Offensive Security Engineer

Offensys

's-Hertogenbosch

Hybrid

EUR 45,000 - 78,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Direct influence on attack library
Autonomy and ownership
Research time and tooling budget
AI-assisted coding tools access
25 vacation days
Hybrid work near Den Bosch

Job summary

Offensys is building a platform to continuously validate security postures through realistic attack simulations. As Founding Offensive Security Engineer, you’ll turn adversary behavior into high-quality simulations and reusable capabilities that scale across hundreds of organizations.

You’ll shape the attack library, decide priorities, and drive quality and innovation in a fast-evolving threat landscape from our Den Bosch office.

Qualifications

  • Experience in offensive security and threat emulation.
  • Ability to translate real-world threat reports into reliable simulations.
  • Proven capability to build reusable offensive capabilities and tooling.

Responsibilities

  • Research emerging threats, adversary behavior, and threat intel reports.
  • Translate real-world TTPs into reliable, reproducible attack simulations.
  • Reproduce, analyze, and operationalize malware techniques and offensive tradecraft.
  • Identify the best way to simulate procedures, from scripting to low-level implementations.
  • Expand and maintain the Offensys attack library.
  • Improve the realism, quality, and effectiveness of simulations.
  • Build tooling and automation to accelerate research and content development.
  • Collaborate with platform engineers to integrate offensive capabilities into the product.
  • Leverage customer feedback to influence future development.

Skills

Offensive security
Red teaming
Threat emulation
Malware development
Malware analysis
Reverse engineering
Security research
Security tooling development

Tools

PowerShell
BOFs
Malware analysis tools

Job description

At Offensys, we're building the platform that enables enterprise security teams to continuously validate their own defenses. We simulate real-world attacker tradecraft, so organizations don't have to guess whether or not they are secure. With Offensys, they know.

Our mission is simple: to enable our clients to stay ahead of the threat.

At the heart of that mission sits our attack library: a growing collection of realistic, reproducible adversary techniques that allows organizations to continuously validate their security posture against real-world threats.

We're looking for someone who wants to help build and own that foundation.

The Role

As Founding Offensive Security Engineer, you'll sit at the intersection of offensive security, threat intelligence, research, and engineering. You'll be responsible for turning real-world adversary behavior into high-quality attack simulations that help our customers understand their true resilience. You're comfortable implementing procedures ranging from simple scripts to complex, low-level native code that will be run in-memory, and can identify the best way to simulate a given technique while balancing realism, reliability, and development effort.

This is not a role for someone who wants to run the same assessments over and over again. You won't spend your days stitching together one-off exploits or writing reports that disappear into a drawer.

Instead, you'll build reusable offensive capabilities for a platform that can scale across hundreds of organizations. You'll help decide which techniques belong in our attack library, what we prioritize next, how we maintain quality, and how we stay aligned with an ever-evolving threat landscape.

Within a year, you'll be one of the key owners of the offensive knowledge and tradecraft that differentiates Offensys from everyone else.

What you'll do

Most offensive security roles focus on delivering engagements. This role focuses on building capability. Every technique you research, every simulation you create, and every improvement you make becomes part of a platform that helps organizations continuously validate their defenses. Rather than impacting a single assessment or client, your work will influence many security teams and thousands of security decisions.

Your Responsibilities Will Be To
  • Research emerging threats, adversary behavior, and threat intelligence reports.
  • Translate real-world TTPs into reliable, reproducible attack simulations.
  • Reproduce, analyze, and operationalize malware techniques and offensive tradecraft.
  • Identify the best way to simulate a procedure, ranging from PowerShell scripts to low-level, custom Beacon Object Files (BOFs).
  • Expand and maintain the Offensys attack library.
  • Continuously improve the quality, realism, and effectiveness of our simulations.
  • Build tooling and automation that accelerates research and content development.
  • Work closely with platform engineers to integrate offensive capabilities into the product.
  • Leverage customer feedback and real-world use cases to influence future development.
Who we're looking for

We're looking for someone with a genuine passion for offensive security and a deep curiosity about how attackers operate. Someone who can take a vague threat report, piece together the missing details, and transform it into a meaningful simulation that provides value to customers. You understand that offensive security is ultimately about helping defenders make better decisions. You are forward-thinking, embrace new technologies, and actively leverage AI and automation to increase your effectiveness while maintaining a high bar for quality and accuracy.

