We are seeking a highly skilled and experienced Senior IT Support Engineer specializing in Offensive Security to join Information Security team. The ideal candidate will have a strong background in penetration testing, security assessments, and infrastructure security audits. This role involves identifying architectural weaknesses, planning and executing penetration tests, and conducting comprehensive security reviews across various environments.
Key Responsibilities:
Penetration Testing & Security Assessments:
- Conduct penetration tests of internal infrastructure, environments, and Internet-facing web applications.
- Perform authentication, authorization, business logic, and API security assessments.
- Identify, validate, and document security vulnerabilities based on industry standards such as OWASP Top 10 and MITRE ATT&CK.
Infrastructure Security Audits:
- Assess network, system, and application security controls.
- Conduct security reviews of cloud-native and distributed architectures, in-house cloud architectures, and physical security of company sites.
- Audit complex enterprise infrastructures including Kubernetes environments, OpenStack platforms, Apache Kafka ecosystems, Active Directory, Microsoft Entra ID, WAN and LAN network infrastructures, Linux and Windows server environments, and hybrid cloud and on-premise architectures.
Reporting & Documentation:
- Report and present findings, risk assessments, and remediation recommendations to technical and management stakeholders.
- Document penetration tests, security assessments, and audit results.
Red Team Engagements:
- Plan and execute internal red team engagements simulating realistic threat actor behavior.
- Conduct attack path analysis, privilege escalation assessments, social engineering, credential compromise, and lateral movement scenarios.
Security Improvement & Collaboration:
- Support remediation activities and security architecture improvements.
- Collaborate with system owners, platform teams, and developers to address identified weaknesses.
- Participate in security architecture reviews and technical design discussions.
- Work closely with IT, network, and application teams to identify security gaps and recommend improvements.
Methodology & Tooling Development:
- Develop and maintain testing methodologies, attack playbooks, and automation scripts.
- Contribute to the continuous improvement of offensive security capabilities and tooling.
Compliance & Awareness:
- Support compliance requirements such as ISO 27001, NIS2, and industry-specific security frameworks.
- Provide technical expertise for security-related projects and initiatives.
- Contribute to security awareness by sharing attack techniques, lessons learned, and best practices