REMOTE- Senior Penetration Tester / Offensive Security Specialist

Digitive LLC
United States
about 1 month ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Private Networks Artificial Intelligence Software System Penetration Testing Burp Suite Cloud Computing Linux Fat Client Python (Programming Language) Linux System Administration Microsoft Security Essentials Nmap
+14 more
Red Team (Cyber Security) Web Application Security SQL Injection Wireshark Web Applications Wireless Networks Scripting Software Security Mitre Att&ck Cyber Threat Analysis Cross-Site Scripting (XSS) Metasploit Purple Team (Cyber Security) Blue Team (Cyber Security)

Job description

Seeking an experienced Penetration Testing and Offensive Security Specialist to lead and execute advanced adversarial simulations across enterprise environments. The role focuses on identifying exploitable weaknesses across network, application, cloud, human, and physical layers, emulating real-world attacker techniques. The ideal candidate will bring hands-on expertise in multi-vector penetration testing, red teaming, exploit development, and adversarial simulation, with the ability to provide actionable remediation insights to strengthen enterprise security posture., 1. Penetration Testing & Red Team Operations

  • Conduct end-to-end penetration testing engagements, including:
  • Internal network assessments
  • External perimeter testing
  • Web application and API security testing
  • Cloud and container security testing
  • Mobile (iOS) and thick client application assessments
  • Wireless infrastructure testing
  • Execute advanced attack simulations to emulate real-world adversary tactics, * Identify, validate, and exploit vulnerabilities using techniques such as:
  • SQL Injection
  • Cross-Site Scripting (XSS)
  • Privilege Escalation
  • Credential harvesting and manipulation
  • Perform:
  • Vulnerability chaining and lateral movement simulations
  • Post-exploitation persistence and privilege escalation
  • Provide risk-rated findings with clear remediation guidance, * Develop and maintain:
  • Custom exploitation scripts and toolkits
  • Automation workflows for reconnaissance and exploitation
  • Leverage:
  • Python scripting and Linux toolchains
  • AI/GenAI-assisted tooling for attack simulation and reconnaissance, * Collaborate with defensive teams to:
  • Validate detection and response capabilities
  • Simulate attack scenarios and measure control effectiveness
  • Support:
  • Breach simulations
  • Ransomware scenario testing

Requirements

Core Technical Skills

  • Proven experience in:
  • Multi-vector penetration testing (Network, Web, Cloud, Mobile, Wireless, Physical)
  • Red teaming and adversary emulation
  • Exploit execution and vulnerability validation
  • Strong understanding of:
  • MITRE ATT&CK framework
  • Modern attack techniques and threat actor TTPs, + Nmap, Wireshark, Burp Suite, Metasploit (or similar toolsets)
  • Experience with:
  • Web application security tools
  • Network and protocol analysis tools __________________

Automation & Scripting

  • Strong development experience in:
  • Python
  • Linux environments
  • Ability to build:
  • Custom scripts, payloads, and automation frameworks __________________

Complementary Experience (Preferred)

  • Exposure to:
  • Investigations and compromise assessments
  • Threat Intelligence and IOC analysis
  • Experience participating in:
  • Red Team vs Blue Team or Purple Team exercises, * Offensive Security Certified Professional (OSCP)
  • Certified Ethical Hacker (CEH)
  • GIAC Security Essentials (GSEC)
  • Other advanced Red Team or exploit development certifications are a plus

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

3:19 min

Setting up a vulnerable test application and monitoring environment

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC 2024

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · WWC Europe 2026

1:19 min

Enhancing product safety through continual red teaming operations

Rebekka Weiss Rebekka Weiss +1 · WWC 2025

1:48 min

Analyzing network packets with database protocol tools

Daniël van Eeden Daniël van Eeden · WWC Europe 2026

Videos

See all

Related articles

See all