
Offensive Security Engineer
Posted Jul 16

Posted Jul 16
This is a fully remote position, open to applicants in Europe.
• Oversee, map, and assess Sporty’s complete external attack surface, encompassing all external domains, subdomains, websites, and public IP addresses associated with Sporty Group.
• Execute adversary emulation exercises targeting internal and office endpoints to verify the efficacy of EDR, XDR, and SOC monitoring systems.
• Assess the security posture of physical office hardware, corporate network devices, and internal edge infrastructure.
• Conduct targeted offensive testing on externally-facing web applications and select public-facing API endpoints.
• Convert findings from external discovery, DNS security posture, network access control vulnerabilities, and EDR emulation into repeatable defensive checks.
• Assist our Purple Team in confirming that EDR policies, perimeter controls, firewall configurations, and network segmentation function as intended.
• Document multi-stage network or system exploitation chains to offer practical, reproducible remediation blueprints for infrastructure and SOC teams.
• Aid IT and Network analysts by providing clear vulnerability descriptions, triage procedures, severity assessments, and escalation instructions.
• Enhance external asset tracking, perimeter health records, and exposure trend analysis.
• Monitor external vulnerability gaps, emulation success rates, remediation timelines, asset health, and perimeter exposure.
• Proven experience in offensive security, perimeter penetration testing, network security evaluations, or adversary emulation.
• Solid understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.
• Hands-on experience in auditing and testing both Linux and Windows environments along with their underlying network services.
• Capability to perform adversary emulation and utilize bypass techniques against contemporary EDR/XDR solutions.
• Familiarity with testing physical office network hardware, including routers, switches, firewalls, and workplace IT systems.
• Competence in translating external exposures and technical network risks into clear, actionable remedies for IT and Security teams.
• Experience with core web vulnerabilities and limited, targeted testing of modern API interfaces.
• Proficient scripting skills in Python, PowerShell, Bash, or similar languages to automate perimeter mapping, emulation workflows, and asset discovery.
• Good understanding of scanning, reconnaissance, and interception tools.
• Excellent documentation abilities.
• A competitive salary along with individual performance-based bonuses every quarter.
• 28 days of paid annual leave.
• Core working hours from 10am to 3pm in your local time zone, with flexibility outside of these hours.
• Referral bonuses and flash bonuses.
• State-of-the-art equipment.
• Annual company retreats that foster opportunities for connection and collaboration with colleagues from around the globe.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.