The Cybersecurity Offensive Security Specialist is responsible for conducting advanced security assessments, penetration testing, red team operations, and security reviews across web applications, APIs, mobile applications, networks, cloud environments, IoT devices, and Operational Technology (OT) systems. The role focuses on identifying vulnerabilities, validating security controls, simulating real-world cyberattacks, and providing actionable remediation recommendations to improve the organization’s security posture.
Key Responsibilities
Red Teaming & Adversary Emulation
- Conduct advanced red team exercises simulating real-world threat actors.
- Execute attack scenarios aligned with MITRE ATT&CK framework.
- Perform phishing campaigns, credential attacks, social engineering simulations, and lateral movement exercises.
- Assess cyber defense effectiveness including SOC, SIEM, EDR
- Develop custom attack techniques and proof-of-concept exploits.
- Conduct Purple Team exercises with security monitoring teams.
Penetration Testing
External & Internal Infrastructure
- Perform black-box, gray-box, and white-box penetration testing.
- Assess internal and external network environments.
- Identify vulnerabilities in:
- Active Directory
- Windows and Linux systems
- Databases
- Virtualization environments
- Cloud platforms
- Validate remediation effectiveness through re-testing activities.
Web Application Security Assessments
- Conduct security assessments against web applications using OWASP Testing Methodology.
- Identify vulnerabilities including:
- SQL Injection
- Cross-Site Scripting (XSS)
- Authentication flaws
- Session management weaknesses
- CSRF
- Access control issues
- File upload vulnerabilities
- Business logic flaws
- Perform manual exploitation and validation of findings.
- Review security architecture and secure coding controls.
API Security Assessments
- Conduct security testing of REST, SOAP, GraphQL, and Microservices APIs.
- Identify:
- Broken Object Level Authorization (BOLA)
- Broken Authentication
- Excessive Data Exposure
- SSRF Vulnerabilities
- Insecure Direct Object References
- JWT Security Weaknesses
- API Abuse Scenarios
- Assess API Gateway implementations and security controls.
- Review API documentation and specifications.
Mobile Application Security Assessments
Android
- Perform static and dynamic security assessments.
- Analyze APK packages and mobile application architecture.
- Evaluate local storage security, cryptography implementation, and backend integrations.
iOS
- Assess iOS application security controls.
- Perform runtime security analysis.
- Test jailbreak protections and application hardening mechanisms.
Mobile Security Areas
- Reverse engineering
- SSL Pinning bypass testing
- Data leakage assessments
- Secure storage validation
- Root/Jailbreak detection testing
- Mobile API security testing
IoT Security Assessments
- Conduct security assessments of Internet of Things (IoT) devices.
- Evaluate:
- Device firmware security
- Wireless communication protocols
- Authentication mechanisms
- Device hardening controls
- Embedded operating systems
- Perform firmware extraction and analysis.
- Identify insecure configurations and exposed services.
Security Reporting & Stakeholder Engagement
- Produce high-quality technical and executive security assessment reports.
- Present findings to technical and business stakeholders.
- Provide practical remediation recommendations.
- Assist asset owners with vulnerability remediation planning.
- Track remediation progress and perform validation testing.
Required Technical Skills
Offensive Security
- Red Team Operations
- Threat Emulation
- Penetration Testing Methodologies
- MITRE ATT&CK
- Cyber Kill Chain
Web & API Security
- OWASP Top 10
- OWASP API Security Top 10
- Burp Suite Professional
- Postman
- JWT, OAuth2, OpenID Connect
Mobile Security
- MobSF
- Frida
- Objection
- APKTool
- JADX
- Burp Suite Mobile Testing
Infrastructure Security
- Active Directory Security
- Windows Security
- Linux Security
- Network Security
- Wireless Security
IoT & OT Security
- Embedded Device Security
- Firmware Analysis
Scripting & Automation
- Python
- PowerShell
- Bash
- API Automation
Education
- Bachelor\'s Degree in Cybersecurity, Computer Science, Information Technology, Computer Engineering, or related field.
Experience
- 4+ years of hands‑on penetration testing experience.
- Proven experience in:
- Red Teaming
- Web Application Security
- API Security Testing
- Mobile Security Assessments
- IoT/OT Security Assessments
Preferred Certifications
Essential (One or More)
- OSCP
- PNPT
- CRTO
- OSEP
- OSWE
- eWPTX
- eMAPT
- GMOB
- GICSP
- GRID
- GPEN
- GWAPT
- CARTP