
Sr Offensive Security Engineer
First Advantage4 days ago
Remote, IndiaSenior
Responsibilities
- Plan, scope, and execute internal and external penetration tests across web and mobile applications, APIs, AWS and Azure cloud environments, networks, and infrastructure.
- Design and run red team, purple team, and adversary emulation engagements using objective-based attack paths and real-world attacker techniques.
- Identify, validate, and safely exploit vulnerabilities, including chaining lower-severity issues into high-impact attack paths.
- Map adversary emulation activities to MITRE ATT&CK tactics, techniques, and procedures.
- Review findings, prioritize exploitability and business risk, create remediation tickets, coordinate fixes, and conduct retests.
- Build and maintain custom scripts, tooling, and automation and help operationalize continuous or autonomous testing platforms.
- Produce technical reports and executive summaries that communicate security findings and business impact.
- Support incident response and threat hunting with offensive expertise and attack-path context.
- Develop repeatable methodologies, playbooks, and metrics to mature the offensive security program.
Requirements
- At least 5 years of hands-on experience in offensive security, penetration testing, red teaming, or a closely related security engineering role.
- Demonstrated expertise in web and mobile application, API, network, infrastructure, and cloud penetration testing across AWS and/or Azure.
- Strong understanding of exploitation, post-exploitation, attack-path chaining, and objective-based adversary emulation.
- Proficiency with Burp Suite Professional, Nmap, Metasploit, Kali Linux, and vulnerability scanners.
- Proficiency in at least one scripting or programming language such as Python, Go, PowerShell, Ruby, or Bash.
- Working knowledge of the MITRE ATT&CK framework and experience mapping engagements to adversary TTPs.
- Strong written and verbal communication skills, including the ability to present findings to technical stakeholders and executive leadership.
- Preferred: advanced offensive security certifications such as OSEP, OSCE³, CRTO, or GXPN.
- Preferred: original security research, CVEs, responsible disclosures, cloud-native attack techniques, Kubernetes testing, continuous testing platforms, detection engineering, SIEM/EDR platforms, relevant compliance and security frameworks, and experience mentoring junior engineers.
Benefits
- Employee Impact Groups.
- FA Cares volunteer opportunities.
- Mentorship Advantage Program.
- SOAR award-winning manager development program.
- Culture programs and benefits focused on employee experience and development.