Senior Offensive Security Specialist (Red Team)

GİZLİ

Fatih

On-site

TRY 450,000 - 650,000

Full time

38 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

GİZLİ is seeking a Senior Offensive Security Specialist to lead Red Team efforts, simulate real-world attacks, and strengthen detection and response capabilities. You will work across AD environments, cloud and on-premise infrastructure, delivering actionable findings and executive reports.

The role emphasizes collaboration with SOC/Blue Team, threat hunting, and security tooling automation in a fast-paced financial tech setting. Strong reporting and stakeholder communication are required.

Qualifications

  • Bachelor's degree in CS/CE or equivalent.
  • Minimum 5 years in Information Security with hands-on Red Teaming or Pen testing.
  • Experience in enterprise networks and Active Directory environments.
  • Banking/fintech or regulated industries experience is a plus.
  • Strong knowledge of AD, Kerberos, LDAP, NTLM and authentication mechanisms.
  • Familiarity with MITRE ATT&CK, NIST and threat frameworks.
  • Proficiency with Python, PowerShell, C#, or Go.

Responsibilities

  • Plan and execute Red Team operations across the organization.
  • Simulate TTPs used by real threat actors and develop ATT&CK-aligned scenarios.
  • Evaluate security controls and SOC/Blue Team detection capabilities.
  • Collaborate in Purple Team exercises and validate SIEM/EDR/XDR effectiveness.
  • Automate testing, build tools, and extend open-source security solutions.
  • Prepare technical reports and risk assessments for stakeholders.

Skills

Red Team operations
Threat modeling
Threat intelligence
Security testing
Communication

Education

Bachelor's degree in Computer Science/Computer Engineering or similar

Tools

BloodHound
SharpHound
Impacket
CrackMapExec
Mimikatz
Rubeus
Sliver
Cobalt Strike
Metasploit
Burp Suite Professional
Nmap

Job description

We are seeking a highly skilled Senior Offensive Security Specialist (Red Team) to join our Information Security team. The successful candidate will be responsible for assessing the organization's attack surface from an adversarial perspective, conducting advanced attack simulations, evaluating the effectiveness of security controls, and contributing to the enhancement of detection and response capabilities across the organization.

Job Description

  • Plan and execute Red Team operations across the organization.
  • Simulate tactics, techniques, and procedures (TTPs) used by real-world threat actors.
  • Develop attack scenarios aligned with the MITRE ATT&CK framework.
  • Assess the effectiveness of security controls and defensive technologies.
  • Evaluate the detection and response capabilities of SOC and Blue Team functions.
  • Demonstrate the business impact of security weaknesses through realistic attack simulations.
  • Perform attack path analysis within Active Directory environments.
  • Conduct privilege escalation, lateral movement, and domain compromise assessments.
  • Analyze trust relationships and authentication mechanisms within identity infrastructures.
  • Evaluate network segmentation, access controls, and infrastructure security mechanisms.
  • Perform post-exploitation activities and analyze attack surfaces of critical infrastructure components.
  • Conduct security assessments of internet banking, mobile banking, customer-facing platforms, and financial applications.
  • Assess authentication, authorization, session management, and API security controls.
  • Perform security testing of REST and SOAP-based services.
  • Collaborate closely with SOC and Blue Team teams through Purple Team exercises.
  • Validate the effectiveness of SIEM, IDS/IPS, EDR/XDR, and other security monitoring technologies.
  • Develop scripts and tools to support offensive security operations.
  • Automate repetitive testing processes and customize open-source security tools when required.
  • Research emerging attack techniques, threat trends, and adversary behaviors.
  • Analyze threat intelligence sources and translate findings into testing methodologies.
  • Provide technical recommendations to improve the organization's security posture.
  • Prepare technical reports, risk assessments, and executive summaries for stakeholders.

