Pen-tester - Product Security
Há 4 dias
What You'll Do:
Avalara's Offensive Security organization is looking for a penetration tester to join our security assessments team. As a member of our in-house pen-test team, your principal mission will be to conduct offensive pen-testing activities against our microservices, applications, infrastructure and data-layer services. You will work closely with our engineering groups to define pen-test scope, lead assessment engagements, and map assessment findings into engineering remediation plans, ultimately guiding our product security uplift activities. This is a unique opportunity for an experienced offensive pen-tester who is collaborative, and has a healthy sense of curiosity to join Avalara Engineering to make real positive impacts to our security posture, and help us improve our security designs in our next-gen of systems and services .
What Your Responsibilities Will Be:
Conduct white-box and grey-box offensive penetration testing against Avalara's applications, microservices and web services
Conduct network infrastructure, Public Cloud (AWS and GCP), AI, and data-layer offensive pen-testing
Perform manual source code reviews and audits (manual and SCA/SAST code audits) as needed to support white-box assessments
Be a subject matter expert and ambassador to Avalara Engineering for secure coding practices, penetration testing, platform security and all aspects of application and product security
Perform any other application security or product security related activities or tasks as needed or directed
Validate 3rd party external pen-test and crowd-sourced application security findings and work with our application security team to triage those across to our engineering teams.
What You'll Need to be Successful:
An Offensive Security Certified Professional (OSCP) certification
5+ years of security assessment experience
Possess a broad knowledge of attack vectors, exploits and mitigations that work at scale or may be linked together for chained attacks
Experience with assessing with Cloud-native services, service meshes, and Kubernetes-platform based microservices
Be able to apply unconventional thinking and problem-solve on the boundary of your knowledge base, learning new technologies or languages as needed to complete pen-test tasks
Be able to think both offensively (like a hacker) and defensively (evaluating product security and design)
Ability to create written work product, detailed technical findings documents, and pen-test reports
Familiarity with industry-standard threat modelling, risk modelling and vulnerability classification
Knowledge of LLM Top-10 and AI hacking experience is a plus
Avalara is an AI-first Company:
AI is embedded in our workflows, decision-making, and products. Success here requires embracing AI as an essential capability.
- You'll bring experience using AI and AI-related technologies, ready to thrive here.
- You'll apply AI every day to business challenges - improving efficiency, contributing solutions, and driving results for your team, our company, and our customers.
- You'll grow with AI by staying curious about new trends and best practices, and by sharing what you learn so others can benefit too.
How We'll Take Care of You:
Total Rewards
In addition to a great compensation package, paid time off, and paid parental leave, many Avalara employees are eligible for bonuses.
Health & Wellness
Benefits vary by location but generally include private medical, life, and disability insurance.
Inclusive culture and diversity
Avalara strongly supports diversity, equity, and inclusion, and is committed to integrating them into our business practices and our organizational culture. We also have a total of 8 employee-run resource groups, each with senior leadership and exec sponsorship.
What You Need To Know About Avalara:
We're defining the relationship between tax and tech.
We've already built an industry-leading cloud compliance platform, processing over 54 billion customer API calls and over 6.6 million tax returns a year. Our growth is real - we're a billion dollar business - and we're not slowing down until we've achieved our mission - to be part of every transaction in the world.
We're bright, innovative, and disruptive, like the orange we love to wear. It captures our quirky spirit and optimistic mindset. It shows off the culture we've designed, that empowers our people to win. We've been different from day one. Join us, and your career will be too.
We're An Equal Opportunity Employer
Supporting diversity and inclusion is a cornerstone of our company — we don't want people to fit into our culture, but to enrich it. All qualified candidates will receive consideration for employment without regard to race, color, creed, religion, age, gender, national orientation, disability, sexual orientation, US Veteran status, or any other factor protected by law. If you require any reasonable adjustments during the recruitment process, please let us know.
