- Experience
- 1–5 yrs
- Salary
- —
- Openings
- 1
- Posted
- 5 seconds ago
- Work mode
- In office
- Education
- Bachelor's degree or equivalent
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
Join a leading global network focused on helping clients build trust and leverage complexity to gain a competitive edge. We seek an experienced offensive security expert to deliver comprehensive Security Testing services, including Red Teaming, Purple Teaming, Breach and Attack Simulation (BAS), Penetration Testing, Cloud Security, and AI Security. This role resides within the Technology Risk Services practice, supporting organizations in enhancing their IT security posture.
Key Responsibilities
- Simulate behaviors of realistic threat actors by employing relevant tactics, techniques, and procedures (TTPs) within client environments.
- Lead purple team exercises in close collaboration with blue teams to test detection capabilities, improve logging, and optimize response strategies.
- Apply frameworks like MITRE ATT&CK to accurately map adversary techniques.
- Partner with the internal threat intelligence team to support attack simulations and emulation operations.
- Create bespoke tools, payloads, and automation scripts tailored to engagement requirements.
- Keep current with the latest threats, adversary tradecraft, and modern offensive security practices.
- Perform vulnerability assessments, penetration tests (VAPT), and source code reviews as necessary.
- Engage directly with clients to manage concerns, resolve issues, and ensure service quality and value.
- Prepare thorough, precise reports and presentations for technical teams and executive leadership.
Preferred Qualifications & Requirements
- Bachelor’s degree in a technical field or equivalent professional experience.
- Between 1 and 5 years of hands-on offensive security experience.
- Previous consulting or client-facing roles within cybersecurity environments.
- Strong ability to document technical findings clearly and communicate effectively to diverse audiences.
- Familiarity with detection engineering, hypothesis-driven threat hunting, and security operations center (SOC) workflows.
- Experience with adversary emulation and intelligence-led security testing approaches.
- Knowledge of continuous integration/continuous deployment (CI/CD) security, container security, and cloud-native infrastructure.
- Bonus skills include malware analysis, reverse engineering, and exploit development.
- At minimum, OSCP or CREST CRT certifications required; additional relevant certifications such as OSEP, CRTO, CRTE, OSED, CREST CCT, CARTP/CARTE, and Azure/AWS security certifications are highly valued.
Minimum education
Bachelor's Degree
Skills
How they work
Communication
Teamwork & Collaboration
Problem Solving
Customer Focus
Learning Agility