Description
Summary:
This role involves conducting penetration testing and technical security assessments across various environments, leveraging AI-assisted tools, and collaborating with teams to improve security.
Highlights:
1. Conduct penetration testing and technical security assessments
2. Integrate AI-assisted tools into offensive security processes
3. Contribute to continuous improvement and knowledge sharing
#### **Sobre o trabalho Offensive Security Specialist**
Luza is an all\-inclusive consulting company focused on talent, tech and innovation. We exist to elevate companies and humans all around the world, making change, from the inside to the outside.
We believe that technology \+ human kindness positively impacts every community around the world. Our approach is simple, we see a world without borders, and believe in equal opportunities. We are guided by our core principles of spreading positivity, good energy and promote equality and care for others.
Our hiring process is unique! People are selected by their value, education, talent and personality. We dont present ethnicity, religion, national origin, age, gender, sexual orientation or identity.
Its time to burst the bubble, and we will do it together!
**What You'll do:**
* Conduct penetration testing (pentesting) and technical security assessments across web applications, APIs, cloud environments, and internal/external infrastructures (including Active Directory / Entra ID);
* Go beyond the use of automated analysis tools through manual investigation, vulnerability validation, and attack vector chaining (*attack\-path chaining*);
* Integrate AI\-assisted tools (LLMs, coding assistants, and agent\-based tools) into offensive security processes, accelerating investigation, script development, payload creation, and report writing;
* Develop or adapt custom scripts and offensive security tools to support specific assessment scenarios;
* Produce clear, technically rigorous, and actionable documentation detailing identified vulnerabilities, business impact, and mitigation recommendations;
* Collaborate closely with development, infrastructure, and security teams to communicate technical security issues and support remediation efforts;
* Contribute to the continuous improvement of internal methodologies, knowledge sharing, research, and offensive security capabilities;
* Hybrid work model;
**Who You Are:**
* Solid hands\-on experience in penetration testing and technical security assessments;
* Practical knowledge of offensive security tools such as Burp Suite, Nmap, Metasploit, or equivalent frameworks;
* In\-depth knowledge of web application security (OWASP Top 10, WSTG), API security, network infrastructure, and Active Directory / Entra ID environments;
* Demonstrated fluency in the use of AI tools, using them as productivity accelerators without compromising critical thinking, independent technical judgment, and result validation;
* Scripting or programming skills to adapt tools, automate repetitive tasks, and develop custom payloads;
* High level of autonomy, proactivity, critical thinking, and problem\-solving skills in complex security assessment scenarios;
* Fluency in English to communicate technical concepts effectively with both technical and non\-technical stakeholders;
**Nice to have:**
* Relevant offensive security certifications such as OSCP, OSWA, OSWE, CRTO, eWPT, or equivalent;
* Active participation in CTFs (Capture The Flag), Bug Bounty programs, cybersecurity research, or open\-source offensive security tool development;
**What you'll get:**
* Wage according to candidate's professional experience;
* Remote Work whenever possible;
* Delivery of work equipment adjusted to the performance of functions;
\- Benefits plan;
* And others.
Work together with expert teams on projects of large magnitude and intensity, long term together with our clients, all leaders in their industries.
Are you ready to step into a diverse and inclusive world with us?
**Together we will promote uniquess!**