FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in offensive security, including red teaming and penetration testing, with a strong command of TTPs and MITRE ATT&CK. Proficient in building custom tooling and emulating real-world threat actors across various environments, while effectively communicating technical risks to stakeholders.
Highest-signal resume keywords
Red Team EngagementsPenetration TestingTTPs and MITRE ATT&CKC2 Frameworks (Mythic, Sliver, Cobalt Strike)Custom Tooling Development (C#, Go, Rust, Python, PowerShell)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Offensive SecurityThreat Intelligence-Driven ScenariosActive Directory AttacksCloud Security (AWS, Azure, GCP)Vulnerability Discovery and ExploitationWeb Application TestingAPIs and Mobile Apps TestingOWASP Top 10Evading EDRAutomation and AI-Assisted Tooling
Soft Skills
Strong Communication SkillsCoaching and MentoringRelationship BuildingReport WritingCollaboration with Security Teams
Tools & Technologies
Burp SuiteEDR Monitoring ToolsCI/CD PipelinesSaaS EnvironmentsAdversary Simulation Tools
Certifications & Qualifications
OSCPOSEPOSWEOSEDCRTO/CRTLGXPNGPENBSCPCloud Security Certifications
Industry Keywords
DORA TLPTTIBER-EUCBESTRansomware SimulationsAdversary Simulation
Tech Stack
Tools & technologiesAWSAzureCloudGoogle Cloud PlatformPythonRustGo
About the role
Key responsibilities & impact- Lead red team, purple team, and threat-led penetration testing (TLPT) engagements from scoping through executive readout
- Emulate real-world threat actors across on-premises, cloud, identity, and SaaS environments
- Test attack surfaces including AI/LLM-powered applications, agentic workflows, and identity platforms
- Use and build AI-assisted tooling and automation during operations
- Develop new tooling and design novel attacks
- Contribute to a robust lab of testing tools and equipment for adversary simulation scenarios
- Partner with defenders to improve detections, response, and measurable security outcomes
- Build lasting relationships with client security teams and advise them on exploitation paths and remediation priorities
- Translate technical risk into business impact for security teams and executives
- Coach and develop teammates through engagement guidance and training
- Scope, execute, report on, and present offensive security engagements
- Help develop new security services based on emerging client demand
Requirements
What you’ll need- Bachelor's degree in a relevant discipline (e.g., CS, CE, IS, MIS, EE) or equivalent hands-on experience
- 5+ years of hands-on offensive security experience in red teaming, penetration testing, or adversary simulation, in consulting or in-house
- Experience running red team engagements emulating real-world threat actors
- Strong command of TTPs and MITRE ATT&CK
- Ability to partner with SOC and detection engineering teams to improve detection and response
- Experience designing threat intelligence-driven scenarios, including ransomware simulations
- Hands-on experience attacking Active Directory, cloud and identity platforms (AWS, Azure, GCP, Entra ID, Okta), and CI/CD pipelines
- Proficiency with C2 frameworks such as Mythic, Sliver, or Cobalt Strike
- Ability to build custom tooling in C#, Go, Rust, Python, or PowerShell
- Strong OpSec and experience evading EDR and other monitoring tools
- Experience performing internal and external network penetration tests, including vulnerability discovery, exploitation, and privilege escalation
- Experience testing web applications, APIs, and mobile apps
- Solid grasp of the OWASP Top 10 and tools such as Burp Suite
- Understanding of attacks against LLM-enabled applications and agents, including prompt injection, data leakage, and tool abuse
- Ability to produce clear, actionable reports and conversations for technical teams and executives
- Strong written and verbal communication skills
- Successful completion of a background check is required for any employment offer
- Certifications such as OSCP, OSEP, OSWE, OSED, CRTO/CRTL, GXPN, GPEN, BSCP, or comparable SANS 600/700-level coursework are a plus
- Cloud security certifications are a plus
- Familiarity with DORA TLPT, TIBER-EU, or CBEST is a plus
- Research, tool releases, blogs, or conference involvement is a plus
Benefits
Comp & perks- Annual bonus plan with 12% bonus target opportunity and/or discretionary stock compensation opportunities
- Medical, dental, and vision coverages
- FSA and HSA healthcare accounts
- Life and accident insurance
- Adoption and fertility assistance
- Paid parental leave up to 10 weeks
- Short- and long-term disability
- 401(k) savings and investment plan with employer match of 50% on the first 6% of contributions
- Choice Time Off (CTO) for vacation, personal needs, and sick time; new hires receive up to 20 days per calendar year
- Up to 11 paid holidays each calendar year
- Hybrid work model combining purposeful in-person work with remote work
- Support for presenting at local, national, and international security conferences
- Support to develop tooling, research new techniques, and create new services
