Role Overview:
As an Offensive Security Engineer, you will be responsible for simulating real-world
cyberattacks to identify vulnerabilities, assess risks, and improve security defenses. You will
work closely with security analysts, DevOps, and IT teams to enhance the organization's
resilience against cyber threats.
Key Responsibilities:
Penetration Testing & Red Teaming
● Conduct advanced penetration testing on web apps, networks, APIs, cloud, and mobile
applications.
● Simulate real-world attack scenarios to evaluate security defenses.
● Perform internal/external network and infrastructure security assessments.
● Execute red team exercises, including phishing simulations and social engineering
campaigns.
● Collaborate with SOC/Security teams to validate monitoring and defense effectiveness.
Vulnerability Research & Exploitation
● Identify, analyze, and exploit vulnerabilities across various systems.
● Develop custom scripts or exploits for proof-of-concept attacks.
● Work with security teams to ensure timely patching and risk mitigation.
Security Tool Development & Automation
● Develop and maintain security testing tools and automation scripts.
● Integrate offensive security techniques into CI/CD pipelines.
● Evaluate vendor security tools and features through controlled attack simulations.
● Build proof-of-concept scenarios to confirm vendor-promoted capabilities function as
intended.
Threat Hunting & Adversary Simulation
● Conduct red team and purple team exercises to test detection & response capabilities.
● Stay ahead of cyber threats by researching latest hacking trends, zero-days, and TTPs.
● Provide actionable intelligence to incident response teams.
Security Reporting & Collaboration
● Document security findings with detailed remediation steps.
● Work with engineering teams to implement security best practices.
● Contribute to security awareness training within the company.
Required Skills & Qualifications:
● Experience: 3+ years in offensive security, penetration testing, or red teaming.
Technical Expertise:
● Strong knowledge of penetration testing tools (Burp Suite, Metasploit, Nmap, Kali Linux,
etc.).
● Deep understanding of network security, web security, and cloud security.
● Proficiency in exploit development, reverse engineering, and malware analysis.
● Experience with scripting languages (Python, Bash, PowerShell).
● Hands-on experience with Active Directory attacks, privilege escalation, and lateral
movement.
Mandatory Certifications(Baseline Requirements):
● CEH (Certified Ethical Hacker - EC - Council V13)
Preferred Certifications(Role Enhancing Credentials):
● OSCP (Offensive Security Certified Professional)
● OSWE / OSEP / OSEE (Advanced Offensive Security Certifications)
● CRTO (Certified Red Team Operator)
● GPEN (GIAC Penetration Tester)