Description :
We are seeking an experienced and highly skilled Offensive Security Lead to spearhead our offensive security initiatives. The ideal candidate will have 10+ years of hands-on experience in penetration testing, red teaming, vulnerability assessment, and security research.
Key Responsibilities :
- Lead and mentor the offensive security team, providing technical expertise and guidance.
- Plan and execute advanced penetration tests, red team operations, and vulnerability assessments on internal and external systems.
- Develop and implement offensive security tools, methodologies, and frameworks to simulate real-world attack scenarios.
- Collaborate with security operations, application security, and infrastructure teams to improve overall security posture.
- Continuously improve security testing processes and reporting standards.
- Stay updated with the latest security trends, threat actor tactics, and toolsets.
- Prepare and present detailed technical reports to both technical and non-technical stakeholders.
- Coordinate with incident response teams to simulate attack scenarios and support threat hunting.
- Lead development and delivery of offensive security training and awareness programs.
- Ensure adherence to security policies, compliance standards, and regulatory requirements.
Primary Skill Set :
1. Advanced Penetration Testing & Red Teaming :
Expertise in network, web, cloud, and application testing.Familiarity with frameworks like MITRE ATT&CK.2. Offensive Tooling & Scripting :
Proficiency with Cobalt Strike, Burp Suite, Nmap.Strong scripting in Python, Bash, PowerShell.3. Exploit Development :
Experience in custom exploit creation and vulnerability research.Understanding of attack vectors like RCE, privilege escalation, etc.4. Leadership & Engagement Management :
Proven experience in leading red team operations.Strong risk reporting and stakeholder communication.5. Adversary Emulation :
Design of realistic attack simulations.Threat actor behavior modeling.Secondary Skill Set :
1. Defensive Security Awareness :
Knowledge of SIEM / EDR tools and blue team operations.2. Cloud Security :
Experience with offensive techniques in AWS, Azure, and GCP.3. Compliance Knowledge :
Familiarity with standards like NIST, PCI-DSS, ISO 27001.4. Soft Skills :
Strong communication, reporting, and stakeholder engagement.5. Relevant Certifications :
OSCP, CEH, or equivalent.(ref : hirist.tech)