerabilidades de lógica empresarial con impacto económico directo: doble gasto, repetición de transacción, condiciones de carrera, montos negativos, desbordamiento/subdesbordamiento, bypass de límite, manipulación de redondeos y reutilización de claves idempotentes. • Construir flujos de trabajo asistidos por IA para recon, triage, generación de PoC, revisión de código y fuzzing dirigido. • Aplicar OWASP Top 10 para LLM y MITRE ATLAS al evaluar características del producto con IA generativa. • Escribir informes ejecutivos y técnicos con gravedad CVSS v4, impacto comercial, PoCs reproducibles y remediaciones accionables. • Rastrear hallazgos hasta su cierre con SLA por gravedad. • Generar evidencia auditables para ISO 27001, BCRA y procesos de diligencia debida de socios. • Presentar hallazgos a los equipos de ingeniería, CTO, CISO y el comité de riesgos. • Incrustarse con escuadras como socio de seguridad: revisiones de diseño, revisiones en pareja y mentoría sobre codificación segura. • Diseñar ejercicios de equipo morado con SecOps, realizar CTF internos y bashes de errores, y mantener un programa de recompensas por errores.
Job Requirements
- 4+ años en pentesting o seguridad de aplicaciones, con experiencia práctica evaluando sistemas en producción.
- Experiencia previa como pentester interno o ingeniero de AppSec en un producto en vivo.
- Antecedentes en desarrollo: capaz de leer y razonar a través del código de forma independiente en al menos 2 lenguajes (Python, .NET, Node/TypeScript o Java).
- Metodología documentada y sistemática: PTES, OWASP WSTG / MASTG / ASVS, OWASP API Top 10.
- Sólidos conocimientos de OAuth 2.0 / OIDC / JWT y sus ataques conocidos (confusión de algoritmo, repetición, confusión de clave, validación de reclamos).
- Amplia experiencia en seguridad de API: BOLA/BFLA, asignación masiva, limitación de tasa, idempotencia, condiciones de carrera, webhooks firmados.
- Cobertura completa de pentesting web: OWASP Top 10, SSRF, deserialización, inyección de plantillas, contaminación de prototipos, y relacionados.
- Pentesting móvil: Frida, Objection, MobSF, eludir la fijación SSL, enganche, análisis estático y dinámico.
- Seguridad en la nube en al menos una nube importante (Azure y/o AWS): IAM, abuso de privilegios, secretos en tuberías, exposición de almacenamiento.
- Uso activo e intencionado de IA con tus propios flujos de trabajo y conciencia de riesgos asociados (datos sensibles, alucinaciones).
- Excelentes habilidades de comunicación escrita: tus informes son entregables auditables.
Benefits
- Teletrabajo
- Oportunidades de crecimiento y desarrollo profesional
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Advisor II, Falcon Complete (Remote)
CrowdStrikeCrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn’t changed — we’re here to stop breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to keep their businesses running, their communities safe and their lives moving forward. We’re also a mission-driven company. We cultivate a culture that gives every CrowdStriker both the flexibility and autonomy to own their careers. We’re always looking to add talented CrowdStrikers to the team who have limitless passion, a relentless focus on innovation and a fanatical commitment to our customers, our community and each other. Ready to join a mission that matters? The future of cybersecurity starts with you. About the Role: The Falcon Complete Security Advisor works within a team of advisors focused on overall health and security posture of all Falcon Complete customers. The ideal candidate will demonstrate a combination of technical, security, and customer management skills aimed at guiding customers towards a successful and secure experience with Falcon Complete. Under the direction of leadership, this role will execute daily tasks to ensure Falcon Complete can achieve its mission to stop breaches. What You'll Do: - Assess customer’s Falcon environment and ensure alignment with Falcon Complete standards. - Provide Falcon Complete customers with recommendations that align to improved security. - Create and recommend remediation for components of CrowdStrike products that may lead to improved security posture. - Contact customers directly upon identification of misalignment with Falcon Complete standards. - Document, update, and resolve all customer related issues in accordance with established procedures and SLAs. - Develop and provide customers with