Offensive Security Lead - Penetration Testing
Core
Lead penetration testing and security assessments for client IT environments to identify cyber risks and improve security posture.
Role type
Senior IC offensive security lead (penetration testing)
Builds
Security testing reports, remediation recommendations, and engagement management for client environments
Domain
Cybersecurity consulting / Professional services
Deliverable
client delivery
Required skills
Penetration testing (blackbox/greybox/whitebox), vulnerability assessment, secure architecture review, wireless testing, social engineering, mobile/embedded device testing, exploit development, risk analysis, engagement management
Preferred skills
TCP/IP, scripting (Perl/Python/Bash/C), OS security (Windows/Linux/Solaris), firewall/router/VPN configuration, threat modeling, fuzzing, password cracking, commercial security tools (Nessus/Qualys/Appscan), open source tools (Kali/Metasploit/nmap/Burp Suite), security frameworks (OWASP/PTES/NIST)
Technologies
Nessus, Qualys, Appscan, Kali Linux, Metasploit, nmap, Wireshark, Burp Suite, Paros, Python, Perl, Bash, C, Windows, Linux, Solaris, AIX, HP-UX
Responsibilities
Perform analysis and testing to verify strengths and weaknesses of client IT environments; Conduct Internet, network, wireless, mobile, and embedded device penetration testing; Assist with development of remediation recommendations; Identify and articulate findings to senior management and clients; Supervise and manage other staff on assigned engagements
Seniority
Senior, hands-on IC with leadership responsibilities