Offensive Security Engineer
Core
Proactively test and identify vulnerabilities across external perimeter, standalone VPS, physical office infrastructure, and endpoint defenses to strengthen Sporty's offensive security posture.
Role type
Senior IC offensive security engineer (adversary emulation & penetration testing)
Builds
Tuned perimeter controls, firewall rules, robust defensive guardrails, and reproducible remediation blueprints
Domain
Cybersecurity, offensive security, network infrastructure
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Offensive security testing, adversary emulation, external asset discovery, DNS vulnerability assessment, Linux/Windows environment auditing, EDR/XDR bypass techniques, physical network hardware testing, web/API vulnerability testing, automation scripting, vulnerability documentation
Preferred skills
Purple team collaboration, exposure trend mapping, vulnerability gap tracking
Technologies
Kali Linux, Nmap, Shodan, Censys, Masscan, Amass, Dig, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, Git, Jira, Confluence
Responsibilities
Monitor and test the entire external attack surface including domains, subdomains, websites, and public IPs; Conduct adversary emulation exercises against internal and office endpoints; Evaluate security posture of physical office hardware and corporate network equipment; Perform scoped offensive testing on external-facing web applications and public API endpoints; Translate discovery and emulation findings into repeatable defensive checks; Support Purple Team validation of EDR policies and firewall rules; Document multi-stage exploitation chains for remediation; Support IT analysts with vulnerability descriptions and triage steps; Improve external asset tracking and exposure trend mapping
Seniority
Senior, hands-on IC