service reports and stats as requested. - Partner with internal teams to ensure customer satisfaction. - Liaise with support team to help troubleshoot and coordinate efforts to resolve technical issues. What You'll Need: - 3+ years in Cybersecurity focused role. - Customer empathy and ability to guide customers towards desired outcome. - Excellent customer-facing communication skills including verbal and written. - Partner with CrowdStrike teams to troubleshoot and resolve customer issues. - Adept in Windows, Linux, and MAC operating systems. - Experience or demonstrated knowledge of threat detection and incident response. - Bachelor's degree in Technology and/or Cybersecurity or relevant experience. - Cybersecurity certifications from reputable organizations such as SANS, ISC2 or equivalent. - US Citizenship or Green Card Holder Bonus Points: - Incident Management and CSIRT operation - Change Management - Malicious Code: Detection and Response - Audit, Logging, and Monitoring Controls (SIEM, UEBA, MDR/XDR). - Intrusion Detection and Response - Experience working with complex, sophisticated clients - Strong analytical capabilities and a desire to learn new things - Able to work across multiple teams to resolve customer issues and requests - Demonstrated experience as a security advisor or consultant - Knowledge of the following frameworks: ISO 27001/2, NIST Cyber Security Framework, CIS Critical Security, PCI DSS, Cloud Controls Matrix and MITRE Att&ck a plus. #LI-RC2 #LI-Remote This role may require the candidate to periodically undergo and pass alcohol and/or drug test(s) during the course of employment.Benefits of Working at CrowdStrike: - Market leader in compensation and equity awards - Comprehensive physical and mental wellness programs - Competitive vacation and holidays for recharge - Paid parental and adoption leaves - Professional development opportunities for all employees regardless of level or role - Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections - Vibrant office culture with world class amenities - Great Place to Work Certified™ across the globe CrowdStrike is proud to be an equal opportunity employer. We are committed to fostering a culture of belonging where everyone is valued for who they are and empowered to succeed. We support veterans and individuals with disabilities through our affirmative action program. CrowdStrike is committed to providing equal employment opportunity for all employees and applicants for employment. The Company does not discriminate in employment opportunities or practices on the basis of race, color, creed, ethnicity, religion, sex (including pregnancy or pregnancy-related medical conditions), sexual orientation, gender identity, marital or family status, veteran status, age, national origin, ancestry, physical disability (including HIV and AIDS), mental disability, medical condition, genetic information, membership or activity in a local human rights commission, status with regard to public assistance, or any other characteristic protected by law. We base all employment decisions--including recruitment, selection, training, compensation, benefits, discipline, promotions, transfers, lay-offs, return from lay-off, terminations and social/recreational programs--on valid job requirements. If you need assistance accessing or reviewing the information on this website or need help submitting an application for employment or requesting an accommodation, please contact us at recruiting@crowdstrike.com for further assistance. Find out more about your rights as an applicant. CrowdStrike participates in the E-Verify program. Notice of E-Verify Participation Right to Work CrowdStrike, Inc. is committed to fair and equitable compensation practices. Placement within the pay range is dependent on a variety of factors including, but not limited to, relevant work experience, skills, certifications, job level, supervisory status, and location. The base salary range for this position for all U.S. candidates is $100,000 - $155,000 per year, with eligibility for bonuses, equity grants and a comprehensive benefits package that includes health insurance, 401k and paid time off.For detailed information about the U.S. benefits package, please click here. Expected Close Date of Job Posting is:07-11-2026
Intermediate Information Security Officer
R&C Request GmbHR&C Request GmbH Matching people since the last decade. Now with a new vision for 2025.
