Search...

Offensive Security Engineer

CloudWalk, Inc. logo
CloudWalk, Inc.

CloudWalk is a financial technology company that operates AI-powered payment and financial services. Its products serve Brazilian sellers and consumers as well as U.S. small and solo entrepreneurs, offering payments, credit, storefronts, financial-management assistance, and customer support.

São Paulo, BR
About CloudWalk, Inc.

CloudWalk operates AI-native financial services and payment products, including InfinitePay for Brazilian sellers, JIM for U.S. microbusinesses, and Pierre, an AI financial agent for consumers in Brazil. It applies AI to credit scoring, fraud detection, customer support, and operational workflows. The company also develops Stratus, an open-source, Ethereum-compatible permissioned blockchain for global payment networks, financial institutions, developers, and enterprises.

View jobs by CloudWalk, Inc.

Skills

About the Role

You will actively pentest applications across the stack, finding vulnerabilities in APIs, mobile apps (Android/iOS) and infrastructure before attackers do. You will plan and execute red team campaigns including phishing, social engineering, lateral movement and privilege escalation. You will build offensive tooling, scanning pipelines and automation to scale impact. You will design and implement LLM-powered agents that detect, classify, triage and remediate vulnerabilities in real time.

Requirements

  • Strong knowledge of common vulnerabilities, exploitation techniques and secure coding practices
  • Experience with web application and API penetration testing
  • Mobile penetration testing (Android/iOS) is a strong plus
  • Proficiency in TypeScript, Go or similar for building tools and services
  • Familiarity with cloud infrastructure security (GCP, AWS, Azure), Kubernetes and service mesh concepts
  • Understanding of CI/CD pipelines and embedding security checks into them
  • Experience leveraging LLMs or AI agents for security tasks
  • Excellent communication and collaboration skills

Responsibilities

  • Pentest applications across the stack and identify vulnerabilities in APIs, mobile apps and infrastructure
  • Plan and execute red team operations including phishing, social engineering, lateral movement and privilege escalation
  • Build offensive tooling, security platforms, scanning pipelines and automation
  • Design and implement LLM-powered agents to detect, classify, triage and fix vulnerabilities in real time