热门公司

NXP Semiconductors
NXP Semiconductors

Leading company in the semiconductor industry

Red Team PenTester

职能DevOps
级别中级
地点Guadalajara, Mexico
方式现场办公
类型全职
发布2个月前
立即申请

必备技能

Python

Java

JavaScript

AWS

Linux

GCP

Azure

About the Role We’re seeking a highly skilled Penetration Tester with hands-on offensive security experience to join our growing security team. In this role, you will assess the security posture of web applications, networks, cloud platforms, and internal infrastructures through realistic attack simulations.
This position is ideal for someone who enjoys challenging technical work, thrives in hands-on exploitation, and can translate findings into clear, risk-based guidance for both technical and non-technical audiences.

  • Key Responsibilities•Perform web application, API, network, and infrastructure penetration tests
  • Identify, exploit, and document security vulnerabilities in real-world scenarios
  • Conduct manual testing beyond automated scanners
  • Execute adversary-style attack chains (lateral movement, privilege escalation, AD abuse)
  • Perform source code reviews (where applicable)
  • Assess cloud environments (AWS, Azure, GCP) for common configuration and architectural weaknesses
  • Produce high-quality reports with clear technical detail and business impact
  • Present findings and remediation guidance to engineering and management teams
  • Support remediation, mitigation validation, and retesting
  • Stay current with vulnerabilities, exploit techniques, TTPs, and offensive security research

Required Skills & Experience:

  • Technical Skills•3+ years of hands-on penetration testing / offensive security experience

  • Strong understanding of:
    o Web vulnerabilities (OWASP Top 10, API security issues)
    o Internal network and infrastructure attack techniques
    o Active Directory exploitation (Kerberoasting, delegation abuse, ACL misconfigurations, NTLM relay)
    o Privilege escalation on Windows and Linux

  • Experience using core offensive tools:
    o Burp Suite, Nmap, Metasploit
    o Blood Hound, Crack Map Exec, Impacket

  • Solid understanding of foundational concepts:
    oTCP/IP, DNS, HTTP(S)
    o Authentication (Kerberos, NTLM, OAuth2, SSO)

  • Comfortable working in:
    o Linux & Windows environments
    oBash, PowerShell, and basic Python scripting

  • Strong reporting skills (technical clarity + business impact)

  • Soft Skills

  • Excellent verbal and written communication skills

  • Ability to explain risks to both technical and non-technical stakeholders

  • Self-driven, curious, and proactive

  • Effective time management across multiple engagements

  • Professional client-facing demeanor

  • Nice to Have

  • Certifications: OSCP, PNPT, CRTO, OSWE

  • Red Team / adversary simulation experience

  • Cloud penetration testing experience

  • Source code review skills (Java, C#, Python, JavaScript)

  • Threat modeling and attack path analysis

  • Experience with EDR/AV evasion techniques (ethical/lab settings)

More information about NXP in Mexico...

浏览量

0

申请点击

0

Mock Apply

0

收藏

0

关于NXP Semiconductors

NXP Semiconductors

NXP Semiconductors produces secure connectivity solutions for embedded applications.

10,001+

员工数

Eindhoven

总部位置

$45B

企业估值

评价

10条评价

3.7

10条评价

工作生活平衡

3.5

薪酬

4.0

企业文化

3.8

职业发展

3.2

管理层

3.0

72%

推荐率

优点

Supportive management and colleagues

Innovation and interesting technology

Good work-life balance and flexible hours

缺点

Management issues and poor communication

Limited career advancement and training

Heavy workload and long hours

薪资范围

227个数据点

Junior/L3

Intern

L3

Junior/L3 · Data Scientist

0份报告

$114,000

年薪总额

基本工资

$99,000

股票

-

奖金

$15,000

$96,900

$131,100

面试评价

42条评价

难度

3.1

/ 5

时长

14-28周

录用率

33%

体验

正面 69%

中性 13%

负面 18%

面试流程

1

Phone Screen

2

Technical Interview

3

Hiring Manager

4

Team Fit

常见问题

Technical skills

Past experience

Team collaboration

Problem solving