Qualifications

  • Bachelor's degree in Computer Science/Computer Engineering or similar academic disciplines.
  • Minimum 5 years of experience in Information Security.
  • At least 3 years of hands-on experience in Red Teaming, Offensive Security, or Penetration Testing.
  • Proven experience conducting security assessments in enterprise networks and Active Directory environments.
  • Experience in banking, financial services, fintech, or regulated industries is considered an advantage.
  • Advanced knowledge of Active Directory architecture and Windows security.
  • Strong understanding of Kerberos, LDAP, NTLM, and authentication mechanisms.
  • Advanced knowledge of TCP/IP, network protocols, and network security architectures.
  • Experience performing web, mobile, and API security assessments.
  • Familiarity with SIEM, EDR/XDR, and security monitoring technologies.
  • Knowledge of Microsoft Azure and Entra ID security architectures.
  • Understanding of IAM, PAM, and MFA technologies.
  • Hands-on experience with Active Directory attack techniques such as Kerberoasting, AS-REP Roasting, DCSync, Pass-the-Hash, Pass-the-Ticket, Golden Ticket, Silver Ticket, ACL Abuse, RBCD, and ADCS abuse.
  • Strong knowledge of OWASP Top 10 and OWASP Mobile Top 10.
  • Experience assessing REST and SOAP APIs.
  • Knowledge of OAuth2, OpenID Connect, JWT, and API Gateway architectures.
  • Proficiency with offensive security tools such as BloodHound, SharpHound, Impacket, NetExec/CrackMapExec, Mimikatz, Rubeus, Sliver, Cobalt Strike, Metasploit, Burp Suite Professional, and Nmap.
  • Proficiency in at least one programming language such as Python, PowerShell, C#, or Go.
  • Experience with security automation, custom tool development, or extending existing security tools is considered an advantage.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and NIST Cybersecurity Framework.
  • Experience conducting Purple Team operations is preferred.
  • Detection Engineering experience is considered an advantage.
  • Knowledge of EDR bypass techniques is preferred.
  • Experience performing attack simulations in cloud environments (Azure, AWS, or GCP) is a plus.
  • Experience assessing Microsoft Entra ID environments is preferred.
  • Experience in Threat Intelligence and Threat Hunting activities is considered an advantage.
  • Knowledge of Malware Analysis or Reverse Engineering is a plus.
  • Contributions to security research, technical blogs, conference presentations, or open-source projects are highly valued.
  • Relevant certifications such as OSCP, CRTP, CRTO, CRTE, OSEP, OSWE, CARTP, or PNPT are preferred.
  • Strong analytical thinking, problem-solving, and technical reporting skills.
  • Ability to communicate technical findings clearly to both technical and non-technical stakeholders.
  • Strong teamwork, collaboration, and stakeholder management skills.
  • Passion for continuous learning, research, and improving the organization's security posture.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Security Specialist
Senior Cyber Security Specialist

GİZLİ • Fatih

On-site
TRY 350,000 - 650,000
Cyber Security Architect
Cyber Security Architect

Aygaz AS • Fatih

On-site
TRY 400,000 - 700,000
Senior Infrastructure and Application Security Specialist
Senior Infrastructure and Application Security Specialist

Gizli • Fatih

On-site
TRY 300,000 - 500,000
Application Security Engineer
Application Security Engineer

n11 • Sarıyer

On-site
TRY 350,000 - 520,000
Senior Red Team Architect - Offensive Security
Senior Red Team Architect - Offensive Security

GİZLİ • Fatih

On-site
TRY 450,000 - 650,000
System and Operational Security Assistant Specialist
System and Operational Security Assistant Specialist

Wideandwise • Çankaya

On-site
TRY 260,000 - 380,000
Senior Security Engineer - Red Team (Remote)
Senior Security Engineer - Red Team (Remote)

Insider One • Fatih

Remote
TRY 600,000 - 900,000
Monthly meal allowance
Private health insurance
ESOP program
+1
Security Engineer
Security Engineer

Crs Soft • Fatih

On-site
TRY 400,000 - 640,000
Buffet breakfast
Education fund
Birthday off
+5
Identity and Access Management Specialist
Identity and Access Management Specialist

Gizli • Fatih

On-site
TRY 446,000 - 670,000
Offensive Security Specialist
Offensive Security Specialist

Etiya • Fatih

On-site
TRY 260,000 - 380,000