Sr Offensive Security Engineer

First Advantage

India

On-site

INR 2,000,000 - 2,800,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

First Advantage is seeking a senior Offensive Security Engineer to join its Threat Management & Security Operations team.

In this hands‑on role, you will think and operate like an adversary—designing and executing penetration tests, red and purple team engagements, and adversary emulation to validate detection and response capabilities across First Advantage’s products, cloud infrastructure, networks, and people.

Qualifications

  • 5+ years of hands-on experience in offensive security, penetration testing, red teaming, or a closely related security engineering role.
  • Demonstrated expertise across web/mobile application, API, network, infrastructure, and cloud penetration testing.
  • Proficiency with Burp Suite Professional, Nmap, Metasploit, and Kali Linux, along with vulnerability scanners.
  • Proficiency in at least one scripting or programming language (e.g., Python, Go, PowerShell, Ruby, or Bash).
  • Working knowledge of the MITRE ATT&CK framework and mapping engagements to adversary TTPs.
  • Excellent written and verbal communication skills, with the ability to present findings to technical and executive audiences.

Responsibilities

  • Penetration testing across web, mobile, APIs, cloud, networks, and infrastructure.
  • Red and purple team engagements to validate detection and response capabilities.
  • Exploit development and chaining to demonstrate real-world impact.
  • Adversary emulation mapped to MITRE ATT&CK to stress defenses.
  • Reviewing findings for accuracy and prioritizing business risk; coordinating remediation.

Skills

Penetration testing
Red team
Adversary emulation
Exploit development
Tooling & automation
Python
PowerShell
MITRE ATT&CK
Burp Suite
Nmap
Metasploit
Kali Linux
Communication skills

Tools

Burp Suite Professional
Nmap
Metasploit
Kali Linux
Cloud & DevOps tooling

Job description

What You'll Do We are seeking a highly skilled and motivated Senior Offensive Security Engineer to join our Threat Management & Security Operations organization. In this hands-on role, you will think and operate like an adversary - continuously finding, exploiting, and helping remediate real-world weaknesses across First Advantage 's products, cloud infrastructure, networks, and people. You will design and execute penetration tests, red and purple team engagements, and adversary emulation exercises that validate our detection and response capabilities and measurably reduce enterprise risk at-scale. This role partners closely with Security Operations, Threat Intelligence & Hunt, Vulnerability Management, Application Security, DevOps, and Product teams to turn offensive findings into prioritized, business-aligned remediation. The ideal candidate is equally comfortable building custom tooling, chaining exploits across complex environments, and communicating impact clearly to both technical teams and executive leadership.

Penetration Testing

Plan, scope, and execute internal and external penetration tests across web and mobile applications, APIs, cloud (AWS/Azure), networks, and infrastructure using real-world attacker techniques.

Red & Purple Teaming

Design and run adversary emulation and red team engagements that combine multiple attack paths to accomplish objective-based goals, and partner with the SOC, Threat Intel & Hunt, and Detection Engineering on purple team exercises to validate and improve detection coverage.

Exploit Development & Chaining

Identify, validate, and safely exploit vulnerabilities - including chaining lower-severity issues into high-impact attack paths - and demonstrate tangible business impact in production-representative environments.

Adversary Emulation

Model real-world threat actor tactics, techniques, and procedures (TTPs) mapped to the MITRE ATT&CK framework to test and strengthen organizational resilience, detection, and response.

Findings & Remediation

Review and validate findings for accuracy, prioritize real-world exploitability and business risk, create remediation tickets, and partner with engineering teams to drive fixes and coordinate retests within policy SLAs.

Tooling & Automation

Build and maintain custom scripts, tooling, and automation to scale offensive testing, and help operationalize continuous/autonomous testing platforms across the environment.

Reporting & Communication

Produce clear, decision-ready reports and executive summaries that translate technical findings into risk and business impact for technical stakeholders, GRC/Audit, and executive leadership.

Incident Response Support

Support incident response and threat hunting efforts by providing offensive expertise, attack-path context, and adversary insight.

Continuous Improvement

Contribute to the maturity of the offensive security program - developing repeatable methodologies, playbooks, and metrics that demonstrate progress over time.

What You Will Need to be Successful

5+ years of hands-on experience in offensive security, penetration testing, red teaming, or a closely related security engineering role. Demonstrated expertise across multiple domains: web/mobile application, API, network, infrastructure, and cloud (AWS and/or Azure) penetration testing. Strong understanding of exploitation and post-exploitation techniques, attack-path chaining, and objective-based adversary emulation. Proficiency with industry-standard offensive tooling such as Burp Suite Professional, Nmap, Metasploit, and Kali Linux, along with vulnerability scanners. Proficiency in at least one scripting or programming language (e.g., Python, Go, PowerShell, Ruby, or Bash) to build custom tools and automation. Working knowledge of the MITRE ATT&CK framework and hands-on experience mapping engagements to adversary TTPs. Excellent written and verbal communication skills, with the ability to present findings to both technical audiences and executive leadership.

What You May Need to be Successful

Advanced offensive certifications (e.g., OSEP, OSCE³, CRTO, GXPN) and a track record of original security research, CVEs, or responsible disclosures. Experience with cloud-native attack techniques and container/Kubernetes (EKS/AKS) and serverless security testing. Experience operating or evaluating continuous/autonomous pen testing and breach-and-attack-simulation platforms. Familiarity with detection engineering, SIEM/EDR platforms, and building purple team feedback loops into SOC content. Knowledge of compliance and security frameworks relevant to our environment. Experience mentoring junior engineers and helping mature an offensive security program.

Why Join Us at First Advantage

At First Advantage , team members are united around a noble purpose: helping organizations to safeguard their workplaces and manage risk. The company's culture is shaped by its core values - Authenticit

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Offensive Security Engineer
Sr Offensive Security Engineer

LM Wind Power / GE • Bengaluru

Hybrid
INR 3,500,000 - 7,000,000
Generous Paid Time Off
Volunteer Time Off (VTO)
Competitive benefits
+1
Senior Manager, Attack Surface Reduction
Senior Manager, Attack Surface Reduction

NopalCyber • Hyderabad

On-site
INR 2,600,000 - 3,800,000
Cyber Security Engineer
Cyber Security Engineer

Evoke HR • Mumbai

On-site
INR 1,500,000 - 2,700,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Jobtailor • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Associate Cybersecurity Consultant
Associate Cybersecurity Consultant

Security Brigade • Mumbai

Hybrid
INR 800,000 - 1,200,000
Competitive salary aligned to experience
Hybrid + remote-friendly
Sponsorship for offensive security certifications
+2
Red Team Specialist
Red Team Specialist

ESP Engineered • Mumbai

On-site
INR 1,200,000 - 2,000,000
Cutting-edge Red Team engagements
Collaborative environment
Continuous learning opportunities
Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Application Security Consultant
Application Security Consultant

SecurityBoat Cybersecurity Solutions Private Limited • Mumbai

On-site
INR 1,200,000 - 2,200,000
Competitive compensation
Specialized cybersecurity team
Professional development
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Principal Penetration Tester/ Offensive Security Team Lead
Principal Penetration Tester/ Offensive Security Team Lead

BreachLock, Inc. • Dadri

On-site
INR 1,500,000 - 2,000,000