FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive offensive security expertise, including red teaming, penetration testing, and adversary simulation, with a strong command of TTPs and MITRE ATT&CK. Proficient in building custom tooling and executing threat-led engagements across diverse environments, while effectively communicating technical findings to stakeholders.
Highest-signal resume keywords
Red Team EngagementsPenetration TestingMITRE ATT&CKCustom Tooling DevelopmentCloud Security
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Offensive SecurityThreat IntelligenceActive Directory AttacksC2 FrameworksVulnerability DiscoveryOWASP Top 10Web Application TestingAPI TestingMobile Application TestingExploitation Techniques
Soft Skills
Creative Problem-SolvingCommunication SkillsCoaching and Development
Tools & Technologies
Burp SuiteMythicSliverCobalt StrikeAWSAzureGCPEntra IDOktaCI/CD Pipelines
Certifications & Qualifications
OSCPOSEPOSWEOSEDCRTOCRTLGXPNGPENBSCP
Industry Keywords
Adversary SimulationThreat-Led TestingOperational SecurityDORA TLPTTIBER-EUCBEST
Tech Stack
Tools & technologiesAWSAzureCloudGoogle Cloud PlatformPythonRustGo
About the role
Key responsibilities & impact- Lead offensive security engagements from scoping through executive readout
- Build lasting relationships with client security teams
- Plan and execute red team, purple team, and threat-led penetration testing engagements
- Emulate real-world threat actors across on-premises, cloud, identity, and SaaS environments
- Test attack surfaces including AI/LLM-powered applications, agentic workflows, and identity platforms
- Use and build AI-assisted tooling and automation during operations
- Develop tooling and design novel attacks
- Contribute to a testing lab with tools and equipment for adversary simulation scenarios
- Partner with defenders to improve detections, response, and measurable security outcomes
- Help develop new security services based on market demand
- Coach and develop teammates
- Translate technical findings into business impact for security teams and executives
Requirements
What you’ll need- Bachelor's degree in a relevant discipline (e.g., CS, CE, IS, MIS, EE) or equivalent hands-on experience
- 5+ years of hands-on offensive security experience in red teaming, penetration testing, or adversary simulation
- Experience running red team engagements emulating real-world threat actors
- Strong command of TTPs and MITRE ATT&CK
- Ability to partner with SOC and detection engineering teams
- Experience designing threat intelligence-driven scenarios, including ransomware simulations
- Hands-on experience attacking Active Directory, cloud and identity platforms (AWS, Azure, GCP, Entra ID, Okta), and CI/CD pipelines
- Proficiency with C2 frameworks such as Mythic, Sliver, or Cobalt Strike
- Ability to build custom tooling in C#, Go, Rust, Python, or PowerShell
- Strong operational security and experience evading EDR and other monitoring tools
- Experience performing internal and external network penetration tests, including vulnerability discovery, exploitation, and privilege escalation
- Experience testing web applications, APIs, and mobile apps
- Solid grasp of the OWASP Top 10 and tools such as Burp Suite
- Ability to manually validate findings and chain issues into real attack paths
- Understanding of attacks against LLM-enabled applications and agents, including prompt injection, data leakage, and tool abuse
- Ability to produce clear, actionable reports and communicate with technical teams and executives
- Creative problem-solving ability
- Successful completion of a background check
- Familiarity with DORA TLPT, TIBER-EU, or CBEST is a plus
- Exploit development or reverse engineering skills are a plus
- Research, tool releases, blogs, or conference involvement is a plus
- Certifications such as OSCP, OSEP, OSWE, OSED, CRTO/CRTL, GXPN, GPEN, BSCP, or comparable SANS 600/700-level coursework are a plus
- Cloud security certifications are a plus
Benefits
Comp & perks- Annual bonus plan with 12% bonus target opportunity and/or discretionary stock compensation opportunities
- Medical, dental, and vision coverages
- FSA and HSA healthcare accounts
- Life and accident insurance
- Adoption and fertility assistance
- Paid parental leave up to 10 weeks
- Short-term and long-term disability
- 401(k) savings and investment plan with an employer match of 50% on the first 6% of contributions
- Choice Time Off (CTO) for vacation, personal needs, and sick time; new hires receive up to 20 days per calendar year
- Up to 11 paid holidays each calendar year
- Hybrid work model with remote work and purposeful in-person work
- Professional development through tooling, research, training, and new service development
- Support for presenting at local, national, and international security conferences
- Collaborative and inclusive culture
- Local, national, and international security conference involvement
