SysTools
Website:
systoolsgroup.com
Job details:
We are seeking a highly skilled Senior Offensive Security Engineer to lead our Red Team operations and advanced penetration testing efforts. In this role, you will act as a real-world adversary to identify, exploit, and help remediate complex security vulnerabilities across our infrastructure, applications, and cloud environments. You will go beyond automated scanning to design custom attack chains, simulate advanced persistent threats (APTs), and work closely with our Blue Team to enhance our detection and response capabilities.
Key Responsibilities
- Red Team Operations: Plan, lead, and execute full-scope, objective-based Red Team engagements simulating real-world adversaries (including social engineering, physical bypass, and digital exploitation).
- Advanced Penetration Testing: Conduct deep-dive network, web application, mobile application, and API penetration tests.
- Adversary Simulation: Develop custom tooling, payloads, and scripts to bypass modern security controls (EDR, AV, WAF, IPS/IDS) and establish persistent access.
- Purple Teaming: Collaborate actively with the SOC/Blue Team to review engagement findings, tune SIEM alerts, and improve overall detection engineering.
- Reporting & Remediation: Translate complex technical findings into actionable, business-focused reports for both executive leadership and engineering teams. Provide precise remediation guidance.
- Mentorship: Guide and train junior to mid-level security engineers, fostering a culture of continuous learning and advanced tradecraft.
Required Qualifications
- Experience: 5+ years of dedicated experience in offensive security, penetration testing, or red teaming.
- Technical Knowledge: Deep understanding of networking protocols, Active Directory environments, operating system internals (Windows/Linux/macOS), and web architectures.
- Frameworks: Proficiency with the MITRE ATT&CK framework, OWASP Top 10, and PTES (Penetration Testing Execution Standard).
- Scripting & Development: Strong ability to write and modify scripts/tools in languages such as Python, Go, C/C++, PowerShell, or Bash.
- Tooling: Expert-level experience with offensive tools (e.g., Cobalt Strike, BloodHound, Burp Suite Pro, Metasploit, Nmap, Impacket).
Preferred Qualifications & Certifications
- Active industry certifications such as OSCP, OSEP, OSWE, OSED (or full OSCE3), CRTO, or PNPT.
- Experience testing cloud environments (AWS, Azure, GCP) and containerized infrastructure (Docker, Kubernetes).
- Published CVEs, bug bounty hall of fame acknowledgments, or contributions to open-source security tools.
Soft Skills
- Impeccable ethics and integrity.
- Strong written and verbal communication skills; ability to explain highly technical concepts to non-technical stakeholders.
- An "attacker's mindset" paired with a builder’s desire to secure and improve systems.
Click on Apply to know more.