CloudWalk, Inc.

Offensive Security Engineer

CloudWalk, Inc.  •  São Paulo, BR (Remote)  •  1 month ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

About the Role

This is not a traditional pentesting role. At CloudWalk, you’ll go beyond running scans or writing reports. You’ll break into systems, exploit real weaknesses, and then engineer automations and agents to make sure those classes of vulnerabilities never come back. Your work will directly shape how CloudWalk defends itself at scale, turning offensive security knowledge into defensive engineering. You’ll be part of a team that blends red teaming, mobile/web pentesting, and security automation. If you enjoy moving fast, exploiting hard problems, and coding the solutions, this role is for you.

What You'll Do

  • Break things that matter. Pentest applications across our stack, identifying vulnerabilities in APIs, mobile apps (Android/iOS), and infrastructure before attackers do.
  • Run red team operations. Plan and execute realistic attack campaigns: phishing with custom domains, social engineering, lateral movement, privilege escalation. Measure real organizational resilience, not checkbox compliance.
  • Build offensive tooling. Engineer security platforms, scanning pipelines, and automation that multiply the team's impact.
  • Weaponize AI for defense. Design and build LLM-powered agents that detect, classify, triage and fix vulnerabilities in real time.     

What We're Looking For

  • Strong knowledge of common vulnerabilities, exploitation techniques, and secure coding practices. You can find bugs in source code, not just with a proxy.                 
  • Experience with web application and API pentesting. Mobile pentesting (Android/iOS) is a strong plus.
  • You code daily. Proficiency in Typescript, Go, or similar, not just scripts, but tools and services others can rely on.                                                    
  • Familiarity with cloud infrastructure security (GCP/AWS/Azure), Kubernetes, and service mesh concepts.
  • Understanding of CI/CD pipelines and how to embed security checks into them.                                                                                               
  • Experience leveraging LLMs or AI agents for security tasks.
  • Excellent communication and collaboration skills to work effectively with engineering teams.     

Bonus Points

  • Experience with red team operations: phishing infrastructure, social engineering, C2 frameworks.                                                                           
  • Familiarity with payment industry security (PCI DSS, card tokenization, acquiring flows).                                                                                  
  • Experience building security platforms or internal tooling (dashboards, bots, vulnerability management systems).                                                           
  • Contributions to open source security tools, published security research or CTFs.       
Join us at CloudWalk, where we're not just engineering solutions; we're building a smarter, AI-driven future for payments and credittogether.
CloudWalk, Inc.

About CloudWalk, Inc.

CloudWalk is a technology company that empowers individuals and small businesses to manage money seamlessly. The company pioneers AI- and blockchain-driven financial solutions through its flagship brands: InfinitePay in Brazil and JIM.com in the U.S., offering digital accounts, Tap to Pay, instant payments, and business growth tools.

By 2024, CloudWalk scaled to $562 million in annualized revenue, tripled its seller base, and achieved nearly $1 million in revenue per employee—placing it among the world’s most efficient fintechs.

Backed by top investors—including Coatue, DST, A*, The Hive, The Light Capital, and Plug and Play Ventures—CloudWalk has raised over $365 million since its founding, fueling its global expansion.

Industry
Unknown
Company Size
501-1,000 employees
Headquarters
São Paulo, BR
Year Founded
2013
Social Media