Roles & Responsibilities
- Offensive Security Operations
- Conduct vulnerability assessments and penetration testing on applications, networks, and cloud systems.
- Execute red team engagements to simulate real-world attacks and identify vulnerabilities and exploitation paths.
- Threat Analysis & Research
- Stay updated on the latest cybersecurity threats, vulnerabilities, and attack vectors.
- Proactively identify and mitigate risks relevant to the transportation and technology sectors.
- Security Audits & Incident Response
- Perform regular security audits, including code reviews and architecture assessments.
- Investigate potential security breaches, recommend corrective actions, and support incident response activities.
- Collaboration & Training
- Collaborate with product development, DevOps, and engineering teams to integrate secure practices.
- Lead internal training programs to promote a security-first culture across the organization.
Requirements
Experience
7 to 10 years of experience in offensive security, ethical hacking, penetration testing, or related roles.Proven expertise as a Cybersecurity Offensive Engineer or a similar position.Technical Skills
Proficiency with security tools such as Burp Suite, Metasploit, Nessus, Nmap, Kali Linux, Qualys, SonarQube, and BlackDuck.Strong understanding of web, network, mobile, and IoT security.In-depth knowledge of OWASP Top 10 and common attack vectors (SQL injection, XSS, CSRF, buffer overflow, etc.).Familiarity with vulnerability management tools (e.g., Qualys, Tenable) and secure coding practices.Hands-on experience with reverse engineering, exploit development, and malware analysis (preferred).Familiarity with DevSecOps tools and processes (static / dynamic code analysis).Knowledge of security frameworks and compliance standards (e.g., OWASP, NIST, SOC, CIS, GDPR, HIPAA, PIPEDA).Programming & Problem-Solving Skills
Proficiency in scripting languages like Python, Bash, Ruby, or PowerShell.Familiarity with programming languages such as C, C++, Java, or Go.Strong problem-solving and creative thinking abilities to simulate real-world attacks and devise effective mitigation strategies.Soft Skills
Exceptional verbal and written communication skills for documentation and collaboration.Excellent organizational skills and attention to detail.Education & Certification
Bachelor's / Master's degree in Computer Science, Information Security, or a related field (preferred).Relevant certifications such as Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), or Cloud Security Certified Professional (CSCP).Skills Required
Devops, Sql