Offensive Security Engineer

Sporty Group

United States

Remote

USD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Remote-first company
Quarterly bonuses
28 days annual leave
Core hours 10am-3pm in local time zone
Referral bonuses

Job summary

Sporty Group is seeking an Offensive Security Engineer to strengthen its external security posture by testing perimeters, DNS configurations, and public assets. You will run adversary emulation, validate EDR/XDR coverage, and translate findings into practical defense improvements.

You will document chains of exploitation and provide blueprints for remediation, collaborating with IT, SOC, and security teams worldwide.

Qualifications

  • Experience in offensive security, perimeter testing, or adversary emulation.
  • Understanding of external asset discovery, DNS vulnerabilities, and public IP routing.
  • Experience auditing Linux and Windows environments and network services.
  • Ability to emulate adversaries and bypass EDR/XDR solutions.
  • Turn external exposures into actionable fixes for IT and security teams.

Responsibilities

  • Monitor and test Sporty's external attack surface and assets.
  • Conduct adversary emulation on endpoints to validate EDR/XDR/SOC effectiveness.
  • Evaluate security of physical office hardware and internal edge infrastructure.
  • Perform scoped tests on web apps and public API endpoints.
  • Translate findings into repeatable defensive checks and remediation blueprints.
  • Support IT with vulnerability descriptions, triage steps, and escalation guidance.
  • Document exposure trends and perimeter health records.

Skills

Offensive security
Adversary emulation
EDR/XDR
Python scripting
PowerShell
Bash
Linux
Windows
Network security
Documentation

Education

Tools

Nmap
Shodan
Censys
Masscan
Amass
Dig/DNS tools
Wireshark
Burp Suite
OWASP ZAP
Microsoft Defender XDR
CrowdStrike Falcon
SentinelOne
Atomic Red Team
Caldera
Python
PowerShell
Bash
Kali Linux
Jira
Confluence

Job description

About the role

Mission Strengthen Sporty's offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails.

What you'll be doing
  • Monitor, map, and test Sporty's entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses.
  • Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms.
  • Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure.
  • Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints.
  • Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks.
  • Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected.
  • Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams.
  • Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance.
  • Improve external asset tracking, perimeter health records, and exposure trend mapping.
  • Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure.
What you'll bring
  • Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation.
  • Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.
  • Practical experience auditing and testing Linux and Windows environments and underlying network services.
  • Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.
  • Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.
  • Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.
  • Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.
  • Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.
  • Good understanding of scanning, reconnaissance, and interception tools.
  • Strong documentation skills.

Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence

What's in it for you
  • Sporty is a remote-first company in pursuit of sustainability
  • A competitive salary plus individual performance-based bonuses every quarter
  • 28 days paid annual leave
  • Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours
  • Referral bonuses and flash bonuses
  • Top-of-the-line equipment
  • Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world
Interview Process:
  • Remote video screening with our Talent Acquisition Team
  • Online assessment via Hackerrank
  • Remote video interview with Team Members (60 Mins)
  • Final discussion with the hiring manager (60 mins)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Hybrid QA Engineer
Lead Hybrid QA Engineer

sportygroup • United States

Remote
USD 120,000 - 160,000
Remote-first
Bonuses quarterly
Paid leave 28 days
+4
Hybrid QA Engineer
Hybrid QA Engineer

sportygroup • United States

Remote
INR 8,637,000 - 12,476,000
Remote-first culture
Performance bonuses quarterly
28 days annual leave
+2
Offensive Security Consultant
Offensive Security Consultant

NEPSE Trading • Northern (KY)

On-site
USD 120,000 - 150,000
Health insurance
Paid holidays
401(k) with company match
+2
Remote Offensive Security Engineer – Perimeter & Emulation
Remote Offensive Security Engineer – Perimeter & Emulation

Sporty Group • United States

Remote
USD 120,000 - 180,000
Remote-first company
Quarterly bonuses
28 days annual leave
+2
Hybrid QA Engineer
Hybrid QA Engineer

Sporty Group • United States

Remote
USD 90,000 - 135,000
Remote-first company
Performance-based bonuses
28 days paid annual leave
+4
Penetration Tester - Infrastructure & Red Team
Penetration Tester - Infrastructure & Red Team

Cybersecurity Jobs • Town of Texas (WI)

On-site
USD 90,000 - 130,000
Flexible work environment
Paid education reimbursement
Volunteer day
Penetration Tester - Infrastructure & Red Team
Penetration Tester - Infrastructure & Red Team

Cybersecurity Jobs • Miami (FL)

Hybrid
USD 90,000 - 130,000
Education reimbursement
Volunteer day
Birthday day off
+2
Sales Engineer (Presales)
Sales Engineer (Presales)

Sprocket Security • Chicago (IL)

On-site
USD 70,000 - 110,000
Unlimited PTO
Company matched 401k
Comprehensive health insurance
+1
Senior Offensive Security Engineer
Senior Offensive Security Engineer

United States Digital Space LLC • Bellevue (NY)

On-site
USD 187,000 - 220,000
Health insurance
Equity
Wellness allowance
+4
Principal Offensive Security Engineer
Principal Offensive Security Engineer

Jobs Paloaltonetworks • California (MO)

On-site
USD 170,000 - 275,000