Senior Vulnerable Machine Engineer
Summary
Designs and builds realistic cybersecurity lab environments (Linux/Windows, Active Directory, cloud) to train professionals, ensuring content is solvable, reproducible, and aligned with learning objectives.
About OffSec
Founded in 2006 by the creators of Kali Linux, OffSec (formerly known as Offensive Security) is the leading provider of continuous professional and workforce development, training, and education for cybersecurity practitioners.
OffSec’s distinct pedagogy and practical, hands-on learning help organizations fill the infosec talent gap by training their teams on today’s most critical skills.
Become a part of our global presence and work from anywhere. With team members in over 40 countries, we believe in inspiring people of all backgrounds and communities. The OffSec team is composed of diverse, internationally published authors, conference speakers, and seasoned information technology professionals from both the private sector and governments worldwide.
Excited about our mission and what we do? Apply and join us!
About the Job
Have you earned your OSCP, OSEP/OSED/OSWE, and gained offensive experience before and/or since then? Are you excited at the opportunity to contribute to the growth and education for the current and next generation of cybersecurity professionals?
If the idea of building lab environments, to provide hands-on experience for individuals to learn and upskill, then this might be the right role for you!
Duties and Responsibilities
Content design and build
Researches and identifies topical, relevant attack vectors suitable for inclusion in OffSec labs, exams, and/or learning content
Design and build VMs and multi-host environments from vectors across Linux and Windows, including Active Directory and Cloud attack paths
Designs realistic scenarios and environment narratives that make each attack path plausible and discoverable through enumeration
Ensures the range of vectors in each environment is appropriate to its stated difficulty level and learning objectives
Maintains variety across the catalogue so that content remains distinct as it rotates through active use
Quality, integrity, and reproducibility
Review labs for unintended solution paths and confirms each is solvable by the intended route within its expected time frame
Validates that machines are deterministic and reproducible in an isolated environment, including reliable reset and revert behaviour
Deliberate selection and use of software and OS versions, monitoring deployed components so that content behaves consistently over its lifetime
Documents the steps required to complete each machine, with difficulty assessed at a level of detail that supports competency mapping and certification review
Collaboration
Coordinates with the relevant team(s) to deploy, update, and retire content
Coordinates with testing to ensure full coverage of both newly created and updated content
Coordinates with the Lab team Manager and Content Architect on vector selection and exploit implementation within courses and learning paths
Coordinates and make recommendations to keep content additions consistent across products
Regularly communicates content additions, changes, and retirements to relevant stakeholders
Senior scope
Acts as a technical reviewer for lab concepts and builds produced by other Vulnerable Machine Engineers and community contributors, providing structured, actionable feedback
Support and mentor other engineers on build standards, documentation quality, and content review practice
Contributes across OffSec's lab and exam portfolio as priorities require, rather than to a single product
Automation and tooling
Creates and maintains automation that makes lab creation timely, consistent, and repeatable
Evaluates new and emerging technologies to make recommendations on their introduction into the lab estate
Create and maintain documentation for every lab, to a standard that allows any team member to rebuild it from the documentation alone, without assistance
Qualifications
OSCP minimum, OSCE³ preferred (or at least one OffSec 300-level cert required)
A Bachelor’s Degree in Systems Engineering, Computer Science, Information Systems, and / or Information Assurance from an accredited institution/related specialized field, or equivalent practical experience.
Demonstrable Active Directory and Cloud attack-path experience.
Proficiency with infrastructure-as-code and configuration management and version control
Scripting proficiency (Python, PowerShell, Bash).
At least five or more years of experience as a Systems Engineer or in a Info-Sec related position (examples), with experience reviewing or approving others' technical security content:
Experience with Penetration Testing
Experience with Bug Bounty Hunting
Experience as a Systems Administrator with a variety of Operating Systems:
MS Windows
MS Windows Based Server Systems
POSIX Server Systems
Linux and Mac Desktop Environments
Strong written and verbal communication skills with an ability to present technical ideas clearly to both technical and non-technical audiences
Work Location and Hours
This role is a full-time salaried position. It is a fully remote position. Work hours for this position are flexible and will be performed from a home office.
Direct Reports
This position has no direct reports. However, the expectations of this role are to provide technical leadership.
EEO
OffSec provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.