TL;DR
Red Team PenTester (Cybersecurity): Assessing the security posture of web applications, networks, and cloud platforms through realistic attack simulations with an accent on hands-on exploitation and translating findings into clear, risk-based guidance. Focus on identifying and exploiting security vulnerabilities in real-world scenarios and executing adversary-style attack chains.
Location: Onsite in Guadalajara, Mexico
Company
NXP Semiconductors N.V. enables a smarter, safer, and more sustainable world through innovation as a world leader in secure connectivity solutions for embedded applications.
What you will do
- Perform web, API, network, and infrastructure penetration tests.
- Identify, exploit, and document security vulnerabilities.
- Conduct manual testing and execute adversary-style attack chains (lateral movement, privilege escalation, AD abuse).
- Perform source code reviews and assess cloud environments (AWS, Azure, GCP).
- Produce high-quality reports and present findings to engineering and management teams.
- Support remediation, mitigation validation, and retesting efforts.
Requirements
- 3+ years of hands-on penetration testing / offensive security experience.
- Strong understanding of web vulnerabilities (OWASP Top 10, API security), internal network, infrastructure, and Active Directory attack techniques.
- Experience using core offensive tools: Burp Suite, Nmap, Metasploit, BloodHound, CrackMapExec, Impacket.
- Solid understanding of foundational concepts like TCP/IP, DNS, HTTP(S), and authentication (Kerberos, NTLM, OAuth2, SSO).
- Comfortable working in Linux & Windows environments with Bash, PowerShell, and basic Python scripting.
- Excellent verbal and written communication skills to explain risks to both technical and non-technical stakeholders.
Nice to have
- Certifications: OSCP, PNPT, CRTO, OSWE.
- Red Team / adversary simulation experience.
- Cloud penetration testing experience.
- Source code review skills (Java, C#, Python, JavaScript).
Culture & Benefits
- Opportunities for online and offline learning to develop core and professional skills.
- Commitment to sustainability and measurable year-on-year progress.
- Inclusive work environment with programs focused on diversity, inclusion, and equality.
- Support for career growth at NXP.
- Values innovation for a smarter, safer, and more sustainable world.
