Vision Cybersecurity logo
Vision Cybersecurity

Vemos além do óbvio.

Cyber Exploitation Analyst – Pentest

Location

Brazil

Posted

6 days ago

Salary

0

Seniority

Senior

Bachelor DegreePortugueseAndroidCloudFirewallsiOSLinuxUnix

Job Description

Cyber Exploitation Analyst – Pentest

Vision Cybersecurity

• Perform offensive security testing on hosts running various platforms and operating systems (Windows, UNIX, Linux); • Conduct intrusion tests (penetration testing) on network infrastructures, cloud systems, mobile applications (Android, iOS), and web applications; • Ethically and responsibly exploit vulnerabilities, whether documented or previously undocumented; • Analyze log files from various sources (hosts, network traffic, firewalls, intrusion detection systems) to identify potential security threats; • Collaborate with the defensive team to establish controls and measures that prevent identified exploitations; • Produce detailed reports on exploitation activities performed and document actions taken during tests; • Present penetration test results and act in a consultative capacity, providing support to incident response teams; • Operate autonomously to perform intrusion tests and pentests across different platforms and environments, adhering to ethical and legal guidelines; • Ability to propose and recommend preventive and corrective actions to mitigate identified vulnerabilities; • Authority to guide and assist defensive teams in implementing controls and adjustments based on test findings.

Job Requirements

  • Bachelor's degree in Information Technology, Information Security, or related fields preferred;
  • Familiarity with pentesting frameworks and offensive security methodologies is desirable;
  • Experience with penetration testing and vulnerability exploitation in operating systems, network infrastructures, cloud environments, and mobile applications;
  • Practical knowledge of security log analysis from various sources for threat detection and identification of potential vulnerabilities;
  • Experience with automated vulnerability scanners is desirable;
  • Practical experience in Bug Bounty programs, CTFs, or labs such as Hack The Box and TryHackMe is a plus;
  • Practical certifications such as OSCP, DCPT, SYCP, CPTS, eJPT, or equivalents will be considered advantages;
  • Basic knowledge of networking, operating systems, web applications, and information security;
  • Familiarity with Linux, Windows, the HTTP protocol, and the OWASP Top 10.

Benefits

  • 🩺 Bradesco Top National health plan;
  • 🦷 Odontoprev dental plan;
  • 🌱 Life insurance;
  • 📱 Pipo Saúde: Digital broker for health and corporate benefits;
  • 🏋️‍ TotalPass: Platform connecting you to multiple networks to support your well-being (and your family's);
  • 🚌 Transportation voucher;
  • 💳 Alelo Tudo: Food and meal benefits on a single card;
  • 💰 Private pension: Double match — VISION contributes alongside you;
  • 🎂 Birthday day off: Take a paid day off during your birthday month;
  • 🤝 Referral program: Earn cash for successful referrals;
  • 📚 Discounts at educational institutions;
  • 🍼 Vision Baby kit: Because new beginnings deserve care and celebration;
  • 🔅 Exclusive discounts with the SESC group: Leisure options for you and your family;
  • 💻 Welcome kit: We prepare a comprehensive kit to support your day-to-day work;
  • ☕ Breakfast and afternoon fruit on in-office days.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 5,001-10,000H1B No Sponsor

• Serve as senior technical expert on project tasks to ensure quality services are delivered on schedule and within available budget to meet customer requirements. • Provide frequent updates to the project manager. • Assist project manager with defining and sequencing project tasks, estimating task duration and developing a project schedule as part of developing a project plan. • Review project plans to understand the scope, schedule and assigned work. • Participate in client and project team meetings. • Assist with research and data analysis, including assisting with conducting customer or stakeholder analyses. • Prepare written documents, reports, and presentations, and assist with giving presentations to clients. • Track and accurately report hours spent on projects. • Work with individuals at all levels, provide input to reports and other deliverables, execute multiple assignments, meet agreed deadlines, and adjust to changing client demands. • Perform quality assurance on project deliverables. • Engage frequently for input related to area of expertise to provides valuable insight that helps enhance the business. • Demonstrate a firm understanding of business and implement opportunities for enhancing effectiveness and efficiencies across the organization. • Develop relationships with existing customers to facilitate development of new business opportunities for current and/or additional services. • Understand and be conversant in ABS Group products and services. • Meet with new and existing clients and actively listen to their needs. • Communicate client needs to project managers. • Review published reports and news articles about existing and potential new clients to identify customer intelligence. • Participate in proposal development. • Represent ABS Group and participate in promoting our products and services. • Support ICS/OT cybersecurity activities within capital projects, operational programs, and compliance-related initiatives in industrial environments. • Serve as a cybersecurity advisor to control systems and project teams, helping align security, operational, and client requirements. • Coordinate with cybersecurity, control systems, IT, operations, and other stakeholders to support project execution and client outcomes. • Contribute to cybersecurity-related documentation, compliance support activities, risk assessments, and continuous improvement initiatives. • Support identification of client needs and service opportunities related to industrial cybersecurity, control systems, and operational resilience.

