Job Opportunity Posted 10 days ago

Penetration Tester

Kore Pagamentos
New Delhi

Job Description

Offensive Security Engineer / Red Team Operator

We are looking for a highly skilled Offensive Security Engineer / Red Team Operator to join our security team.

This is a hands-on technical role for someone with strong experience in penetration testing, adversary simulation, vulnerability research, and offensive security tooling. You will work exclusively within authorized environments to identify weaknesses and help strengthen the security of our applications, infrastructure, APIs, and payment systems.

Responsibilities

  • Conduct authorized penetration tests across web applications, APIs, networks, cloud environments, and internal infrastructure
  • Perform Red Team exercises and adversary simulations
  • Identify, validate, and document security vulnerabilities
  • Assess Active Directory and Windows-based environments
  • Develop custom offensive security tools and proof-of-concept code for controlled testing environments
  • Perform vulnerability research and exploit analysis
  • Analyze malicious techniques, malware behavior, and attack chains for defensive research
  • Perform reverse engineering and debugging when required
  • Evaluate security controls, including endpoint protection and detection mechanisms
  • Work closely with engineering teams to reproduce vulnerabilities and implement effective remediation
  • Produce clear technical reports detailing findings, impact, evidence, and remediation recommendations

Technical Skills

We are particularly interested in candidates with experience in:

  • Penetration Testing
  • Red Team Operations
  • Adversary Simulation
  • Web Application & API Security
  • Network Security
  • Active Directory Security
  • Vulnerability Research
  • Exploit Development
  • Reverse Engineering
  • Malware Analysis
  • Windows Internals
  • C2 infrastructure and frameworks
  • Security automation and custom tooling

Strong programming/scripting skills in one or more of:

  • C / C++
  • C#
  • Python
  • PowerShell
  • Bash
  • Assembly / x86-64 knowledge is a strong plus

Certifications

The following certifications are highly desirable:

  • OSCP — Offensive Security Certified Professional
  • OSEP — Offensive Security Experienced Penetration Tester
  • OSWE — Offensive Security Web Expert
  • CRTO / CRTO II — Certified Red Team Operator
  • eCPPT / eCPTX
  • GPEN
  • GWAPT

Equivalent hands-on experience will also be considered.

Nice to Have

  • Experience in fintech, banking, or payment infrastructure
  • Knowledge of Pix and Brazilian payment systems
  • Experience securing high-volume APIs and financial applications
  • Cloud security experience (AWS, Azure, or GCP)
  • Bug bounty or vulnerability research background
  • Experience building offensive security tooling in controlled environments

What We Value

We are looking for someone who understands how modern attacks work at a deep technical level — not simply someone who knows how to run automated security tools.

The ideal candidate can think like an attacker, develop their own tooling when necessary, understand complex attack chains, and translate offensive findings into meaningful security improvements.

All offensive security activities are conducted exclusively within authorized systems and controlled environments.

About this job listing
This job opportunity is provided through our external job listing network. MyJobAlerts helps you discover job opportunities and redirects you to the original listing to apply.