Devoteam Cyber Trust | Autonomous Pentesting Engineer
Devoteam
Lisboa
Tempo inteiro
Mais 167 vagas em Lisboa.
Envie seu CV e descubra quais realmente combinam com você.
- A Devoteam Cyber Trust é a unidade especializada em cibersegurança do Grupo Devoteam. Com mais de 800 especialistas localizados na região EMEA, o nosso objetivo é estabelecer a cibersegurança como um facilitador do sucesso dos negócios, em vez de um obstáculo. Utilizamos uma abordagem abrangente de Resiliência Cibernética, Segurança Aplicada e Gestão de Serviços de Segurança para proteger a jornada tecnológica de empresas de grande e média dimensão de todos os setores e indústrias.
Mission
Develop and evolve an autonomous pentesting platform based on agentic systems, integrated within the Offensive Security domain—specifically the Offensive Engineering and Innovation team—ensuring systems are effective, controllable, and capable of producing relevant and reliable outputs in real\-world penetration testing scenarios.
Role Context
- This role sits within the Offensive Engineering and Innovation team, responsible for creating new technical capabilities that extend and scale offensive security services.
- The platform aims to automate significant parts of the pentesting lifecycle, aligned with methodologies such as the OWASP Web Security Testing Guide (WSTG), leveraging agents, LLMs, and integrations with existing security tooling.
- This is not an isolated experimental initiative. It is a production\-oriented capability with direct application in delivery environments.
- Define and evolve the architecture of autonomous pentesting agents
- Develop controlled execution pipelines (tasking, tool usage, feedback loops)
- Design and improve mechanisms for:
+ State management
+ Tool usage orchestration
+ Validation and control of agent execution
- Integrate and optimize LLM\-based systems within agent workflows
- Define and validate tool\-calling interfaces and integrations with pentesting tools
- Ensure alignment with established methodologies (e.g., OWASP WSTG)
- Test and validate agent behavior in real\-world scenarios
- Identify, analyze, and mitigate system failures and edge cases
- Contribute to internal standards, engineering practices, and design patterns
Required
- Strong proficiency in Python
- Experience with APIs and distributed systems
- Practical experience with LLMs (usage, integration, limitations)
- Understanding of agent\-based systems
- Ability to design complex, non\-deterministic systems
- Experience with:
+ State management and execution continuity
+ Tool orchestration
+ Output validation and evidence handling
- Strong debugging capability (deep system\-level troubleshooting)
- Ability to validate system behavior, not only code correctness
- Experience with agent frameworks
- Background in Application Security (AppSec)
- Experience with security testing automation
- Exposure to multiple LLM models and providers
- Strong critical thinking
- Ability to operate in imperfect and evolving systems
- Experimental and outcome\-driven mindset
- Strong focus on control, reliability, and predictability
- High autonomy and ownership
- Agents produce useful, actionable outputs
- Execution is predictable and controllable
- Low rate of unexpected or unsafe behaviors
- Effective integration into real pentesting workflows
- Continuous system evolution without uncontrolled complexity growth
- O que oferecemos:
- Valorização e acompanhamento do talento;
- Aposta no desenvolvimento dos nossos colaboradores;
- Colaboração numa empresa em constante crescimento e evolução;
- Forte cultura organizacional: colaboração, partilha, flexibilidade, integridade e low ego.Gostarias de te juntar à nossa equipa? Então envia o teu CV.
Este anúncio é de indeed. Ver anúncio original ↗