Jobgether

Sr Offensive Security Engineer

Jobgether India

Internet Marketplace Platforms · 11-50 employees

14 h ago
Remote security Senior (5-10 yrs) Full-time India
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will lead hands-on penetration testing, red and purple team engagements, and adversary emulation across applications, cloud infrastructure, and networks. Additionally, you will develop custom scripts and automation to scale security testing while partnering with engineering teams to prioritize and remediate vulnerabilities.

What they look for

Penetration testing Red teaming Purple teaming Adversary emulation Cloud security Exploit development Python Go PowerShell Burp Suite Metasploit MITRE ATT&CK Kubernetes security Vulnerability management Threat hunting Automation

Requirements

The role requires 5+ years of hands-on experience in offensive security and demonstrated expertise across web, mobile, and cloud platforms. Candidates must possess strong scripting skills and familiarity with industry-standard offensive security tools and the MITRE ATT&CK framework.

Benefits

Medical coverage Dental coverage Paid time off Volunteer time off Global employee assistance program Professional development Mentorship opportunities

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr Offensive Security Engineer based in India.

This role offers an opportunity to think and operate like a real-world adversary while helping strengthen enterprise security at scale. You will lead hands-on penetration testing, red and purple team engagements, and adversary emulation across applications, cloud infrastructure, networks, and enterprise systems. The position combines deep technical security expertise with exploit development, attack-path analysis, automation, and threat-informed testing. You will work closely with security operations, threat intelligence, vulnerability management, application security, DevOps, and product teams. Your findings will help organizations identify meaningful weaknesses, prioritize remediation, and improve detection and response capabilities. The role is well suited to an experienced offensive security professional who enjoys solving complex problems and clearly communicating technical risk to both engineers and senior leaders.

\n

Accountabilities:

  • Plan, scope, and execute penetration tests across web and mobile applications, APIs, cloud environments, networks, and infrastructure using realistic attacker methodologies.
  • Design and conduct red team, purple team, and adversary emulation exercises that combine multiple attack paths to achieve defined objectives and evaluate organizational resilience.
  • Identify, validate, and safely exploit vulnerabilities, including chaining lower-severity weaknesses into higher-impact attack paths within controlled, production-representative environments.
  • Model real-world threat actor tactics, techniques, and procedures using the MITRE ATT&CK framework to assess and strengthen detection and response capabilities.
  • Review security findings for accuracy, assess exploitability and business impact, prioritize remediation, create actionable tickets, and work with engineering teams through remediation and retesting.
  • Develop and maintain custom scripts, offensive security tooling, and automation to scale penetration testing and support continuous or autonomous security testing capabilities.
  • Produce clear, decision-ready technical reports and executive summaries that translate vulnerabilities and attack paths into measurable business and security risk.
  • Support incident response and threat hunting activities by providing offensive security expertise, adversary context, and attack-path analysis.
  • Partner with security, engineering, DevOps, product, and infrastructure teams to turn offensive findings into practical, prioritized security improvements.
  • Contribute to the maturity of the offensive security program by developing repeatable methodologies, playbooks, metrics, and continuous improvement initiatives.

Requirements:

  • 5+ years of hands-on experience in offensive security, penetration testing, red teaming, or a closely related security engineering role.
  • Demonstrated expertise across multiple security domains, including web and mobile applications, APIs, networks, infrastructure, and cloud platforms such as AWS and/or Azure.
  • Strong understanding of exploitation, post-exploitation, attack-path chaining, privilege escalation, and objective-based adversary emulation.
  • Proficiency with industry-standard offensive security tools such as Burp Suite Professional, Nmap, Metasploit, Kali Linux, and vulnerability scanning platforms.
  • Strong scripting or programming skills in at least one language such as Python, Go, PowerShell, Ruby, or Bash, with the ability to develop custom tools and automation.
  • Practical knowledge of the MITRE ATT&CK framework and experience mapping offensive engagements to adversary tactics, techniques, and procedures.
  • Strong understanding of cloud-native attack techniques, with experience testing containerized or Kubernetes environments and serverless platforms preferred.
  • Familiarity with detection engineering, SIEM and EDR technologies, and purple team feedback loops is highly valuable.
  • Experience evaluating or operating continuous penetration testing and breach-and-attack-simulation platforms is advantageous.
  • Knowledge of relevant cybersecurity, compliance, and security frameworks.
  • Strong written and verbal communication skills, with the ability to explain complex vulnerabilities, attack scenarios, and business impact to both technical stakeholders and executive leadership.
  • Advanced offensive security certifications such as OSEP, OSCE³, CRTO, or GXPN are preferred.
  • A track record of original security research, CVEs, responsible disclosures, or other demonstrable security research is a plus.
  • Experience mentoring junior security engineers and helping develop or mature an offensive security program is advantageous.

Benefits:

  • Full-time opportunity based in India with a remote work environment.
  • Competitive benefits package, including medical and dental coverage, subject to applicable eligibility requirements.
  • Generous paid time off program.
  • Volunteer Time Off opportunities supporting community and philanthropic initiatives.
  • Global Employee Assistance Program focused on employee well-being.
  • Professional development opportunities, including structured learning and career-development programs.
  • Mentorship opportunities designed to support professional growth and knowledge sharing.
  • Access to employee impact groups and initiatives that foster inclusion, collaboration, and connection.
  • Opportunities to work on sophisticated offensive security challenges across cloud, application, infrastructure, and enterprise environments.
  • Supportive, collaborative culture focused on innovation, continuous learning, teamwork, and meaningful security impact.
  • Equal opportunity workplace committed to fair employment practices and a recruitment process free from discrimination, harassment, and retaliation.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Similar roles