Role Description Du begleitest ein wachsendes Fintech dabei, bankenfähig zu werden und regulatorische Standards zu setzen. - DORA-Umsetzung: Du implementierst die DORA-Anforderungen (Digital Operational Resilience Act) und steuerst deren Einhaltung im Unternehmen. - Architektur-Governance: Du prüfst unsere IT-Infrastruktur auf Konformität und stellst eine effiziente, angemessene Umsetzung von Sicherheitsmaßnahmen sicher. - Fachliche Vertretung: Du vertrittst unsere Sicherheitskonzepte fundiert gegenüber Kunden, Partnerbanken und Aufsichtsbehörden. - Risikomanagement: Du berätst die Geschäftsführung bei strategischen IT-Risiken und agierst als kompetenter Ansprechpartner für alle Sicherheitsfragen. Qualifications - Studium oder Ausbildung im IT-Bereich (z. B. Systemarchitektur) mit Fokus auf Informationssicherheit oder IT-Compliance. - Erste fundierte Erfahrung mit Frameworks wie ISO 27001 oder DORA; Fähigkeit, regulatorische Texte in technische Prozesse zu übersetzen. - Du arbeitest eigenverantwortlich, denkst lösungsorientiert und trittst auch in Verhandlungen mit externen Stakeholdern sicher auf. - Verhandlungssicheres Deutsch und Englisch. Benefits - Einstiegsgehalt bis zu 50-60.000 € Brutto - Geplante Gehaltssteigerung nach 6 Monaten Bewährungsphase - Beteiligung über virtuelle Anteile (VSOP) - Hohe Flexibilität und volle Remote-Option - Nice to have: Krypto Erfahrung
IT Security Engineer
Digistore24 USAA full-service vendor & affiliate platform with one of the world’s largest affiliate marketplaces. #MoreSalesLessWork
Role Description Do you have IT support experience and enjoy assisting our team with their daily tasks in both German and English? Then this could be your new dream job! - Protect our systems and cloud environments: - You continuously analyze security risks, implement modern security standards, and ensure the protection of our cloud infrastructure and critical business systems. - Establish clear security policies and processes: - You further develop our security policies, standardize security processes, and ensure their adoption across the entire organization. - Drive security awareness and training initiatives: - You strengthen security awareness throughout the company through training sessions, workshops, and proactive communication with all teams. - Ensure structured incident and risk management: - You identify security incidents at an early stage, coordinate their handling, prepare analyses, and continuously improve our incident response procedures. - Ensure compliance with standards and regulations (PCI, ISO, NIS2): - You support the company in meeting external compliance requirements, prepare audits, and guide business units through compliance processes. - Monitor our core security mechanisms: - You analyze security-critical components, support monitoring and audit processes, and ensure transparency regarding security-relevant events. - Collaborate closely with Product, IT, and Engineering teams: - You support other teams in designing secure solutions, reducing risks, simplifying security processes, and contributing to a secure, scalable overall architecture. - Ensure a secure software development lifecycle: - You expand our secure development lifecycle (SSDLC), support teams on security-related topics, and ensure that security reviews are a reliable part of our processes. Qualifications - You identify security risks at an early stage and proactively think in terms of solutions. - You have a strong understanding of how software, infrastructure, and cloud systems interact. - Assessing the security of systems, services, and processes is your passion. - Nice-to-have: Experience with compliance standards such as ISO 27001, PCI DSS, or NIS2. - Nice-to-have: Experience with security testing (e.g., SAST, DAST, vulnerability scans). - Understanding of secure development and infrastructure processes (SSDLC, Cloud Security, IAM, Risk Management). - Strong analytical thinking when evaluating security incidents and vulnerabilities. - Excellent communication skills – able to explain technical risks in a clear and understandable way. - Basic knowledge of cloud environments (GCP/AWS) and automated workflows (e.g., CI/CD). - Nice-to-have: Experience with security tools and standards such as SIEM, SSO/MFA, audits, and policies. Requirements - This position is NOT for you if: - You do not enjoy identifying and minimizing security risks. - You struggle with structured analytical work and forward-thinking planning. - You are not interested in continuously learning about security topics: IT security is constantly evolving. - You do not enjoy working independently on security-critical projects. - You tend to avoid conflicts: security sometimes means addressing clear risks openly and directly. - You do not feel comfortable working in an international team. - You do not identify with our values. Benefits - Work in our partner's coworking spaces (max. 3 days a week) or in your home office, as long as you can guarantee uninterrupted internet access. - Regular further education. - The stability of an extremely successful German high-tech company that is funded by its successful product and not by investors. - Outcome focused teams and a culture of direct feedback. - Modern equipment: MacBook. - International, collaborative team with strong cohesion. - Spectacular team events in various European countries. - Autonomy from day one. - Work in your team on a first-name basis, without a dress code, and at eye level. - Flexible working hours from Mondays to Fridays.
Intermediate Information Security Officer
R&C Request GmbHR&C Request GmbH Matching people since the last decade. Now with a new vision for 2025.
• DORA implementation: You will implement the DORA requirements (Digital Operational Resilience Act) and ensure compliance across the company • Architecture governance: You will review our IT infrastructure for compliance and ensure efficient, appropriate execution of security measures • Subject-matter representation: You will represent our security concepts professionally to clients, partner banks, and supervisory authorities • Risk management: You will advise executive management on strategic IT risks and serve as a competent point of contact for all security-related questions



