FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Penetration Tester – Offensive Security, Red Team
Saipos | Sistema para RestaurantePenetration Tester focusing on security for web applications and APIs at Saipos. Join a leading SaaS company for food service technology in Brazil.
Tech Stack
Tools & technologiesAWSCloud
About the role
Key responsibilities & impact- Plan and execute intrusion/penetration tests autonomously within a defined scope: web applications, APIs, cloud infrastructure, and internal networks.
- Build and maintain an internal continuous pentest program — cadence, rotating scope, and prioritization based on business risk.
- Produce high-quality technical and executive reports, including severity, business impact, and actionable recommendations.
- Validate and further investigate findings from external pentest vendors, cloud posture tools, and internal scans.
- Conduct security assessments of critical integrations and authentication flows before and after remediation.
- Perform security testing on mobile applications and installers — mapping attack surfaces that automated tools do not cover.
- Execute social engineering and targeted phishing exercises, contributing to the awareness program and security culture.
- Track the remediation lifecycle — verifying the effectiveness of implemented fixes through structured retests.
Requirements
What you’ll need- Strong experience in penetration testing of web applications and APIs: OWASP Top 10, OWASP API Security Top 10, business logic, and authentication/authorization flows.
- Hands-on knowledge of security in AWS cloud environments: IAM privilege escalation, S3 misconfigurations, Lambda, assumable roles, and policy analysis.
- Proficiency with pentest tools: Burp Suite Pro, Metasploit, Nmap, Nuclei, and cloud enumeration tools such as Pacu and ScoutSuite.
- Ability to write PoCs and custom exploit scripts when available tools do not cover the scenario.
- Experience testing mobile applications and thick clients, including analysis of communications, local storage, and client-side attack surfaces.
- Knowledge of social engineering techniques and ability to structure targeted phishing simulations with clear scope criteria and metrics.
- Production of high-quality technical reports — with detailed reproduction steps, impact context, and actionable recommendations the team can implement.
- True methodological autonomy: defines scope, prioritizes by risk, and documents reasoning without relying on external scripts.
- Critical thinking and an adversarial mindset.
- Independence and methodological autonomy.
- Proactivity: anticipating attack surfaces.
- Risk communication for technical and non-technical audiences.
- Professional ethics and responsibility.
- Collaboration with defensive/security teams.
- Attention to delivery and closure of findings: quality of output and completion of remediation.
Benefits
Comp & perks- 30 days paid vacation
- Health insurance with 100% of the monthly premium paid by the company
- Dental plan
- Life insurance
- Full equipment kit
- Home office allowance - R$180.00/month
- Day off during your birthday month
- Gympass discount
- No dress code — be yourself!
- Extended maternity and paternity leave