Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Security Technologist - Offensive/Pentester

AT Uber
Uber

Security Technologist - Offensive/Pentester

São Paulo, Brazil

Uber's Product Security organization is looking for a penetration tester to join our Offensive Security team. As a member of our in-house pen-test team, your principle mission will be to conduct offensive pen-testing activities against our microservices, applications, infrastructure and data-layer services. You will work closely with our engineering groups to define pen-test scope, lead assessment engagements, and map assessment findings into engineering plans of action for remediation, ultimately guiding our product security uplift activities. This is a unique opportunity for an experienced offensive pen-tester who is collaborative, and has a healthy sense of curiosity to join Uber Engineering Security to make real positive impacts to our security posture, and help us improve our security designs in our next-gen of systems and services.

Want more jobs like this?

Get Software Engineering jobs in São Paulo, Brazil delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.


--- What the Candidate Will Do ----

  • Conduct white-box and grey-box offensive penetration testing against Uber's mobile applications, front-end & back-end microservices and web services
  • Conduct network infrastructure, Public Cloud (AWS and GCP), and data-layer offensive pen-testing
  • Perform mobile reverse engineering and/or mobile instrumentation of mobile application products as needed to deliver mobile security assessments.
  • Perform manual source code reviews and audits (manual and SCA/SAST code audits) as needed
  • Be a subject matter expert and ambassador to Uber Engineering for secure coding practices, penetration testing, mobile platform security and all aspects of application and product security
  • Perform any other application security or product security related activities or tasks as needed or directed
  • Validate 3rd party external pen-test and crowd-sourced application security findings and work with our Appsec team to triage those across to our engineering teams

---- Basic Qualifications ----

  • A pen-test certification such as Offensive Security Certified Professional (OSCP) or CEH, OSWE, OSCE, GPEN, GMOB, GWAPT, GXPN, eWAPT, eMAPT and/or willing to work towards ultimately obtaining one as part of your career path
  • 3+ years of relevant engineering or security assessment experience
  • Possess a broad knowledge of attack vectors, exploits and mitigations that work at scale or may be linked together for chained attacks
  • Experience with assessing with Cloud-native services, service meshes, and Kubernetes-platform based microservices
  • Experience with assessment of mobile-based applications (not just web/UI)
  • Be able to apply unconventional thinking and problem-solve on the boundary of your knowledge base, learning new technologies or languages as needed to complete pen-test tasks
  • Be able to think both offensively (like a hacker) and defensively (evaluating product security and design)
  • Ability to create written work product, detailed technical findings documents, and pen-test reports
  • Ability to create and write scripts to automate redundant activities
  • Great interpersonal skills, deep technical ability, and a history of successful execution in the assessments industry. If you enjoy discussing anything from procedural linking tables in kernels to remote code execution in JVMs, then we want you on the team
  • Experience with Java, Go, Python or Node.js (bonus points for more than one)
  • Familiarity with industry-standard threat modeling, risk modeling and vulnerability classification.
  • Experience with pre-assessment architectural and API analysis to scope and prepare white-box and grey-box assessments.
  • Experience working with in-house engineering organizations, S-SDLC/CICD software lifecycle and QA processes.
  • Experience with mobile reverse engineering and penetration testing.
  • Experience with CLI offensive security tooling.

We welcome people from all backgrounds who seek the opportunity to help build a future where everyone and everything can move independently. If you have the curiosity, passion, and collaborative spirit, work with us, and let's move the world forward, together.

Offices continue to be central to collaboration and Uber's cultural identity. Unless formally approved to work fully remotely, Uber expects employees to spend at least half of their work time in their assigned office. For certain roles, such as those based at green-light hubs, employees are expected to be in-office for 100% of their time. Please speak with your recruiter to better understand in-office expectations for this role.

*Accommodations may be available based on religious and/or medical conditions, or as required by applicable law. To request an accommodation, please reach out to accommodations@uber.com.

Client-provided location(s): São Paulo, State of São Paulo, Brazil
Job ID: Uber-127001
Employment Type: Full Time

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Health Reimbursement Account
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • FSA With Employer Contribution
    • Fitness Subsidies
    • On-Site Gym
    • Mental Health Benefits
  • Parental Benefits

    • Fertility Benefits
  • Work Flexibility

    • Flexible Work Hours
    • Remote Work Opportunities
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Casual Dress
    • Pet-friendly Office
    • Snacks
    • Some Meals Provided
    • On-Site Cafeteria
  • Vacation and Time Off

    • Paid Vacation
    • Unlimited Paid Time Off
    • Paid Holidays
    • Personal/Sick Days
    • Sabbatical
    • Volunteer Time Off
  • Financial and Retirement

    • 401(K)
    • Company Equity
    • Performance Bonus
  • Professional Development

    • Work Visa Sponsorship
    • Associate or Rotational Training Program
    • Promote From Within
    • Mentor Program
    • Access to Online Courses
  • Diversity and Inclusion

    • Employee Resource Groups (ERG)
    • Diversity, Equity, and Inclusion Program