Offensive Security Lead Expert
Daily tasks
- Technical Leadership & Delivery: Lead and execute Attack & Penetration Testing engagements, including web/mobile app security, infrastructure testing, and cloud security assessments.
- Advanced Offensive Security: Conduct Red Team assessments, application code reviews, social engineering campaigns, threat modeling, and security architecture reviews.
- Hands-on Testing & Analysis: Perform deep-dive technical testing, analyze vulnerabilities, handle evidence securely, and craft high-quality, actionable reports.
- Risk Communication: Translate complex technical findings into business-relevant risks with clear, prioritized remediation guidance.
- Team Guidance & Mentorship: Guide, mentor, and review the work of a small team of security consultants, driving their technical growth and quality standards.
Requirements
Experience: 4+ years of hands-on experience in Dev / IT Security conducting penetration testing projects and security assessments. Offensive Security Expertise: Deep understanding of OWASP Top 10, ASVS (Application Security Verification Standards), and common attack paths across web, mobile, infrastructure, and cloud. Strong familiarity with Red Team methodologies and frameworks (e.g., MITRE ATT&CK, OSINT, Social Engineering).
Technical Fundamentals: In-depth knowledge of IT system architecture, network protocols, operating systems, and full-stack web applications (frontend to backend). Ability to provide concrete technical solutions and recommendations to mitigate vulnerabilities.
Certifications: Industry-recognized offensive certifications such as OSCP , OSWE , GPEN , or equivalent. Consulting & Soft Skills: Strong communication, structured documentation, and presentation skills to convey technical topics to non-technical stakeholders. Languages: Excellent command of English (spoken and written).
Must have: Security, Testing, OWASP, Protocols, Web applications, OSCP, OSWE