District Of Columbia + 1 moreAll locations: District Of Columbia | Washington
$150K - $190K / year
GuidePoint Security logo

Senior Security Advisor - Access Management

GuidePoint Security

We help organizations make smarter cybersecurity decisions that minimize risk.

Full TimeRemoteTeam 201-500H1B Sponsor

Role Description - Responsible for creating new solutions to help provide customers with more advisory value - Leads IAM assessment discovery sessions in order to deep dive into custom Access Management solutions - Use discovery session information to build assessments containing recommendations and roadmaps - Help clients through the vendor selection process - Acts as trusted advisor for clients through the presales process in order to help figure out what services best fit with client needs Qualifications - The ideal candidate will have deep experience in Access Management, spanning both Workforce IAM and Customer Identity (CIAM) - Seven plus years of hands-on experience with designing, architecting & building Access Management solutions across various technologies (Okta or Ping) - Strong verbal and writing skills to develop technical documentation and presentations - Experience in leading technical architecture and security design discussions - Experience with consultative and complex technical deployment projects, managing various stakeholder relationships - 4-5 years’ experience in scoping and sizing complex projects - 4-5 years’ experience in responding to RFPs and developing statement of work - Understanding of common IAM industry standards and best practices Requirements - Okta, Ping or similar IAM vendor certifications - Bachelors or Master’s Degree in Computer Science, Computer Engineering, MIS or related field Benefits - Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions) - Group Medical Insurance options: - Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans) - High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans) - If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually) - Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans - 12 corporate holidays and a Flexible Time Off (FTO) program - Healthy mobile phone and home internet allowance - Eligibility for retirement plan after 2 months at open enrollment - Pet Benefit Option

United States
Elastic logo

Principal Security ML Research Engineer

Elastic

Self-described as the leading platform for search-powered solutions, Elastic helps organizations, their customers, and their employees find what they need faste

Role Description As a Principal Security ML Research Engineer on the Threat Research and Detection Engineering team, you'll play a key role in enhancing the Elastic Security threat protections by developing advanced AI and machine learning solutions. In this position, you will address real-world cyber threats using innovative ML detection techniques and effective workflows. What You Will Be Doing - Design innovative ML architectures that enhance threat detection and response capabilities. - Prototype advanced AI agent workflows to streamline incident investigation processes. - Collaborate with cross-functional teams to define project specifications and ensure models are optimized for real-world performance and accuracy. - Develop machine learning models aimed at detecting behavioral anomalies in security telemetry. - Create techniques for profiling threat actors to better understand and predict their behaviors. - Collaborate with stakeholders to refine security use cases, ensuring the applicability of ML models. - Build evaluation frameworks to assess ML model performance metrics while developing benchmarking pipelines to test for accuracy and latency. - Implement guardrails that minimize false-positive rates in detection systems. - Measure the endurance of models against adversarial attacks and prompt injections, and conduct regular audits of model robustness to report findings to stakeholders. - Mentor senior engineers in machine learning best practices and security methodologies to elevate the team's expertise. - Collaborate closely with Product Management to ensure that security research aligns with product roadmaps. - Foster well-developed relationships with engineering teams to guarantee the seamless implementation of machine learning solutions. - Produce technical blogs that showcase your innovative findings in security machine learning. - Author white papers that tackle emerging threats and detection strategies. - Present insights at industry conferences to share advancements in security ML, and engage with the security research community to promote collaboration and information sharing. Qualifications - Master's degree in Computer Science, Cybersecurity, or a related field, or 5+ years designing and implementing security machine learning models. - Experience with vector search technology for data retrieval, Retrieval-Augmented Generation techniques, working knowledge of deep learning, clustering, and graph algorithms, and experience training models using scikit-learn, xgboost, PyTorch/Tensorflow. - Knowledge of behavioral anomaly detection in security telemetry and expertise in profiling threat actor behaviors using machine learning. - Ability to develop evaluation frameworks for ML model performance metrics and experience with benchmarking pipelines for testing accuracy and latency. - Experience developing industry-leading scalable machine learning models that significantly improved threat detection while ensuring minimal false-positive rates. - Published research in reputable security and machine learning journals or presented findings at major security conferences and workshops. - Proficiency in modern AI/ML frameworks and hands-on experience integrating LLM APIs into production applications. - Ability to comfortably rotate across projects, collaborate across functions and teams, and seamlessly adapt to evolving team structures. - Proven ability to seamlessly transition between different projects, codebases, or scrum teams based on dynamic business priorities. - Ability to work autonomously and drive decisions and results in a distributed team by leveraging asynchronous, direct, and transparent communication. Benefits - Competitive pay based on the work you do here and not your previous salary. - Health coverage for you and your family in many locations. - Ability to craft your calendar with flexible locations and schedules for many roles. - Generous number of vacation days each year. - We match up to $2000 (or local currency equivalent) for financial donations and service. - Up to 40 hours each year to use toward volunteer projects you love. - Minimum of 16 weeks of parental leave.

