Cyber Offensive Security Senior Associate

Grant Thornton - USPhiladelphia, PennsylvaniaOn-siteFull-timeMid level, 2–5 yearsListed 2 hours ago

Apply now

About this role

As a Senior Offensive Security Consultant on our Cyber Defense team, you will get the opportunity to lead adversarial testing engagements for clients across a range of industries. In this role, you will simulate real-world adversaries to identify exploitable weaknesses, validate detection and response capabilities, and help clients measurably strengthen their security posture. This is a hands-on technical role with significant client interaction and ideal for someone who thrives on solving complex problems and communicating impact to both technical teams and executive stakeholders.

From day one, you’ll be empowered by the greater Cyber & Risk team to help clients make the moves that will help them achieve their vision and help you achieve more, confidently.

Your day-to-day may include:

- Penetration Testing: Plan and execute network, application, API, and cloud penetration tests, from scoping through exploitation, post-exploitation, and reporting.

- Adversary Emulations: Design and run, threat-informed attack simulations to validate the effectiveness of client security controls and detection coverage.

- Assume-Breach: Conduct assume-breach engagements, collaborating with defensive teams to test detection, response, and containment capabilities.

- AI Red Teaming: Perform adversarial testing of AI/ML systems and LLM-enabled applications, including prompt injection, model manipulation, data exfiltration, and abuse-case testing.

- Threat Emulation: Emulate the tactics, techniques, and procedures (TTPs) of relevant threat actors, mapping activity to frameworks such as MITRE ATT&CK.

- Reporting & Communication: Produce clear, high-quality deliverables that translate technical findings into prioritized, business-relevant remediation guidance; present results to technical staff, management, and executive/board audiences.

- Client Advisory: Serve as a trusted technical advisor, helping clients understand risk, prioritize remediation, and mature their security programs.

- Practice Development: Contribute to methodology development, tooling, automation, and the mentoring of junior team members.

You have the following technical skills and qualifications:

- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field is required

- 3+ years of hands-on experience in offensive security, penetration testing, or red teaming.

- Demonstrated expertise across multiple domains (network, application, cloud, and/or internal infrastructure testing).

- Strong understanding of adversary TTPs and frameworks such as MITRE ATT&CK and ATLAS and OWASP.

- Proficiency with industry-standard tooling and command-and-control frameworks.

- Scripting and automation skills (e.g., Python, PowerShell, Bash).

- Experience conducting assume-breach or adversary emulation engagements.

- Excellent written and verbal communication skills, including the ability to produce professional, client-ready reports.

- Ability to work independently, manage multiple engagements, and meet deadlines in a client-service environment.

Preferred qualifications:

- Relevant certifications such as OSCP, OSEP, OSWE, GPEN, GXPN, GWAPT or CREST.

- Prior consulting or professional-services experience.

- Cloud security testing experience across AWS, Azure, and/or GCP.

- Experience with AI/ML or LLM security testing and adversarial techniques.

- Familiarity with breach and attack simulation platforms.

- Experience testing the security of D365 and integrations a plus.

- Contributions to the security community (research, tooling, CVEs, conference talks, or publications).

#hybrid

#LI-LG1