Description
I am currently recruiting an Offensive Security Specialist II on behalf of a software company operating in the cybersecurity, remote access and privileged access management space.
As a Recruitment Consultant at FED IT, I am presenting an opportunity for a security professional who is looking to work on meaningful offensive security initiatives, advanced testing engagements and innovative cybersecurity projects within a collaborative and highly technical environment.
As part of the Security team, you will be responsible for performing end-to-end offensive security assessments aimed at identifying, validating and documenting security weaknesses across applications, infrastructure and cloud environments.
Key responsibilities include:
Conduct penetration testing activities against web applications, APIs, infrastructure environments and SaaS platforms.
Identify, exploit and document application, network and system vulnerabilities.
Participate in advanced offensive security and Red Team exercises alongside senior specialists.
Validate remediation efforts and contribute to vulnerability lifecycle management.
Produce detailed technical findings, proof-of-concept documentation and risk assessments.
Support the creation of penetration testing reports and technical recommendations.
Automate recurring security validation and testing activities.
Contribute to the development and enhancement of internal offensive security tools.
Leverage AI-driven solutions to accelerate research, testing scenarios and technical analysis.
Monitor emerging threats, vulnerabilities and offensive security methodologies.
Collaborate closely with Security, Product, Development, Infrastructure and IT teams.
Participate in security reviews, audits and continuous improvement initiatives.
3 to 5 years of experience in offensive cybersecurity, penetration testing or Red Team operations.
Industry-recognized offensive security certification such as OSCP, OSCP+ or HTB CPTS.
Strong knowledge of Windows, Linux and Active Directory environments.
Experience performing web application and infrastructure security assessments.
Hands-on knowledge of vulnerability identification, exploitation and validation methodologies.
Experience with modern offensive security tools including:
Burp Suite
Nmap
Metasploit
BloodHound
Sliver
Strong technical writing and communication skills.
Ability to explain complex security risks to both technical and non-technical stakeholders.
Strong interest in artificial intelligence applications within cybersecurity.
Analytical mindset, autonomy and team-oriented approach.