FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in Penetration Testing, Red Teaming, and Offensive Security, with a strong focus on Web Application and API Security. Proficient in developing attack scenarios, conducting security assessments, and integrating security practices into CI/CD pipelines.
Highest-signal resume keywords
Penetration TestingWeb Application SecurityAPI SecurityAdversary EmulationKali Linux
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Adversary SimulationVulnerability AssessmentAttack MethodologiesSecurity TestingAttack Automation Scripting
Tools & Technologies
Burp SuiteOWASP ZAPNmapMetasploitCobalt Strike
Certifications & Qualifications
OSCPCISSPGWAPTGPENAZ-500
Industry Keywords
MITRE ATT&CKOWASP Top 10Cloud SecurityDevSecOpsIncident Response
Tech Stack
Tools & technologiesAndroidAWSAzureCloudDockerGoogle Cloud PlatformGraphQLiOSKubernetesLinuxMicroservicesPythonSDLCSOAPSQL
About the role
Key responsibilities & impact- Conduct adversary emulation exercises and Red Team engagements
- Execute attack simulations against enterprise environments, Active Directory, cloud infrastructure and critical business applications
- Perform reconnaissance, initial access, privilege escalation, persistence, lateral movement and data exfiltration simulations
- Assess SOC, SIEM, EDR, XDR, MDR and Incident Response capabilities
- Develop custom attack scenarios based on the MITRE ATT&CK framework
- Deliver executive and technical reports with attack paths, impact analysis and remediation recommendations
- Perform manual and automated security assessments of web applications
- Identify and exploit vulnerabilities including SQL Injection, XSS, CSRF, SSRF, broken authentication, authorization bypass, business logic flaws and file upload vulnerabilities
- Perform REST, SOAP, GraphQL and microservices API security assessments
- Evaluate APIs against the OWASP API Security Top 10 and identify BOLA vulnerabilities
- Conduct Android and iOS application security assessments
- Perform static and dynamic analysis of mobile applications, including local data storage security assessment
- Configure and execute DAST scans across web applications and APIs
- Validate and triage findings
- Integrate DAST into CI/CD and DevSecOps pipelines
- Assist development teams with remediation and secure coding practices
Requirements
What you’ll need- Bachelor’s degree
- 5+ years of hands-on experience in Penetration Testing, Red Teaming, or Offensive Security
- Strong understanding of adversary simulation and attack methodologies
- Strong expertise in Web Application Security and API Security
- Knowledge of OWASP Top 10 and OWASP API Top 10
- Hands-on experience with Burp Suite, OWASP ZAP and similar tools
- Network penetration testing and vulnerability assessment experience
- Hands-on experience with Nmap, Metasploit, BloodHound, Cobalt Strike/equivalent
- Knowledge of Active Directory attack techniques
- Hands-on security testing across Azure, AWS and/or GCP
- Understanding of cloud attack paths, IAM, misconfigurations and cloud-native security
- Strong hands-on experience with Kali Linux and offensive security tooling
- Ability to develop attack/automation scripts using Python, PowerShell or Bash
- Working knowledge of MITRE ATT&CK, Secure SDLC and NIST CSF
- Preferred: OSCP, OSEP, OSWE, CRTO, CRTP, PNPT, CISSP, GWAPT, GPEN, GMOB, GXPN or AZ-500 certifications
- Good-to-have: mobile penetration testing using MobSF and Frida
- Good-to-have: secure code review and advanced application security testing
- Good-to-have: Cloud Red Teaming across Azure/AWS/GCP
- Good-to-have: Kubernetes, Docker and container security experience
- Good-to-have: integration of security testing into CI/CD pipelines, DAST, threat modeling and DevSecOps practices
- Good-to-have: Purple Team exercises and advanced adversary emulation
Benefits
Comp & perks- Laptop support with ordering
- Hybrid work arrangement