-
Senior Penetration Testing Manager
1 semana atrás
Remoto, Brasil Avalara Tempo inteiro R$60.000 - R$120.000 por anoO que você fará:Avalara's Product Security organization is looking for a Penetration Testing Senior Manager to lead our Offensive Security team. In this role you will be responsible for leading a team of highly skilled penetration testers whose mission will be to conduct offensive pen-testing activities against our microservices, applications,...
-
Senior Penetration Testing Manager
Há 4 dias
Remoto, Brasil Avalara Tempo inteiro US$120.000 - US$240.000 por anoWhat You'll Do:Avalara's Product Security organization is looking for a Penetration Testing Senior Manager to lead our Offensive Security team. You will lead a team of accomplished penetration testers whose mission will be to conduct offensive pen-testing activities against our microservices, applications, infrastructure, data-layer and AI-based services....
-
Senior Automation Tester in .NET
Há 8 horas
Remoto, Brasil EPAM Systems Tempo inteiro R$60.000 - R$120.000 por anoWe are looking for a skilled Senior Automation Tester in .NET to become a key member of our team. You will focus on building and maintaining automated testing solutions to ensure our software meets the highest standards of quality and performance. This role is ideal for someone who thrives in a collaborative environment and is committed to delivering...
-
Senior Automation Tester
Há 2 dias
Remoto, Brasil Ci&T Tempo inteiro R$80.000 - R$120.000 por anoWe are tech transformation specialists, uniting human expertise with AI to create scalable tech solutions.With over 7.400 CI&Ters around the world, we've built partnerships with more than 1,000 clients during our 30 years of history. Artificial Intelligence is our reality.We're looking for a Senior Tester who is well versed with automation testing to join...
-
Sales Engineer, Brazil
Há 2 dias
Remoto, Brasil Absolute Software Tempo inteiro R$90.000 - R$120.000 por anoAlthough this role is remote, the ideal candidate will be in Rio De Janeiro or Sao Paulo.Absolute Security is looking for a Sales Engineer (SE) to provide technical sales support as a solution expert within our fast-growing India business. The SE is a highly technical sales professional who is responsible for working with Account Executives (AEs) and Channel...
-
Offensive Security Manager
Há 5 horas
Remoto, Brasil Ambev Tech Tempo inteiro R$80.000 - R$150.000 por anoThe largest brewery in the world has an open position for Senior Cybersecurity Engineer (Red Team). We are looking for a Senior Red Team professional who can operate as an adversary, collaborate with defensive teams and deliver professional penetration testing. You'll be responsible for planning and executing adversary emulation campaigns, conducting...
-
Senior Backend Engineer
1 semana atrás
Remoto, Brasil Ambush Consulting Tempo inteiro R$8.000 - R$15.000 por anoAmbush is a People Company. But what does that mean exactly? It means we care about our people as much as we care about building great products. We take a human-centered approach to identifying, retaining and integrating highly talented, long-term remote people into America's best product and development team.We began our consulting journey in 2015 and have...
-
Regional Sales Engineer
Há 2 dias
Remoto, Brasil CrowdStrike Tempo inteiro R$80.000 - R$120.000 por anoAs a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations. Since 2011, our mission hasn't changed — we're here to stop breaches, and we've redefined modern security with the world's most advanced AI-native platform. Our customers span all industries, and they count on CrowdStrike to...
-
Professional Services Engineer
Há 2 dias
Remoto, Brasil faacc154-ca5c-4143-87bf-d55b760f6f57 Tempo inteiro R$90.000 - R$120.000 por anoBrazil, RemoteNXLog helps companies manage their logs better. We provide a unified platform for log collection, storage, and analysis. We offer versatile solutions to capture high-volume logs from diverse sources, transform log data on the fly, filter, enrich, and route it to other systems to boost business, security, and compliance. We combine the stability...
-
Account Executive, Enterprise
Há 2 dias
Remoto, Brasil Absolute Software Tempo inteiro R$60.000 - R$120.000 por anoAbsolute Security is investing heavily in net new enterprise growth across Latin America. As an Enterprise Account Executive based in Brazil, you will own a greenfield territory and be accountable for closing new logo ARR within the country's largest and most security-conscious organizations — including Fortune 1000 equivalents and regulated sectors like...