About this role
- Required Qualifications and Experience
- Three or more years of recent, hands-on experience in red teaming or adversary emulation across web applications, mobile applications, networks, infrastructure, cloud, or identity environments.
- Practical experience with industry-standard offensive security platforms and tools, such as Cobalt Strike, Burp Suite, Metasploit, Nmap, BloodHound, Rubeus, and Impacket.
- Strong understanding of Active Directory architecture, Kerberos-based attack paths, and modern cloud identity ecosystems, including Microsoft Entra ID and OIDC/OAuth.
- Proficiency in one or more scripting or programming languages, such as Python, PowerShell, C#, C++, SQL, or Bash, for automation, payload customization, and testing defensive controls.
- Demonstrated ability to document attack paths, assess business impact, write clear technical reports, and present findings to technical and executive stakeholders.
- Bachelor’s degree in computer science, cybersecurity, or a related field, or equivalent practical industry experience.
Prior Experience :
The candidate must have 4 to 6 years of relevant experience in a similar role, preferably in a professional services organization.