Pessoa Coordenadora de Segurança Ofensiva (Red Team)
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Pessoa Coordenadora de Segurança Ofensiva (Red Team) based in Brazil.
This is a remote, full-time leadership opportunity focused on strengthening offensive cybersecurity capabilities across a complex technology environment.
You will lead the planning and coordination of realistic cyberattack simulations, penetration tests, and advanced threat emulation activities.
The role combines Red Team leadership with responsibility for vulnerability management and application security initiatives.
You will continuously assess the organization’s attack surface, prioritize risks, and validate the effectiveness of preventive, detective, and responsive security controls.
Working across offensive, defensive, engineering, architecture, and governance teams, you will help embed security into technology and software development practices.
You will also develop technical talent, establish performance indicators, and drive continuous improvements across security programs.
The position offers the opportunity to shape cybersecurity strategy while helping protect sensitive assets and support regulatory and organizational requirements.
Accountabilities:
- Offensive Security Leadership: Plan, coordinate, and supervise offensive security campaigns, including penetration testing, Red Team operations, and controlled simulations of advanced persistent threats, ensuring all activities are ethical, secure, controlled, and aligned with corporate policies.
- Security Methodologies and Operations: Develop, implement, and continuously improve methodologies, processes, and tools for offensive security operations while keeping practices aligned with emerging threats, tactics, techniques, and industry standards.
- Vulnerability Management: Coordinate infrastructure vulnerability management programs, ensuring adequate coverage of critical technology assets and establishing strategies for vulnerability identification, classification, prioritization, remediation, and ongoing tracking.
- Application Security: Coordinate application and secure-code vulnerability management throughout the software development lifecycle, promoting Application Security, DevSecOps, Secure by Design, and Secure Coding practices across development teams.
- Security Validation: Continuously assess technical vulnerabilities, process weaknesses, and security control gaps while validating the effectiveness of preventive, detective, and responsive controls through offensive and Purple Team activities.
- Attack Surface Monitoring: Monitor the organization’s cyber exposure across on-premises and cloud environments, networks, operating systems, databases, applications, and other technology assets, ensuring risks are identified and addressed according to business impact.
- Risk Metrics and Governance: Define and monitor KPIs, maturity metrics, remediation SLAs, and other performance indicators for Red Team, Vulnerability Management, and AppSec programs, providing clear reporting to relevant stakeholders.
- Team Development: Coordinate, develop, and coach the Offensive Security team, encouraging technical growth, knowledge sharing, collaboration, and integration with other cybersecurity and technology functions.
- Regulatory and Audit Support: Support regulatory processes, internal and external audits, compliance assessments, and other governance activities by providing relevant technical information and evidence related to cybersecurity controls and practices.
- Security Culture: Promote cybersecurity awareness across the organization and encourage the adoption of stronger security practices through collaboration, knowledge sharing, and continuous improvement.
- Education: Completed higher education in Information Technology, Computer Science, Information Systems, Engineering, or a related field, with a completed postgraduate qualification in Technology, Information Security, Cybersecurity, Management, or a related discipline considered desirable.
- Offensive Security Experience: Solid professional experience in cybersecurity with a focus on Offensive Security, Red Team, penetration testing, or threat emulation, including experience planning and structuring offensive security operations.
- Leadership Experience: Demonstrated experience leading technical teams and developing cybersecurity professionals, with the ability to coordinate multidisciplinary initiatives and foster technical excellence.
- Vulnerability and AppSec Programs: Experience coordinating Vulnerability Management and/or Application Security programs, including vulnerability prioritization, remediation tracking, and integration of security practices into software development.
- Offensive Security Knowledge: Strong knowledge of penetration testing, defense evasion, controlled attack simulations, Purple Team activities, MITRE ATT&CK, and Attack Surface Management.
- Application Security: Familiarity with application security architecture, SSDLC, DevSecOps, OWASP Top 10, API security, SAST, DAST, SCA, IAST, and CI/CD pipeline security.
- Infrastructure and Cloud Security: Knowledge of Windows and Linux operating systems, Active Directory and Microsoft environments, corporate networks and communication protocols, cloud security across Azure, AWS and/or GCP, containers, and Kubernetes.
- Certifications: OSCP, OSEP, and OSWE certifications are desirable and demonstrate relevant offensive security expertise.
- Strategic and Behavioral Skills: Strong leadership and people-development capabilities, strategic cybersecurity risk awareness, influencing and negotiation skills, analytical and investigative thinking, risk-based decision-making, results orientation, collaboration, adaptability, and continuous learning.
- Work Arrangement: Full-time remote position for professionals based in Brazil.
- Meal and Food Support: Food and meal allowance to support everyday expenses.
- Home Office Support: Monthly financial assistance for professionals working remotely or under a hybrid arrangement.
- Childcare Support: Monthly reimbursement for eligible daycare, preschool, or babysitting expenses.
- Mobility Assistance: Financial support for transportation-related expenses.
- Profit Sharing: Participation in a results-based compensation program.
- Life Insurance: Corporate life insurance providing additional financial protection and security.
- Private Pension: Employer-supported private pension program to help employees plan for the future.
- Healthcare: Medical and dental coverage available for employees and their dependents.
- Professional Development: Access to an English-learning platform to support personal and professional development.
- Wellness Support: Access to Wellhub for gyms and studios across the country, as well as Zenklub for psychological support and self-development resources for employees and dependents.
- Additional Time Off: Birthday day off and a day off during the month of an employee’s child’s birthday.
- Seasonal Benefit: Christmas allowance designed to support a special end-of-year celebration.
- Extended Parental Leave: 180 days of maternity leave and 20 days of paternity leave.
- Inclusive Workplace: A work environment committed to diversity, inclusion, accessibility, and equal opportunities.
Requirements
Benefits
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1