Skip to main content
Insight Assurance

Ethical Hacker/Pentester Mid Level (2+ Years) - LATAM

RemoteBrazil, Colombia, Costa Rica +1 more only
Published
Role
Security
Experience
Mid
Company size
Mid-size
Salary not disclosed
Check eligibility

Open to BR, CO, CR, PA only. Set where you work from to check your eligibility.

No BS summary

Mid-level offensive security / red team operator with 2+ years in penetration testing or red team operations. Must be in LATAM countries listed and know scripting, Windows/Linux, Active Directory, cloud environments, and offensive security tools like Cobalt Strike, Metasploit, BloodHound, Impacket, and Burp Suite.

Core skills

Cobalt StrikePenetration TestingRed Teaming

Required skills

Python/PowerShell/BashWindowsLinuxActive DirectoryAWS/Azure/GCPMITRE ATT&CKMetasploitBloodHoundImpacketBurp Suite

What you'll do

  • Plan and execute realistic attack scenarios simulating the tactics, techniques, and procedures (TTPs) of sophisticated threat actors.
  • Design and deliver red team engagements, including physical, social engineering, and cyberattack components.
  • Perform penetration testing of networks, applications, and systems using tools such as Burp Suite, Metasploit, Cobalt Strike, and custom scripts.
  • Bypass defensive controls, including IDS/IPS, firewalls, EDR solutions, and WAFs.
  • Exploit vulnerabilities to achieve and escalate privilege levels while avoiding detection.
  • Prepare detailed reports documenting findings, attack vectors, and recommended mitigation.
  • Present results to both technical and non-technical stakeholders.
  • Collaborate with blue teams to refine incident detection and response capabilities.
  • Guide on improving threat hunting and monitoring strategies.
  • Stay updated on the latest attack techniques, vulnerabilities, and defensive countermeasures.
  • Research and develop new tools, exploits, and methodologies to enhance the red team’s capabilities.

What they require

  • Minimum 2 years in offensive security, penetration testing, or red team operations.
  • Proficient in scripting and automation using Python, PowerShell, Bash, or similar.
  • Strong knowledge of Windows and Linux systems, Active Directory, and cloud environments (AWS, Azure, GCP).
  • Familiarity with modern TTPs (e.g., MITRE ATT&CK framework).
  • Preferred: Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), GIAC Penetration Tester (GPEN), or other relevant certifications.
  • Hands-on experience with Cobalt Strike, Metasploit, BloodHound, Impacket, Burp Suite, and other offensive security tools.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and within a team.
  • Excellent communication skills, both verbal and written.
  • Critical thinking and creativity in approach to security challenges.

Insight Assurance is a global audit firm delivering cybersecurity and compliance audit services across SOC 2, ISO 27001, PCI DSS, HITRUST, CMMC, and FedRAMP frameworks.

🇺🇸 United StatesCybersecurityMid-size
Salary not disclosed