Senior Offensive Security Specialist (Red Team)

Eminevim

Fatih

On-site

TRY 300,000 - 540,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Tech training
Health insurance
Social support
Special leave
Cultural programs
Competitive compensation
Mentoring program
Inclusive environment

Job summary

Eminevim is seeking a Senior Offensive Security Specialist (Red Team) to assess the organization’s attack surface from an adversarial perspective and lead advanced attack simulations.

You will develop MITRE ATT&CK–aligned scenarios, evaluate security controls, and enhance detection and response capabilities across banking-oriented systems. Collaborate with SOC and Blue Team to demonstrate business impact of security weaknesses.

Qualifications

  • Bachelor's degree in Computer Science/Computer Engineering or similar.
  • Minimum 5 years of experience in Information Security.
  • At least 3 years of hands‑on Red Teaming or Offensive Security.
  • Experience in security assessments in enterprise networks/AD environments.
  • Banking/fintech or regulated industries experience is a plus.
  • Advanced knowledge of Active Directory and Windows security.
  • Strong knowledge of Kerberos, LDAP, NTLM, and authentication mechanisms.
  • Familiarity with SIEM, EDR/XDR, and security monitoring tools.

Responsibilities

  • Plan and execute Red Team operations across the organization.
  • Simulate real-world attacker techniques and develop MITRE ATT&CK aligned scenarios.
  • Assess security controls and defensive technologies.
  • Evaluate SOC/Blue Team detection and response capabilities.
  • Demonstrate business impact of security weaknesses via attack simulations.
  • Perform Active Directory attack simulations and privilege escalation assessments.
  • Analyze trust, authentication, and network segmentation within infrastructure.
  • Collaborate with Purple Team exercises and report findings.

Skills

Red Team operations
Threat modeling
Adversarial simulations
MITRE ATT&CK
Security testing
Incident response
Technical reporting
Clear communication

Education

Bachelor's degree in Computer Science/Computer Engineering

Tools

BloodHound
SharpHound
Impacket
Mimikatz
Burp Suite Pro
Nmap
Metasploit
Cobalt Strike
Rubeus
PowerShell

Job description

About US Our company Eminevim, the leader of the savings finance sector, continues its activities as a leading brand with 164 branches across the country, nearly 3000 employees and a market share of more than 50%.

Eminevim, which has touched millions of people and enabled more than 300 thousand families to achieve their goals, has been awarded Diamond awards in the housing and automobile categories at the A.C.E. Awards Excellent Customer Satisfaction Achievement Awards in 2021 and 2022 with this approach while moving forward with the understanding of providing the best experience by meeting the expectations and needs of its customers at the highest level.

If you would like to be a part of our team that adopts the understanding of "excellence" in corporate development processes, #We Are Here For You! #Eminevim

About the Job

We are seeking a highly skilled Senior Offensive Security Specialist (Red Team) to join our Information Security team. The successful candidate will be responsible for assessing the organization’s attack surface from an adversarial perspective, conducting advanced attack simulations, evaluating the effectiveness of security controls, and contributing to the enhancement of detection and response capabilities across the organization.

