Zurück zu Jobs
ScovaiScovaiJobs
Redherd.io

Redherd.io

Offensive Security Consultant MOZ — Intermediate

Johannesburg, MZVor OrtUnbefristetVollzeit500.000 € – 550.000 € / Jahr

Veröffentlicht am 2. Okt. 2026

Diese Stelle wird in PT ausgeschrieben

Offensive Security Consultant - Mozambique

Location: Maputo, Mozambique
Employment type: Full time, permanent
Seniority: Junior to intermediate, hands-on penetration testing

At a glance

  • Hands-on penetration testing across web applications, APIs, internal and external infrastructure, and networks, for a consultancy's Mozambique operation.
  • Based in Maputo, with working Portuguese. Portuguese is required because the work serves clients in Mozambique.
  • A strong junior with practical, demonstrable work will be considered alongside intermediate candidates.

About RedHerd

RedHerd is a specialist cybersecurity recruitment and advisory firm. We work with consultancies, product companies, vendors and enterprise security teams across Africa, the UK, Europe and the United States. We are recruiting this position exclusively on behalf of our client. Their identity is shared with you during qualification, before anything is submitted. We never introduce your profile without your knowledge and consent.

About the client

Our client is an established cybersecurity consultancy that delivers offensive security and managed security services to organisations across Southern Africa and beyond. It runs a separate operating company in Mozambique, and this seat sits there.

Its client base includes businesses in Portuguese - and French-speaking markets.

The role

This seat builds the client's offensive-security capacity on the ground in Mozambique. You run authorised assessments, find and validate vulnerabilities, and explain both the technical and business risk to the people who have to fix them.

You work inside agreed scopes, methodologies, legal authorisations and client confidentiality requirements. On complex engagements, you work alongside senior consultants, and structured training supports your development.

What it is not. It is not a scanner-driven role. The client wants findings validated by hand and false positives filtered out before they reach a report. It is not a senior or lead seat, and it is not a people-management position.

What you will do

  • Scope-aware reconnaissance and enumeration, then exploitation and post-exploitation within the agreed rules of engagement.
  • Penetration tests and vulnerability assessments across web applications, APIs, internal and external infrastructure, and networks.
  • Test authentication, authorisation, session management and access control for common weaknesses.
  • Validate every vulnerability by hand and demonstrate it safely, keeping operational risk to clients low.
  • Use commercial and open-source tooling well, without leaning on automated scanner output.
  • Keep clear, reproducible evidence and accurate engagement notes throughout.
  • Write reports that cover the technical finding, the business impact, the risk rating and practical remediation.
  • Present findings to technical stakeholders and help with remediation discussions.
  • Retest to confirm that reported vulnerabilities have actually been fixed.
  • Keep up with new offensive techniques, vulnerabilities and industry developments.

What you must bring

Hands-on penetration testing or offensive security in a professional environment. Around two years is the level for this seat, and a strong junior with practical, demonstrable work will be considered.

  • Recognised penetration-testing certifications, for example OSCP, PNPT, CPTS, CRTO, CRTP, eCPPT, eWPT or eWPTX, GPEN, or equivalent practical credentials.
  • Web application and API testing with Burp Suite or similar.
  • Working knowledge of internal and external network testing across Windows, Linux and Active Directory environments.
  • Practical use of Nmap, Nessus or an equivalent scanner, Metasploit, Linux security tooling and common enumeration frameworks.
  • A sound understanding of the OWASP Top 10, common infrastructure vulnerabilities, networking and operating systems.
  • The judgement to separate exploitable vulnerabilities from false positives and explain their real impact.
  • Clear, professional technical report writing in English.
  • Working Portuguese, spoken and written. 
  • Based in Maputo, with the legal right to work in Mozambique.
  • Willingness and ability to travel for client engagements when required.

