31 Aug
|
Kore Pagamentos
|
New Delhi
31 Aug
Kore Pagamentos
New Delhi
Offensive Security Engineer / Red Team Operator
We are looking for a highly skilled Offensive Security Engineer / Red Team Operator to join our security team.
This is a hands-on technical role for someone with robust experience in penetration testing, adversary simulation, vulnerability research, and offensive security tooling. You will work exclusively within authorized environments to identify weaknesses and help strengthen the security of our applications, infrastructure, APIs, and payment systems.
Responsibilities
- Conduct authorized penetration tests across web applications, APIs, networks, cloud environments, and internal infrastructure
- Perform Red Team exercises and adversary simulations
- Identify, validate, and document security vulnerabilities
- Assess Active Directory and Windows-based environments
- Develop custom offensive security tools and proof-of-concept code for controlled testing environments
- Perform vulnerability research and exploit analysis
- Analyze malicious techniques, malware behavior, and attack chains for defensive research
- Perform reverse engineering and debugging when required
- Evaluate security controls, including endpoint protection and detection mechanisms
- Work closely with engineering teams to reproduce vulnerabilities and implement effective remediation
- Produce clear technical reports detailing findings, impact, evidence, and remediation recommendations
Technical Skills
We are particularly interested in candidates with experience in:
- Penetration Testing
- Red Team Operations
- Adversary Simulation
- Web Application & API Security
- Network Security
- Active Directory Security
- Vulnerability Research
- Exploit Development
- Reverse Engineering
- Malware Analysis
- Windows Internals
- C2 infrastructure and frameworks
- Security automation and custom tooling
Strong programming/scripting skills in one or more of:
- C / C++
- C#
- Python
- PowerShell
- Bash
- Assembly / x86-64 knowledge is a strong plus
Certifications
The following certifications are highly desirable:
- OSCP — Offensive Security Certified Qualified
- OSEP — Offensive Security Experienced Penetration Tester
- OSWE — Offensive Security Web Expert
- CRTO / CRTO II — Certified Red Team Operator
- eCPPT / eCPTX
- GPEN
- GWAPT
Equivalent hands-on experience will also be considered.
Nice to Have
- Experience in fintech, banking, or payment infrastructure
- Knowledge of Pix and Brazilian payment systems
- Experience securing high-volume APIs and financial applications
- Cloud security experience (AWS, Azure, or GCP)
- Bug bounty or vulnerability research background
- Experience building offensive security tooling in controlled environments
What We Value
We are looking for someone who understands how modern attacks work at a deep technical level — not simply someone who knows how to run automated security tools.
The ideal candidate can think like an attacker, develop their own tooling when necessary, understand complex attack chains, and translate offensive findings into meaningful security improvements.
All offensive security activities are conducted exclusively within authorized systems and controlled environments.
📌 Penetration Tester (New Delhi)
🏢 Kore Pagamentos
📍 New Delhi