GeekHunter Logo

Plans

Login

EN

EN

Suprema Group

Especialista em Cyber Security | Presencial

On-site

Sorocaba, SP, Brazil

Salary Range

BRL

R$ 22,000.00 - R$ 23,400.00 / month

Contractor

Experience Level

Senior

Requirements

6+ years of experience in the career
Go
AppSec/APIsec
Trivy
Nessus
JavaScript/TypeScript
Burp Suite
Amazon Web Services (AWS)
Nmap
Python
Java
Nuclei

Desired Skills

Kubernetes
Cloudflare WAF
Bug bounty

Tasks and Responsibilities

Show original

We develop high-scale, high-availability, and high-criticality digital products. We are hiring our first dedicated Cyber Security professional to ensure security is built into the architecture from the start.

This is a technical, hands-on role, working alongside the Engineering and Infrastructure teams. You will have the autonomy to define how Cyber Security will be built here.

100% on-site model in Sorocaba - SP

Contractor (PJ) + Benefits

Benefits

  • Health plan;
  • Dental plan;
  • Meal voucher of R$ 31.00 per day;
  • Birthday day off + R$150 bonus.

What you'll do

  • Assess web applications, APIs, and services, identify vulnerabilities, and track remediation with Engineering until validation
  • Participate in the architecture of new products, including threat modeling and review of authentication, authorization, and integrations
  • Review infrastructure security in AWS and Cloudflare (IAM, networks, secrets, WAF) and map the external attack surface
  • Integrate SAST, DAST, SCA, and secret scanning into the development cycle
  • Manage vulnerabilities: run scanners, prioritize by real business impact, and track CVEs affecting our stack
  • Write scripts and automations, analyze logs, and support incident response

You are the right person if

  • You have experience in AppSec, Product Security, Offensive Security, or Security Engineering
  • You identify and exploit vulnerabilities in web applications and APIs (OWASP Top 10 and API Security, OAuth, JWT)
  • You read code and program in JavaScript/TypeScript, Python, Java, Go, or similar
  • You have experience with AWS (IAM, networks, containers, secrets)
  • You use Burp Suite, Nmap, and scanners such as Nessus, Nuclei, or Trivy
  • You can distinguish a theoretically critical vulnerability from a truly exploitable risk, and communicate with developers as an equal

Nice to have

Bug bounty or independent research, Kubernetes and container security, Cloudflare WAF, secure CI/CD, financial or regulated environments, incident response, certifications (OSCP, OSWE, AWS Security Specialty, CISSP)

Share job:

Share job: