Live opening · Posted 5 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
About the Role
We're looking for an Ethical Hacker to join our Red Team, focused on simulating real-world adversary tactics, techniques, and procedures (TTPs) to test and strengthen our organization's security posture. This is a hands-on offensive security role — you'll be actively finding and exploiting weaknesses before real attackers do, not just running scans and filing tickets.
What You'll Do
Plan and execute red team engagements, adversary simulations, and breach-and-attack simulation exercises against production and pre-production environments
Manually identify and exploit vulnerabilities across web applications, APIs, mobile apps, internal networks, and cloud infrastructure — injection flaws, authentication/authorization bypasses, business-logic abuse, IDOR/BOLA, SSRF, and privilege escalation
Conduct Active Directory attacks (Kerberoasting, Pass-the-Hash, Golden Ticket, lateral movement) to demonstrate real domain-compromise scenarios
Design and run phishing, social engineering, and physical security assessments where in scope
Map findings to MITRE ATT&CK and produce clear, evidence-backed reports with reproducible PoCs for technical and executive audiences
Collaborate with the Blue Team / SOC in purple-team exercises to validate detection coverage and close gaps
Build and maintain custom offensive tooling and scripts to support engagements (not just operate off-the-shelf scanners)
Stay current on emerging attack techniques, CVEs, and adversary TTPs relevant to our industry
Must-Have Qualifications
Hands-on experience manually finding and exploiting vulnerabilities in real environments — not just running Burp/Nessus/Nmap and forwarding output
Practical Active Directory / internal network attack experience (Kerberoasting, lateral movement, privilege escalation)
Solid understanding of MITRE ATT&CK and how to map attacker behavior to it
Comfortable scripting in Python and/or Bash to build or adapt offensive tooling
Can clearly document and present findings — root cause, impact, and reproduction steps — to both engineers and leadership
Preferred Qualifications
A public track record: CVEs, accepted bug bounty reports (with class/severity), published write-ups, or open-source security tooling contributions
Red team certifications such as CRTP, CRTA, OSCP, or equivalent hands-on (not multiple-choice) credentials
Experience with C2 frameworks (Cobalt Strike, Sliver) and EDR/AV evasion techniques
Cloud attack-path experience (AWS/Azure/GCP IAM misconfigurations, exposed storage, over-privileged roles)
Exposure to AI/LLM security — prompt injection, jailbreak testing, or MCP/agent-tool-abuse research
Experience with purple-teaming or working directly with detection/blue teams to improve coverage
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.