Useful extras

  • French. The client also works with businesses in French-speaking markets.
  • Active Directory attack-path analysis and privilege escalation.
  • Mobile, cloud, wireless or thick-client testing.
  • Scripting in Python, PowerShell or Bash.
  • Responsible disclosures, CTFs, security research or other public practical work.
  • A tertiary qualification in IT, computer science, cybersecurity or a related field.

Work arrangement

Maputo, Mozambique. Primarily office-based, with flexible working hours.

Travel is required for client engagements when needed.

Package and development

Package will be discussed during the Clearing Call with RedHerd.

  • Company-provided devices and the professional tooling the role needs.
  • A structured training and certification path.
  • Company-supported learning, lab access and certification exams.
  • Exposure to varied client environments and a broad spread of offensive-security work.

Process and verification

  1. Apply on the job page. Submit a CV, a list of your current certifications, and answer all the screening questions. Links to public work help: technical articles, research, responsible disclosures, GitHub projects or CTF profiles.
  2. Clearing call with RedHerd to discuss your application, the role and the package.
  3. Practical technical assessment with the client, role-relevant and run in an authorised environment.
  4. Discussion with the team about your approach and findings.
  5. Reference and background checks before offer. The client runs these itself.

If a profile or CV does not fully describe confidential work, candidates are encouraged to explain their contribution without disclosing sensitive customer or employer information.

Why this role

  • A seat that builds offensive-security capability in Mozambique, with a regional consultancy behind it.
  • A structured training and certification path, with exams and lab access paid for, which makes it a real step for a strong junior.
  • Senior consultants to work alongside on complex engagements.
  • Varied engagements across web, API, infrastructure and network testing.
  • Company-provided devices and tooling.

Equal opportunity

Applications are considered against the skills, experience, location and verification requirements of the role. RedHerd and our clients are committed to a fair and respectful process and do not discriminate on the basis of any protected characteristic.

Rollenübersicht

Jobart

Vollzeit

E-Mail

charles.wroth@redherd.io

Erforderliche Kompetenzen

Penetration testing / offensive securityWeb application and API testing (Burp Suite or similar)Reconnaissance, enumeration, exploitation and post-exploitationManual vulnerability validation and safe exploitation (false-positive filtering)Internal and external network penetration testing (Windows and Linux)Active Directory attack-path analysis and privilege escalationNmap (network discovery and enumeration)Nessus or equivalent vulnerability scanningMetasploit (exploitation framework)OWASP Top 10 and web security knowledgeTechnical report writing and communicating business risk to stakeholdersEvidence collection, reproducible evidence and engagement documentationUnderstanding rules of engagement, legal authorisations and client confidentialityPortuguese (working spoken and written)Scripting (Python, PowerShell or Bash)

Ähnliche Stellen

wedded.wonderland

Luxury Travel Advisor, Independent Partner, South Africa | Wedded Wonderland

wedded.wonderland

Johannesburg, ZAVor OrtUnbefristetVollzeit
vorgestern
Redherd.io

SOC Technical Specialist — Intermediate

Redherd.io

Johannesburg, ZAVor OrtUnbefristetVollzeit500.000 € – 550.000 € / Jahr
vor 6 Tagen
TMA Proactive Partners

Sales Manager – Digital Advertising - Johannesburg

TMA Proactive Partners

Johannesburg, ZAVor OrtUnbefristetVollzeit
vor 7 Tagen
TMA Proactive Partners

Document Controller – Freight/Shipping/Port Operations

TMA Proactive Partners

Johannesburg, ZAVor OrtUnbefristetVollzeit
vor 8 Tagen
Redherd.io

Offensive Security Consultant ZA — Intermediate

Redherd.io

Johannesburg, ZAVor OrtUnbefristetVollzeit450.000 € – 500.000 € / Jahr
vor 9 Tagen
CS

Account Manager - German Speaking

CodeConnect Staffing

Johannesburg, ZAVor OrtUnbefristetVollzeit
vor 10 Tagen