Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Junior Pentester based in Brazil.
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Junior Pentester based in Brazil. Join a global security team where you’ll build hands-on experience across modern penetration testing engagements. You’ll work alongside experienced offensive security professionals across web applications, APIs, mobile, cloud, networks, and LLMs. The role combines manual testing with AI-assisted security workflows, giving you exposure to emerging approaches in offensive security. You’ll receive structured mentorship while developing your testing methodology, reporting, and client communication skills. As your expertise grows, you’ll take on increasingly complex engagements and greater ownership. This is an opportunity to strengthen your offensive security craft while contributing directly to the security of a diverse customer base.
Conduct penetration testing engagements across web applications, APIs, mobile applications, cloud environments, LLMs, and networks using established methodologies and internal playbooks. Combine manual testing techniques with AI-assisted tools for activities such as reconnaissance, payload generation, and initial vulnerability triage. Validate AI-generated results manually, assess their accuracy, and understand the limitations of automated security tooling. Identify, validate, and document security vulnerabilities with clear reproduction steps, supporting evidence, risk ratings, and practical remediation recommendations. Assist senior penetration testers with engagement scoping, preparation, and other pre-engagement activities as required. Contribute to the continuous improvement of internal testing templates, skills, plugins, MCPs, checklists, and technical documentation. Gradually take ownership of more complex testing engagements as your technical expertise and confidence develop. Requirements 1–2 years of experience in penetration testing, vulnerability assessment, or a closely related offensive security role; internships, freelance engagements, and bug bounty experience are also relevant. At least one of the following certifications: BSCP or OSCP . Foundational knowledge of web application security, including the OWASP Top 10, authentication and session management vulnerabilities, and common injection flaws. Practical interest in offensive security demonstrated through self-study, security labs, CTFs, bug bounty programs, personal projects, coursework, or similar activities. Comfortable incorporating AI tools into security workflows and able to critically validate AI-generated results rather than relying on them without verification. Interest in emerging AI-related attack surfaces and how AI-powered features can introduce new security risks. Security research, responsible disclosures, technical blog posts, conference talks, or other public security contributions are a plus, regardless of scale. Strong English communication skills, both written and verbal, with the ability to explain technical security concepts clearly to different audiences. A curious, self-driven, collaborative mindset and a genuine desire to continuously expand your offensive security toolkit. Benefits Competitive base salary. Exceptional private healthcare. Early equity opportunity in a fast-growing company. Fully remote, work-from-home model. Flexible paid time off. Company-provided laptop. Monthly wellness and home Wi-Fi stipend. Structured career progression from junior to mid-level penetration tester, with clear development milestones and regular feedback. Mentorship from experienced offensive security professionals. Training, certification, and conference budget to support continued professional development.
Tips for this job
Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
jobgether (lever) ↗Browse current Job and Scholarship listings from jobgether (lever) →