Finance & Insurance
Pentester
In this project you’ll contact with the European stock market area. Despite its development center being located in Porto and all administrative support in Lisbon, you will be part of a multicultural team that is spread across several European cities.
We are seeking a Pentester to join our team in Porto (hybrid).
Requirements:
- Minimum of 2 years of professional experience as a Pentester / Offensive Security Specialist, performing penetration tests and technical security assessments.
- Proven practical experience in Web Application Security, API Security, and vulnerability assessment, with strong knowledge of the OWASP Top 10 and OWASP Web Security Testing Guide.
- Solid knowledge of authentication and authorization testing, HTTP, network and infrastructure security, and security assessment methodologies.
- Experience working with Linux and Windows environments, Active Directory / Entra ID, and cloud security concepts and technologies.
- Proficiency in scripting or programming and experience with vulnerability research, manual exploitation, attack-path analysis, and the development or adaptation of offensive security tooling. Strong analytical, communication, and critical-thinking skills are required.
Responsibilities:
- Perform penetration tests and technical security assessments across web applications, APIs, infrastructure, cloud, and identity environments.
- Identify, validate, and exploit vulnerabilities through manual investigation, attack-path analysis, and vulnerability chaining, assessing their realistic technical and business impact.
- Conduct reconnaissance, authentication and authorization testing, source code or configuration analysis, and develop or adapt scripts and offensive security tools when required.
- Produce clear and technically accurate security findings, including evidence, impact, exploitability, and actionable remediation recommendations, and support remediation validation activities.
- Contribute to the continuous improvement of offensive security methodologies, tooling, automation, vulnerability research, and knowledge sharing, leveraging AI and modern offensive security techniques while independently validating all AI-generated outputs.
We offer:
- Health insurance;
- A personalized training plan, with a budget to spend on the training and technical books you find necessary;
- Constant feedback so you can grow professionally;
- Remote onboarding process;
- Team events every semester so you can live new adventures;
- Culture of proximity and transparency. Your ideas and needs are heard and valued by us!