United States
Elastic logo

Senior Security Research Engineer

Elastic

Self-described as the leading platform for search-powered solutions, Elastic helps organizations, their customers, and their employees find what they need faste

Role Description In this role, you'll work with the Threat Research and Detection Engineering (TRaDE) team, which plays a key part in shaping the detection capabilities within Elastic Security. We're seeking a Senior Security Research Engineer who has a solid background in macOS and Kubernetes/container security, useful experience in detection engineering, and a genuine interest in enhancing defensive measures. What You Will Be Doing - Develop tailored detection analytics for endpoint macOS and Kubernetes/container environments. - Validate rule functionality and minimize false positives through thorough reviews. - Analyze multi-source telemetry to uncover detection opportunities and enhance clarity. - Collaborate with peers to implement innovative detection methodologies and engage in community knowledge sharing. - Emulate various threat scenarios to thoroughly assess detection capabilities. - Develop and refine detection rules based on the outcomes of these simulations. - Evaluate existing protection mechanisms against simulated attacks and document your findings while recommending improvements for threat detection. - Collaborate with the engineering team to identify telemetry gaps in existing security measures. - Design and implement enhancements that improve detection accuracy. - Assess current telemetry data's gaps in identifying emerging threats and integrate advanced analytics to strengthen detection capabilities. - Provide technical guidance on best practices for utilizing telemetry in security measures. - Write and publish insightful blogs that focus on detection strategies and methodologies. - Contribute to open-source intelligence (OSINT) research, sharing valuable findings with the community. - Develop and maintain a repository of security rules and detection content. - Engage with the cybersecurity community to promote knowledge sharing and best practices, and collaborate with external partners to enhance resources and tools for threat detection. Qualifications - Experience with detection rule development for macOS/Kubernetes/container environments. - Proficiency in using Elastic Security features and tools. - Created detection rules that reduced false positives, improved incident response performance, and enhanced detection coverage. - Published contributions to community detection content or security research. - Innovated and shared novel approaches for telemetry analysis within security research communities. - Achieved recognition or accolades for contributions to detection engineering or threat research initiatives. - Ability to comfortably rotate across projects, collaborate across functions and teams, and seamlessly adapt to evolving team structures. - Proven ability to seamlessly transition between different projects, codebases, or scrum teams based on dynamic business priorities. - Work autonomously and drive decisions and results in a distributed team by leveraging asynchronous, direct, and transparent communication. Benefits - Competitive pay based on the work you do here and not your previous salary. - Health coverage for you and your family in many locations. - Ability to craft your calendar with flexible locations and schedules for many roles. - Generous number of vacation days each year. - We match up to $2000 (or local currency equivalent) for financial donations and service. - Up to 40 hours each year to use toward volunteer projects you love. - Minimum of 16 weeks of parental leave.

United States