CxSC - Systems Specialist I (Cybersecurity - PenTester)

InatelSanta Rita do Sapucaí, Minas Geraisgupypublished 08/10/2026
Must-have:CI/CDSecurity
Machine translation — original language: Portuguese.Show original

The specialist shall perform functions related to PenTests within the Cybersecurity Center - CxSC. In addition to actively working on security tests, the specialist shall coordinate actions with CxSC interns, which consists of: 1) promoting actions that can be performed by interns in the scope of PenTests and 2) promoting technical training for the formation of interns in various areas of cybersecurity.

Responsibilities and assignments

  • Completed degree in Telecommunications Engineering, Computer Engineering, Information Security, or related areas.
  • Proven experience in vulnerability analysis and penetration testing (Pentest) in Web applications, APIs, networks, and infrastructure.
  • Advanced knowledge in security testing methodologies, such as OWASP Testing Guide.
  • Knowledge in manual vulnerability analysis, with the ability to identify, exploit, and validate vulnerabilities without exclusive dependence on automated tools.
  • Experience in secure code analysis (SAST), dynamic analysis (DAST), and security testing in complex environments.
  • Mastery of offensive security and vulnerability analysis tools, such as Burp Suite, Nmap, Metasploit, Wireshark, among others.
  • Solid knowledge of Windows and Linux operating systems, TCP/IP networks, and communication protocols.
  • Experience in preparing technical and executive vulnerability reports and mitigation recommendations.
  • Ability to review, document, and improve processes, methodologies, and technical procedures.
  • Experience in technical guidance, review of deliverables, and support for the development of less experienced professionals.
  • Technical English for reading documentation, standards, and specialized publications.
  • Intermediate knowledge of Information Security standards, frameworks, and best practices (such as ISO/IEC 27001, NIST, CIS Controls, and OWASP).
  • Knowledge in team management and coordination, including activity planning, demand distribution, performance monitoring, and effective communication with different areas of the organization.
  • Ability to actively contribute to the definition and evolution of the cybersecurity analysis methodology applied to telecommunications equipment, systems, networks, and applications, IT, and related areas.

Desirable:

  • Certifications in the Information Security area, such as CompTIA Security+, CEH, eJPT, PNPT, OSCP, among other relevant certifications.
  • Knowledge in secure development and code review with a focus on vulnerability identification.
  • Knowledge in DevSecOps, CI/CD pipelines, and integration of security tests into the development cycle.

Requirements and qualifications

  • OWASP Testing Guide
  • Burp Suite, Nmap, Metasploit, Wireshark, among others.
  • Windows and Linux, TCP/IP networks, and communication protocols
  • ISO/IEC 27001, NIST, CIS Controls, and OWASP