Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Saipos | Sistema para Restaurante

Penetration Tester – Offensive Security, Red Team

Saipos | Sistema para Restaurante

Penetration Tester focusing on security for web applications and APIs at Saipos. Join a leading SaaS company for food service technology in Brazil.

Posted 7/27/2026full-timeRemote • BrasilMid-LevelSeniorWebsite

Tech Stack

Tools & technologies
AWSCloud

About the role

Key responsibilities & impact
  • Plan and execute intrusion/penetration tests autonomously within a defined scope: web applications, APIs, cloud infrastructure, and internal networks.
  • Build and maintain an internal continuous pentest program — cadence, rotating scope, and prioritization based on business risk.
  • Produce high-quality technical and executive reports, including severity, business impact, and actionable recommendations.
  • Validate and further investigate findings from external pentest vendors, cloud posture tools, and internal scans.
  • Conduct security assessments of critical integrations and authentication flows before and after remediation.
  • Perform security testing on mobile applications and installers — mapping attack surfaces that automated tools do not cover.
  • Execute social engineering and targeted phishing exercises, contributing to the awareness program and security culture.
  • Track the remediation lifecycle — verifying the effectiveness of implemented fixes through structured retests.

Requirements

What you’ll need
  • Strong experience in penetration testing of web applications and APIs: OWASP Top 10, OWASP API Security Top 10, business logic, and authentication/authorization flows.
  • Hands-on knowledge of security in AWS cloud environments: IAM privilege escalation, S3 misconfigurations, Lambda, assumable roles, and policy analysis.
  • Proficiency with pentest tools: Burp Suite Pro, Metasploit, Nmap, Nuclei, and cloud enumeration tools such as Pacu and ScoutSuite.
  • Ability to write PoCs and custom exploit scripts when available tools do not cover the scenario.
  • Experience testing mobile applications and thick clients, including analysis of communications, local storage, and client-side attack surfaces.
  • Knowledge of social engineering techniques and ability to structure targeted phishing simulations with clear scope criteria and metrics.
  • Production of high-quality technical reports — with detailed reproduction steps, impact context, and actionable recommendations the team can implement.
  • True methodological autonomy: defines scope, prioritizes by risk, and documents reasoning without relying on external scripts.
  • Critical thinking and an adversarial mindset.
  • Independence and methodological autonomy.
  • Proactivity: anticipating attack surfaces.
  • Risk communication for technical and non-technical audiences.
  • Professional ethics and responsibility.
  • Collaboration with defensive/security teams.
  • Attention to delivery and closure of findings: quality of output and completion of remediation.

Benefits

Comp & perks
  • 30 days paid vacation
  • Health insurance with 100% of the monthly premium paid by the company
  • Dental plan
  • Life insurance
  • Full equipment kit
  • Home office allowance - R$180.00/month
  • Day off during your birthday month
  • Gympass discount
  • No dress code — be yourself!
  • Extended maternity and paternity leave