Mô tả công việc
Lead complex offensive engagements and act as a subject-matter expert in applying advanced tooling and automation to testing and adversary simulation.
Key Responsibilities
- Plan and execute advanced web/API, infrastructure, cloud, and identity-focused tests; lead red and purple-team exercises.
- Apply structured processes and specialised tooling to accelerate reconnaissance, vulnerability discovery, exploit chain development, and evidence collection, while maintaining rigorous manual validation.
- Produce clear, actionable reporting, including exploitation narratives, business-impact descriptions, and prioritised remediation guidance.
- Capture mature attack paths and engagement patterns as reusable playbooks and internal lab scenarios.
- Collaborate with defensive teams to validate detections and inform new rules, thresholds, and hunting hypotheses.
- Provide coaching and day-to-day guidance to Consultants and Associates; review their work products.
- Support technical pre-sales by contributing to scopes, assumptions, and level-of-effort estimates.
Yêu cầu công việc
- 4–7 years in penetration testing or red-team roles, including lead responsibilities.
- Strong offensive skills across at least two areas such as web/app, cloud, Active Directory, phishing/social engineering, or mobile.
- Experience designing or using enhanced tooling for code review, recon, exploit development, or documentation.
- Proficiency in at least one scripting language (for example Python, Go, or similar).
- Relevant certifications (OSCP, OSWE, OSEP, or equivalent) are desirable.
Key KPIs
- Number and impact of critical/high findings on led engagements.
- Client satisfaction ratings and repeat business on offensive projects.
- Quantity and quality of playbooks, labs, and internal methodologies contributed.
- Feedback from junior staff on mentoring and technical leadership.