Responsibilities:
: Conduct thorough penetration tests on client systems, networks, and applications. Provide actionable insights and recommendations for remediation based on identified vulnerabilities.
Technical Expertise:Demonstrate proficiency in a variety of offensive security tools and techniques. Stay current with industry trends, emerging threats, and advancements in offensive security methodologies.
Documentation and Reporting: Document all testing procedures, findings, and recommendations in clear and concise reports. Communicate technical details effectively to both technical and non-technical stakeholders as well as provide proactive guidance on improving an organization’s security posture.
Required Skills:
- Excellent written and verbal communication skills – English
- Experience developing and conducting red team and penetration testing engagements
- Experience performing application security assessments
- Public speaking experience at known security conferences is a plus
- Capable of performing assessments with common offensive toolsets as well as the ability to build custom tools and implants
- Solid knowledge of scripting languages such as Python, Perl, PowerShell, Ruby
- Development experience using C, C++, .NET, Java, Go
- Experience carrying out vulnerability assessments, physical assessments, wireless assessments, and social engineering campaigns.
- Strong understanding of operating system internals and endpoint security controls such as EDR and various evasion techniques
- Solid understanding of Active Directory and Azure AD
Qualifications:
- Bachelor’s Degree in Computer Engineering, Computer Science or related field
- Or 8 - 10+ years’ experience in Attack and Penetration testing roles
- Certifications in offensive security such as OSCP, OSEP, GXPN, GRTP, etc.