Website:
cypherleap.com
Job details:
๐ฆ๐ฒ๐ป๐ถ๐ผ๐ฟ ๐ข๐ณ๐ณ๐ฒ๐ป๐๐ถ๐๐ฒ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ผ๐ป๐๐๐น๐๐ฎ๐ป๐ (๐๐บ๐บ๐ฒ๐ฑ๐ถ๐ฎ๐๐ฒ ๐๐ผ๐ถ๐ป๐ถ๐ป๐ด)
Location: India (Remote - Preference for South India)
Employment Type: Full-time
Experience: 7+ Years (10+ preferred)
Client Base: Australia & International
Joining: Immediate / Within 30 Days Preferred
๐๐ฏ๐ผ๐๐ ๐๐๐ฝ๐ต๐ฒ๐ฟ๐๐ฒ๐ฎ๐ฝ
CypherLeap is a CREST-accredited cybersecurity consultancy delivering offensive security, governance, compliance and managed security services to organisations across Australia. We are seeking a Senior Offensive Security Consultant to independently deliver complex offensive security engagements for international clients while contributing to the growth of our offensive security capability.
๐ ๐ฎ๐ป๐ฑ๐ฎ๐๐ผ๐ฟ๐ ๐ฅ๐ฒ๐พ๐๐ถ๐ฟ๐ฒ๐บ๐ฒ๐ป๐๐
โข 7+ years of hands-on offensive security consulting experience.
โข Demonstrated experience delivering services to international clients (Australian client experience highly desirable).
โข Excellent spoken and written English.
โข Ability to independently scope, execute and deliver offensive security engagements.
โข Author of 50+ professional penetration testing reports.
โข Strong client-facing consulting and presentation skills.
โข Available to join within 30 days (immediate joiners preferred).
Key Responsibilities
โข Lead penetration testing engagements from scoping through final reporting.
โข Perform web, API, mobile, external, internal, Active Directory, cloud and wireless security assessments.
โข Produce executive-quality reports requiring minimal review.
โข Present findings to technical teams, CIOs, CISOs and executive stakeholders.
โข Conduct remediation workshops and retesting.
โข Support technical scoping, proposal development and effort estimation.
โข Review work produced by junior consultants and provide mentoring.
โข Contribute to the continuous improvement of CypherLeap's offensive security methodologies.
Research & Capability Development
โข Research newly disclosed vulnerabilities (CVEs) and assess customer impact.
โข Develop and validate proof-of-concept exploits where appropriate.
โข Develop custom offensive security scripts, tooling and automation.
โข Build and maintain internal attack labs for research and testing.
โข Create reusable methodologies, playbooks and assessment checklists.
โข Evaluate emerging offensive security techniques and technologies.
โข Publish internal technical documentation and contribute to knowledge sharing.
โข Where appropriate, contribute to technical blogs, whitepapers or security research.
๐ง๐ฒ๐ฐ๐ต๐ป๐ถ๐ฐ๐ฎ๐น ๐๐
๐ฝ๐ฒ๐ฟ๐๐ถ๐๐ฒ
โข External & Internal Infrastructure Penetration Testing
โข Active Directory Security Assessments
โข Web Application & API Penetration Testing
โข Mobile Application Security Testing (Android & iOS)
โข AWS, Azure, Microsoft 365 & Entra ID Security Assessments
โข Windows & Linux Privilege Escalation
โข Kerberos Attacks & Lateral Movement
โข Wireless Security Testing
โข Red Team Exercises & Social Engineering
โข Secure Configuration Reviews
โข Container & Kubernetes Security (Desirable)
โข Source Code Review (Desirable)
๐ฃ๐ฟ๐ฒ๐ณ๐ฒ๐ฟ๐ฟ๐ฒ๐ฑ ๐๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป๐
โข OSCP
โข OSEP
โข OSWE
โข PNPT
โข CRTO
โข CRTP
โข CREST CRT/CCT
โข GWAPT
โข GXPN
โข Demonstrated consulting experience is valued more highly than certifications.
๐ช๐ต๐ ๐๐ผ๐ถ๐ป ๐๐๐ฝ๐ต๐ฒ๐ฟ๐๐ฒ๐ฎ๐ฝ
โข Work directly with international enterprise clients.
โข Exposure to a broad range of technologies and industries.
โข Remote-first working environment.
โข Certification and professional development support.
โข Opportunity to contribute to research, tooling and innovation.
Click on Apply to know more.