Senior Vulnerability Resercher - Cybersecurity Company

Posted 10 Days Ago
Be an Early Applicant
Hiring Remotely in São Paulo, BRA
In-Office or Remote
Senior level
Information Technology • Software
The Role
The role involves researching vulnerabilities in web applications, automating testing logic, and collaborating with engineering teams to enhance security measures.
Summary Generated by Built In
About Truelogic

At Truelogic we are a leading provider of nearshore staff augmentation services headquartered in New York. For over two decades, we’ve been delivering top-tier technology solutions to companies of all sizes, from innovative startups to industry leaders, helping them achieve their digital transformation goals.

Our team of 600+ highly skilled tech professionals, based in Latin America, drives digital disruption by partnering with U.S. companies on their most impactful projects. Whether collaborating with Fortune 500 giants or scaling startups, we deliver results that make a difference.

By applying for this position, you’re taking the first step in joining a dynamic team that values your expertise and aspirations. We aim to align your skills with opportunities that foster exceptional career growth and success while contributing to transformative projects that shape the future.

Our Client

A hypergrowth cybersecurity startup focused on building advanced Agentic Red Team capabilities. Their platform automates offensive security techniques to help organizations continuously identify vulnerabilities, attack paths, and security gaps across modern environments.

Designed for mid-market and enterprise organizations, the platform enables security teams to proactively strengthen their defenses through scalable, automated security testing and intelligent attack simulation.


Job Summary

We are looking for a highly skilled Vulnerability Researcher to identify real-world security vulnerabilities across modern web applications and translate those findings into scalable, automated testing logic.

This role combines hands-on offensive security expertise with an automation-focused mindset. You’ll work on replicating sophisticated attack scenarios at scale, helping evolve the platform’s automated red team capabilities.

You’ll collaborate closely with engineering and product teams to improve detection logic, expand testing coverage, and continuously enhance the platform’s offensive security engine.

Responsibilities
  • Perform security research on web applications, APIs, and complex application workflows.

  • Identify, validate, and reproduce real-world vulnerabilities in modern applications.

  • Analyze authentication, authorization, session management, and access control mechanisms.

  • Translate manual penetration testing techniques into automated detection and exploitation logic.

  • Develop and refine payloads, exploit strategies, and vulnerability validation methods.

  • Analyze HTTP traffic, browser behavior, and application flows to uncover security weaknesses.

  • Collaborate with engineering teams to improve the platform’s automation and offensive security capabilities.

  • Document findings clearly, including technical details, impact analysis, and reproduction steps.

Qualifications and Job Requirements
  • 5+ years of hands-on experience in vulnerability research, penetration testing, bug bounty programs, or offensive security.

  • Strong expertise in web application and API security.

  • Deep understanding of Authentication and authorization flows; JWT, OAuth, SSO, sessions, and cookies; Access control vulnerabilities and privilege escalation.

  • Proven experience identifying vulnerabilities (IDOR / BOLA, Business logic flaws, Authentication bypasses, Privilege escalation vulnerabilities).

  • Experience using offensive security tools (Burp Suite, Postman, curl, Browser DevTools).

  • Ability to analyze and manipulate HTTP requests/responses and application behavior.

  • Scripting experience with Python or JavaScript.

  • Experience converting manual pentesting workflows into automated testing logic.

  • Strong communication and documentation skills.

  • Conversational English proficiency.

  • Must be located in Latin America.

Nice to have
  • Strong Python development skills.

  • Experience with browser automation (Playwright, Selenium, Puppeteer).

  • Experience with GraphQL, gRPC, WebSockets, and mobile APIs.

  • Exposure to cloud security environments.

  • Familiarity with AI-driven security or automated exploitation workflows.

  • Familiarity with tools such as Nuclei or custom vulnerability scanners.

What We Offer
  • 100% Remote Work: Enjoy the freedom to work from the location that helps you thrive. All it takes is a laptop and a reliable internet connection.

  • Highly Competitive USD Pay: Earn an excellent, market-leading compensation in USD, that goes beyond typical market offerings.

  • Paid Time Off: We value your well-being. Our paid time off policies ensure you have the chance to unwind and recharge when needed.

  • Work with Autonomy: Enjoy the freedom to manage your time as long as the work gets done. Focus on results, not the clock.

  • Work with Top American Companies: Grow your expertise working on innovative, high-impact projects with Industry-Leading U.S. Companies.

Why You’ll Like Working Here
  • A Culture That Values You: We prioritize well-being and work-life balance, offering engagement activities and fostering dynamic teams to ensure you thrive both personally and professionally.

  • Diverse, Global Network: Connect with over 600 professionals in 25+ countries, expand your network, and collaborate with a multicultural team from Latin America.

  • Team Up with Skilled Professionals: Join forces with senior talent. All of our team members are seasoned experts, ensuring you're working with the best in your field.

Apply now!

Skills Required

  • 5+ years of experience in vulnerability research, penetration testing, bug bounty programs, or offensive security
  • Strong expertise in web application and API security
  • Deep understanding of authentication and authorization flows
  • Proven experience identifying vulnerabilities such as IDOR/BOLA
  • Experience using offensive security tools
  • Scripting experience with Python or JavaScript
  • Experience converting manual pentesting workflows into automated logic
  • Strong communication and documentation skills
  • Conversational English proficiency
  • Must be located in Latin America
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
266 Employees
Year Founded: 2003

What We Do

Truelogic Software is a Nearshore tech firm specializing in Staff Augmentation Services and Innovation Projects. We build innovative digital products by extending the engineering teams of US companies with our elite group of 500 Latin American highly experienced tech talent. Our SERVICES Staff Augmentation Services Dedicated Agile Teams Innovation Projects Our EXPERTISE Mobile & Web Development Data Engineering DevOps QA Automation & Testing UX/UI Designing Project Management Email us [email protected]

Similar Jobs

Luxury Presence Logo Luxury Presence

Staff Data Engineer

Marketing Tech • Real Estate • Software • PropTech • SEO
Easy Apply
Remote or Hybrid
12 Locations
500 Employees

Mondelēz International Logo Mondelēz International

Consultant

Big Data • Food • Hardware • Machine Learning • Retail • Automation • Manufacturing
Remote or Hybrid
Brazil
90000 Employees

CrowdStrike Logo CrowdStrike

Technical Support

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
Brazil
10000 Employees

CrowdStrike Logo CrowdStrike

Sales Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
Brazil
10000 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York City, NY
100 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account