Attiva gli avvisi di lavoro via e-mail!

Offensive Security Specialist (Red Team)

Würth Phoenix

Genova

Remoto

EUR 50.000 - 80.000

Tempo pieno

23 giorni fa

Descrizione del lavoro

A leading company in the security domain is seeking an Offensive Security Specialist to join their Red Team remotely. The successful candidate will engage in planning and executing penetration testing, collaborating with internal teams to enhance security measures across various platforms. This role offers the opportunity to work with a highly qualified team and contribute to innovative security projects on an international scale.

Servizi

Flexible working hours
Continuous training opportunities
Market-leading certifications funded
Accident and supplementary health insurance
Engagement in cultural and social events

Competenze

  • 3+ years of experience in penetration testing, red teaming, and social engineering.
  • Knowledge of Windows and Linux operating systems and their vulnerabilities.
  • Familiarity with security frameworks like OWASP and NIST.

Mansioni

  • Plan and execute penetration tests and red teaming activities.
  • Identify vulnerabilities in security postures and recommend corrective actions.
  • Collaborate with teams to support secure application development.

Conoscenze

Penetration Testing
Vulnerability Assessment
Red Teaming
Scripting (Python, PowerShell, Bash)
Problem Solving

Formazione

Degree in Computer Science or Cybersecurity

Strumenti

Burp Suite
Metasploit
BloodHound

Descrizione del lavoro

Category : R&D Location : Bolzano / Full Remote

Offensive Security Specialist (Red Team)

Are you a system breacher, adept at uncovering hidden vulnerabilities? Join our Red Team and put your skills to the test by planning and executing targeted attack simulations, developing and integrating custom tools for penetration testing and post-exploitation, thereby contributing to the security of strategically important applications.

As an Offensive Security Specialist, you will play a crucial role in identifying and exploiting vulnerabilities on both on-premises and cloud platforms, with the goal of continuously testing and improving the organization’s detection and response capabilities. You will provide detailed reports and contribute to the overall strengthening of corporate security.

Responsibilities :

  • Plan and execute penetration tests and red teaming activities on systems, applications, networks, cloud and physical infrastructures.
  • Identify vulnerabilities and gaps in clients’ security postures and propose detailed, practical corrective measures to mitigate identified risks.
  • Simulate realistic attacks to assess the effectiveness of security controls and detection and response capabilities.
  • Collaborate with internal teams to support secure application development and infrastructure protection.
  • Contribute to the creation and improvement of custom attack tools, scripts, and testing methodologies.
  • Draft technical and strategic reports to communicate offensive activity results to clients and internal stakeholders.
  • Monitor and emulate emerging trends in threat actors’ techniques, tactics, and procedures (TTPs).

Requirements :

  • Degree in Computer Science, Cybersecurity, or related fields, or equivalent industry experience.
  • At least 3 years of experience in penetration testing, red teaming, and social engineering activities.
  • Practical knowledge of tools such as Burp Suite, Metasploit, Sliver, BloodHound, and similar.
  • In-depth knowledge of Windows and Linux operating systems, with particular attention to their vulnerabilities and cybersecurity implications.
  • Familiarity with security frameworks and standards, such as OWASP, MITRE ATT&CK, and NIST.
  • Good knowledge of scripting languages (e.g., Python, PowerShell, Bash) to automate attack and analysis activities.
  • Ability to analyze and exploit vulnerabilities in applications, systems, and cloud infrastructures.
  • Excellent problem-solving skills and results-oriented mindset.
  • Autonomy in managing work tasks, as well as in communication with clients and stakeholders.

Nice to have :

  • Knowledge of distributed cloud systems (AWS, Azure, GCP, Kubernetes) and related security implications.
  • Experience in secure software development lifecycle and supply chain attacks.
  • Certifications in offensive security, such as OSCP, OSEP, CRTO, and / or cloud certifications (AWS Security Specialty, Azure Security Engineer, CKS).
  • Familiarity with advanced penetration testing techniques, exploit development, and red teaming.

We offer :

  • Collaboration with a highly qualified and motivated team.
  • Continuous training to maintain and develop professional skills.
  • Engagement in international projects involving leading security technologies and frameworks.
  • Opportunities to obtain market-leading certifications funded by the company.
  • Flexible working hours and the possibility of remote work to ensure a proper work-life balance.
  • Competitive compensation package, including a company MBO incentive system.
  • Company production bonus convertible into a wide range of Welfare goods and services.
  • Accident insurance and supplementary health insurance.
  • A young and dynamic work environment that constantly promotes events dedicated to all collaborators, such as sports activities, informal dinners, cultural visits, etc.

J-18808-Ljbffr

Ottieni la revisione del curriculum gratis e riservata.
oppure trascina qui un file PDF, DOC, DOCX, ODT o PAGES di non oltre 5 MB.