Remote job
Offensive Security Engineer
Job details
About this role
Role overview
An offensive security role on a Proactive Threat team focused on emulating real-world adversaries to uncover risk before attackers can exploit it. The work spans hands-on penetration testing, end-to-end red team engagements, and tight collaboration with defensive counterparts. A core goal is validating and continuously strengthening detection and response capabilities across products and infrastructure.
Responsibilities
- Simulate adversary tactics, techniques, and procedures (TTPs) against products, services, and infrastructure - Plan and execute hands-on penetration tests across applications, systems, and networks - Lead red team engagements from scoping and threat modeling through execution and debrief - Partner with blue team counterparts to validate detections, response playbooks, and alerting - Communicate findings, quantify risk, and drive remediation with engineering and product teams
Requirements
- Substantial experience in offensive security, penetration testing, or red team operations - Deep familiarity with common adversary TTPs and frameworks such as MITRE ATT&CK - Strong technical skills across application, network, and cloud environments - Clear written and verbal communication for reporting findings to varied audiences
Nice to have
- Experience building or maintaining offensive tooling and adversary emulation infrastructure - Familiarity with blue team tooling such as SIEM and EDR, and how detections are authored - Knowledge of modern cloud environments and web application architectures - Contributions to the security community via talks, research, or open-source tooling