
Senior Offensive Security Engineer
Posted Sep 3

Posted Sep 3
This is a fully remote position, open to applicants in India.
• Plan, define scope, and conduct penetration tests for both internal and external environments, covering web and mobile applications, APIs, AWS/Azure cloud services, networks, and infrastructure.
• Create and implement adversary emulation and red team operations utilizing various attack vectors and goal-oriented objectives.
• Collaborate with Security Operations, Threat Intelligence & Hunt, Detection Engineering, Vulnerability Management, Application Security, DevOps, and Product teams on purple team activities and remediation efforts.
• Detect, verify, and responsibly exploit vulnerabilities, including combining lower-severity issues into significant attack pathways.
• Model the tactics, techniques, and procedures of threat actors using the MITRE ATT&CK framework.
• Analyze findings, assess exploitability and business risk, generate remediation tickets, facilitate fixes, and organize retests.
• Develop and sustain custom scripts, tools, and automation for scalable offensive testing.
• Assist in the operationalization of continuous and autonomous testing platforms.
• Create decision-ready reports and executive summaries that translate technical findings into business implications.
• Contribute to incident response and threat hunting with offensive expertise, attack-path context, and adversary insights.
• Establish repeatable methodologies, playbooks, and metrics to enhance the offensive security program.
• 5+ years of practical experience in offensive security, penetration testing, red teaming, or a closely related security engineering position.
• Proven expertise in penetration testing for web/mobile applications, APIs, networks, infrastructure, and cloud environments (AWS and/or Azure).
• Strong comprehension of exploitation and post-exploitation techniques, attack-path chaining, and objective-driven adversary emulation.
• Proficient in tools such as Burp Suite Professional, Nmap, Metasploit, Kali Linux, and various vulnerability scanners.
• Skilled in at least one scripting or programming language, including Python, Go, PowerShell, Ruby, or Bash.
• Familiarity with the MITRE ATT&CK framework and practical experience in mapping engagements to adversary TTPs.
• Exceptional written and verbal communication abilities, capable of presenting findings to both technical audiences and executive leadership.
• Advanced offensive certifications such as OSEP, OSCE³, CRTO, or GXPN are advantageous.
• A record of original security research, CVEs, or responsible disclosures is a plus.
• Experience with cloud-native attack techniques, as well as security testing for containers/Kubernetes (EKS/AKS) and serverless environments, is a plus.
• Familiarity with operating or assessing continuous/autonomous penetration testing and breach-and-attack-simulation platforms is beneficial.
• Understanding of detection engineering, SIEM/EDR platforms, and integrating purple team feedback loops into SOC content is an advantage.
• Knowledge of relevant compliance and security frameworks is a plus.
• Experience in mentoring junior engineers and contributing to the advancement of an offensive security program is a plus.
• Employee Impact Groups
• FA Cares volunteer opportunities
• Mentorship Advantage Program
• SOAR, an award-winning manager development program
• Culture programs and benefits designed to enhance the employee experience and support professional development
Campbell's
VALCE Talent Solutions
The Hello Team
Anduril Industries
Get handpicked remote jobs straight to your inbox weekly.