We are seeking a highly skilled and experienced Cybersecurity Consultant with over 5 years of proven expertise in penetration testing, red teaming, vulnerability assessment , and Active Directory exploitation . In this role, you will simulate real-world attack scenarios, uncover critical vulnerabilities, and provide technical remediation guidance to strengthen security postures. You will also mentor junior team members and work cross-functionally to embed security best practices throughout the organization.
Key Responsibilities
- Perform manual penetration testing on a variety of targets including :
- Web applications
- Internal business applications
- APIs
- Internal and external networks
- Mobile applications
- Plan and execute network penetration testing and Red Team assessments to simulate sophisticated threat actor behavior.
- Conduct Active Directory and Windows infrastructure testing , including attacks on Certificate Services , Kerberos , and NTLM .
- Execute social engineering assessments , including phishing campaigns and physical security evaluations.
- Conduct OSINT investigations to identify public exposure of sensitive assets or credentials.
- Customize and develop tools, scripts, and proof-of-concept exploits to meet specific operational goals.
- Continuously research emerging threats, vulnerabilities, attack vectors, and security technologies.
- Present detailed technical reports to stakeholders with risk ratings, impact summaries, and actionable remediation steps.
- Work closely with development, IT, and business teams to integrate security into project lifecycles and DevOps pipelines.
- Mentor junior team members , contribute to knowledge sharing, and promote security awareness throughout the organization.
Required Skills and Qualifications
Minimum 5 years of professional experience in cybersecurity with a focus on :Network and web application penetration testingRed teaming engagementsVulnerability assessments and exploit developmentIn-depth understanding of :Network protocols and system architecturesMicrosoft enterprise infrastructure (Windows Servers, Active Directory, AD CS, Azure)Web and mobile application security , authentication mechanisms, and encryptionExperience with manual exploitation techniques , as well as using and customizing tools like :Burp Suite, Nmap, Metasploit, BloodHound, Cobalt Strike, etc.Knowledge of social engineering attack vectors and security awareness testingAbility to perform business logic assessments and identify flaws beyond automated scanningStrong communication skills, including the ability to translate technical findings into executive-level reportsPreferred Certifications
One or more of the following certifications are highly desirable :
OSCP – Offensive Security Certified ProfessionalOSEP – Offensive Security Experienced Penetration TesterCRTP / CRTO – Certified Red Team Professional / OperatorOSWA / GWAPT – Web Application Security CertsProfessional Attributes
Excellent analytical and problem-solving skillsHigh degree of attention to detailStrong written and verbal communication skillsSelf-motivated with a proactive approach to learning and threat researchComfortable working both independently and in collaborative team settingsSkills Required
Penetration Testing, Web Application Security Testing, Network Penetration Testing