Ideally, you bring experience in one or more of the following areas:
  • Offensive security
  • Red teaming
  • Threat emulation
  • Malware development
  • Malware analysis
  • Reverse engineering
  • Detection engineering
  • Security research
  • Security tooling development

You're comfortable writing (low-level) code and building automations. You enjoy investigating how things work, breaking them apart, and turning that knowledge into reusable capabilities.

Experience with endpoint tradecraft, adversary emulation, platform development, or certifications such as OSCP, OSED, OSCE3, CRTO, or CRTL is valuable, but not required.

Open-source contributions, research projects, blog posts, conference talks, or publicly visible work tell us more than a CV full of buzzwords.

What we offer
  • Direct influence on and ownership of the content, quality, and direction of our attack library.
  • Close collaboration with the founders from day one.
  • A high degree of autonomy.
  • Time and freedom for research, experimentation, and innovation.
  • Access to and budget for modern development tooling, including the latest and greatest AI-assisted coding tools.
  • A competitive salary between €4,000 and €7,000 gross per month, depending on experience and profile.
  • 25 vacation days.
  • Hybrid working, with approximately two days per week at our office in Den Bosch (near Central Station).

You'll be one of the first offensive security hires at Offensys. That means you'll help shape not only the library, but also the engineering culture, technical standards, and ways of working that will define the company as it grows. If you're excited about building a category-defining security product and want to have an impact on its future, we'd love to hear from you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Platform Engineer
Platform Engineer

Offensys • 's-Hertogenbosch

Hybrid
EUR 56,000 - 89,000
Influence on product
Founder collaboration
High autonomy
+5
Founding Offensive Security Engineer: Build Attacks
Founding Offensive Security Engineer: Build Attacks

Offensys • 's-Hertogenbosch

Hybrid
EUR 45,000 - 78,000
Direct influence on attack library
Autonomy and ownership
Research time and tooling budget
+3
Senior Offensive Security Engineer
Senior Offensive Security Engineer

bol.com • Netherlands

On-site
EUR 90,000 - 130,000
Security Lead
Security Lead

Hamlyn Williams • Amsterdam

Hybrid
8% holiday allowance
Pension
Training Budget
Security Engineer
Security Engineer

Software Search • Netherlands

Hybrid
EUR 100,000 - 123,000
Permanent contract
Training budget and security community
Software Engineer
Software Engineer

Hadrian • Amsterdam

On-site
EUR 60,000 - 80,000
Unlimited paid holiday
Stock options package
Mobile phone stipend
+3
Security Automation Engineer
Security Automation Engineer

Northwave • Utrecht

Hybrid
EUR 50,000 - 70,000
Competitive salary with annual review
Pension contributions
25 vacation days plus national holidays
+3
Security Software Engineer (Junior)
Security Software Engineer (Junior)

United States Digital Space LLC • Delft

Hybrid
EUR 60,000 - 85,000
Thirteenth month salary
8% holiday allowance
Pension scheme
+5
Staff Cybersecurity Specialist - Incident Response (f/m/x)
Staff Cybersecurity Specialist - Incident Response (f/m/x)

Eye Security • Netherlands

On-site
EUR 70,000 - 90,000
Generous time-off policy
Remote-friendly culture
Quarterly meetups
+1
Security Consultant
Security Consultant

Software Search • Netherlands

Hybrid
EUR 102,000 - 122,000
Permanent contract
Project variety and autonomy
Competitive compensation
+4