Job Description
  • Plan and execute Red Team operations across the organization.
  • Simulate tactics, techniques, and procedures (TTPs) used by real-world threat actors.
  • Develop attack scenarios aligned with the MITRE ATT&CK framework.
  • Assess the effectiveness of security controls and defensive technologies.
  • Evaluate the detection and response capabilities of SOC and Blue Team functions.
  • Demonstrate the business impact of security weaknesses through realistic attack simulations.
  • Perform attack path analysis within Active Directory environments.
  • Conduct privilege escalation, lateral movement, and domain compromise assessments.
  • Analyze trust relationships and authentication mechanisms within identity infrastructures.
  • Evaluate network segmentation, access controls, and infrastructure security mechanisms.
  • Perform post-exploitation activities and analyze attack surfaces of critical infrastructure components.
  • Conduct security assessments of internet banking, mobile banking, customer-facing platforms, and financial applications.
  • Assess authentication, authorization, session management, and API security controls.
  • Perform security testing of REST and SOAP-based services.
  • Collaborate closely with SOC and Blue Team teams through Purple Team exercises.
  • Validate the effectiveness of SIEM, IDS/IPS, EDR/XDR, and other security monitoring technologies.
  • Develop scripts and tools to support offensive security operations.
  • Automate repetitive testing processes and customize open-source security tools when required.
  • Research emerging attack techniques, threat trends, and adversary behaviors.
  • Analyze threat intelligence sources and translate findings into testing methodologies.
  • Provide technical recommendations to improve the organization's security posture.
  • Prepare technical reports, risk assessments, and executive summaries for stakeholders.
Qualifications
  • Bachelor's degree in Computer Science/Computer Engineering or similar academic disciplines.
  • Minimum 5 years of experience in Information Security.
  • At least 3 years of hands‑on experience in Red Teaming, Offensive Security, or Penetration Testing.
  • Proven experience conducting security assessments in enterprise networks and Active Directory environments.
  • Experience in banking, financial services, fintech, or regulated industries is considered an advantage.
  • Advanced knowledge of Active Directory architecture and Windows security.
  • Strong understanding of Kerberos, LDAP, NTLM, and authentication mechanisms.
  • Advanced knowledge of TCP/IP, network protocols, and network security architectures.
  • Experience performing web, mobile, and API security assessments.
  • Familiarity with SIEM, EDR/XDR, and security monitoring technologies.
  • Knowledge of Microsoft Azure and Entra ID security architectures.
  • Understanding of IAM, PAM, and MFA technologies.
  • Hands‑on experience with Active Directory attack techniques such as Kerberoasting, AS-REP Roasting, DCSync, Pass-the-Hash, Pass-the-Ticket, Golden Ticket, Silver Ticket, ACL Abuse, RBCD, and ADCS abuse.
  • Strong knowledge of OWASP Top 10 and OWASP Mobile Top 10.
  • Experience assessing REST and SOAP APIs.
  • Knowledge of OAuth2, OpenID Connect, JWT, and API Gateway architectures.
  • Proficiency with offensive security tools such as BloodHound, SharpHound, Impacket, NetExec/CrackMapExec, Mimikatz, Rubeus, Sliver, Cobalt Strike, Metasploit, Burp Suite Professional, and Nmap.
  • Proficiency in at least one programming language such as Python, PowerShell, C#, or Go.
  • Experience with security automation, custom tool development, or extending existing security tools is considered an advantage.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and NIST Cybersecurity Framework.
  • Experience conducting Purple Team operations is preferred.
  • Detection Engineering experience is considered an advantage.
  • Knowledge of EDR bypass techniques is preferred.
  • Experience performing attack simulations in cloud environments (Azure, AWS, or GCP) is a plus.
  • Experience assessing Microsoft Entra ID environments is preferred.
  • Experience in Threat Intelligence and Threat Hunting activities is considered an advantage.
  • Knowledge of Malware Analysis or Reverse Engineering is a plus.
  • Contributions to security research, technical blogs, conference presentations, or open-source projects are highly valued.
  • Relevant certifications such as OSCP, CRTP, CRTO, CRTE, OSEP, OSWE, CARTP, or PNPT are preferred.
  • Strong analytical thinking, problem‑solving, and technical reporting skills.
  • Ability to communicate technical findings clearly to both technical and non‑technical stakeholders.
  • Strong teamwork, collaboration, and stakeholder management skills.
  • Passion for continuous learning, research, and improving the organization's security posture.
What We Offer
  • Technical and leadership training through Emin Academy, designed to support your career development
  • Supplementary health insurance provided for all employees
  • Social support in cases such as marriage, childbirth, and bereavement
  • Special leave days for occasions such as birthdays, children’s first day of school or report card day, and wedding anniversaries
  • Cultural and social programs for employees, nutrition consultancy, and Idea Cube (Fikir Küpü) awards
  • Competitive compensation, bonus, and reward system that recognizes and rewards success
  • “My Emin Buddy” mentoring program, ensuring fast adaptation and continuous support
  • Equal opportunities for all employees and an inclusive working environment
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Expert Technical Business Analyst
Expert Technical Business Analyst

Eminevim • Fatih

On-site
TRY 240,000 - 360,000
Emin Academy training
Supplementary health insurance
Social support
+5
Senior Technical BA & BI Developer
Senior Technical BA & BI Developer

Eminevim • Fatih

On-site
TRY 300,000 - 420,000
Emin Academy
Health insurance
Social support
+4
Security Engineer
Security Engineer

Crs Soft • Fatih

On-site
TRY 400,000 - 640,000
Buffet breakfast
Education fund
Birthday off
+5
Senior Security Engineer 'Application Security'
Senior Security Engineer 'Application Security'

Yapı Kredi Teknoloji • İzmit

Hybrid
TRY 350,000 - 520,000
Hybrid work
Koç Group offices
Career development path
+3
Senior Cyber Incident Responder
Senior Cyber Incident Responder

Softtech • Fatih

Hybrid
TRY 300,000 - 420,000
Private medical insurance
Group life insurance
Meal allowances
+5
Senior Red Team Specialist: Enterprise Attack Simulations
Senior Red Team Specialist: Enterprise Attack Simulations

Eminevim • Fatih

On-site
TRY 300,000 - 540,000
Tech training
Health insurance
Social support
+5
Senior Information Security Specialist
Senior Information Security Specialist

Pazarama • Kartal

Hybrid
TRY 420,000 - 700,000
Cyber Security Detection Engineering Manager
Cyber Security Detection Engineering Manager

Yapı Kredi Teknoloji • İzmit

Hybrid
TRY 900,000 - 1,200,000
Hybrid model
Koç Group offices access
Career development
+3
Expert Software Engineer
Expert Software Engineer

Fineksus • Fatih

Hybrid
TRY 420,000 - 660,000
Subsidized Meals
Transportation Fee
Healthcare Coverage
+7
System, Infrastructure & Security Solution Partner
System, Infrastructure & Security Solution Partner

Organik Kimya • Eyüpsultan

Hybrid
TRY 360,000 - 600,000
Great Place to Work
Top Employer
Hybrid work model (1 home office day)
+1