Point your AI agent at freehire and let it find you a job.

Get the CLI →

Staffy

NewBe an early applicant

Pentester

Posted
Discussion

Summary

Senior penetration tester who leads end-to-end offensive security assessments across cloud environments (AWS, Azure, GCP, Kubernetes) and modern web applications/APIs, builds AI/LLM-powered tooling to automate pentest workflows, and partners with DevOps and SRE teams to strengthen the SSDLC.

About the company

We are a young and fast-growing technology company with five years of experience working across Latin America and the United States. We work closely with teams and founders to help them build strong, high-impact teams through recruiting, outsourcing, and team-building services.

Our culture is based on effective communication, trust, and transparency. We believe the best work happens when people feel heard, supported, and empowered to grow. Today, more than 80 professionals across the region work remotely on challenging projects, collaborating and learning from each other every day.

About the role

We are looking for a Senior Pentester with strong hands-on experience in cloud security and web application penetration testing, capable of leading complex security assessments end-to-end.

The ideal candidate combines deep technical expertise, adversarial thinking, and practical experience using AI, LLMs, and AI agents to automate, scale, and enhance penetration testing workflows.

You will also work closely with Engineering, DevOps, and SRE teams to strengthen the Secure Software Development Lifecycle (SSDLC) and continuously improve the security posture of products and platforms.

Responsibilities

  • Execute and lead advanced penetration tests across AWS, Azure, and/or GCP environments, including Kubernetes, serverless, IAM, storage, networking, and CI/CD pipelines
  • Conduct security assessments of modern web applications, REST/GraphQL APIs, and distributed architectures
  • Define testing plans, scope, effort estimates, and assessment strategies, driving engagements autonomously from planning through delivery
  • Identify, exploit, and document complex vulnerabilities, including business logic flaws, vulnerability chains, misconfigurations, and authentication bypasses
  • Produce high-quality technical and executive reports, including risk and severity assessments, reproducible evidence, and clear, actionable remediation guidance
  • Present findings and conduct technical and executive debriefs with both technical and non-technical stakeholders
  • Build and integrate AI agents and LLM-based solutions to enhance penetration testing activities, including reconnaissance, discovery, analysis, exploitation assistance, payload generation, fuzzing, and reporting
  • Develop custom scripts and tooling to automate security tasks and improve assessment efficiency
  • Partner with DevOps, SRE, and Product teams to incorporate security practices earlier in the development lifecycle
  • Contribute to cloud hardening, preventive security controls, and continuous SSDLC improvements.
  • Stay current with emerging threats, offensive techniques, cloud security, and AI security trends

Requirements

  • 5+ years of experience in Offensive Security / Penetration Testing, with a strong focus on cloud security and web applications
  • Hands-on experience with Cloud Penetration Testing across AWS, Azure, and/or GCP, including IAM abuse, privilege escalation, misconfigurations, lateral movement, container/Kubernetes security, and secrets exposure
  • Strong experience in Web Application Penetration Testing, including OWASP Top 10, ASVS, business logic testing, and REST/GraphQL API security
  • Strong hands-on experience with offensive security tools such as Burp Suite Pro, Nmap, Nessus/Qualys, Metasploit, sqlmap, ffuf, Nuclei, and/or ZAP, as well as cloud-native tools such as AWS/Azure/GCP CLIs, ScoutSuite, Prowler, CloudSploit, kube-bench, and Trivy
  • Ability to develop custom security tooling and automation using Python, Bash, and/or Go
  • Strong knowledge of the SSDLC, including threat modeling, secure coding practices, SAST, DAST, IAST, and CI/CD security controls
  • Practical experience using AI, LLMs, or AI agents as part of penetration testing or offensive security workflows
  • Ability to independently manage and lead security assessments from planning through final delivery
  • Excellent written and verbal communication skills, with the ability to communicate technical findings and security risks to both technical and business stakeholders

Nice to have

  • Certifications such as OSCP, OSWE, OSEP, GXPN, GPEN, AWS Security Specialty, or equivalent
  • Experience with Mobile Penetration Testing across iOS and/or Android
  • Experience with Red Teaming or Purple Teaming
  • Knowledge of GenAI Security, including prompt injection, model exploitation, and RAG security
  • Experience with CI/CD and DevSecOps ecosystems, including GitHub Actions, GitLab, Jenkins, and/or ArgoCD from an offensive security perspective
  • Experience working with application and product security in large-scale cloud environments

Benefits

  • Beneficios por conectividad
  • Capacitaciones y certificaciones a cargo de la empresa
  • Prepaga de primer nivel
  • Dia de cumple free
  • Plan de carrera personalizado / capacitación constante
  • Kit de Bienvenida
  • Convenios para descuentos especiales junto a Unilever, Tienda Molinos y otras, Descuentos en formación junto a Siglo 21 y Coderhouse

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available