freehire launches on Product Hunt on 26 August.

Follow →

Offensive Security Specialist

Summary

Conducts penetration testing and security assessments on web apps, APIs, and infrastructure using manual techniques and AI-assisted tools. Requires offensive security expertise, scripting capabilities, and strong communication skills.

We're fast learners, hard workers, natural collaborators... and we Make Modern Happen!

Our ambition is to unlock the potential of our digital world so that organisations everywhere can innovate and thrive securely.

We aim to achieve this goal by bringing together the world’s most talented people and the most powerful technologies, combining them to address our customers' challenges and to build something stronger together.

If you share our vision, join us!

Right now, we are looking for a Offensive Security Specialist to integrate our internal team, based in Porto.


Your responsibilities include:

  • Perform penetration testing and technical security assessments across web applications, APIs, cloud environments, and internal/external infrastructure (including Active Directory / Entra ID).
  • Go beyond automated scanning through manual investigation, vulnerability validation, and attack-path chaining.
  • Integrate AI-assisted tools (LLMs, coding assistants, agent-based tooling) into offensive workflows to accelerate research, scripting, payload development, and reporting.
  • Develop or adapt custom scripts and offensive security tooling to support specific assessment scenarios.
  • Produce clear, technically sound, and actionable documentation detailing security findings, business impact, and remediation guidance.
  • Collaborate closely with development, infrastructure, and security teams to communicate technical security issues and support remediation efforts.
  • Contribute to the continuous improvement of internal methodologies, knowledge sharing, research, and offensive capabilities.

You must have:

  • Solid practical experience in penetration testing and technical security assessments.
  • Hands-on proficiency with offensive security tooling (such as Burp Suite, Nmap, Metasploit, or equivalent frameworks).
  • Strong working knowledge of web application security (OWASP Top 10, WSTG), API security, network infrastructure, and Active Directory / Entra ID environments.
  • Demonstrated AI fluency: ability to use AI tools as workflow accelerators while maintaining independent technical judgment and critical validation.
  • Scripting or programming capabilities to adapt tools, automate repetitive tasks, and develop custom payloads.
  • High autonomy, proactivity, critical thinking, and problem-solving skills in complex assessment scenarios.
  • Proficiency in English to communicate technical concepts effectively with technical and non-technical stakeholders.

We value:

  • Relevant offensive security certifications such as OSCP, OSWA, OSWE, CRTO, eWPT, or equivalent.
  • Active engagement in CTFs, Bug Bounty programs, security research, or open-source offensive tool development.
  • Strong collaborative mindset with an interest in team-based investigations, pair testing, and knowledge sharing.
We offer:
  • Regular professional development;
  • Certification paths resources;
  • Regular teambuilding programs;
  • Friendly workplace.
Workplace: Porto - Hybrid ( 3 days at office)

Claranet: Make Modern Happen!



See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available