> Markdown version of [/jobs/ext/1604356-offensive-security-engineer](https://www.wearedevelopers.com/jobs/ext/1604356-offensive-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Offensive Security Engineer - **Company:** Sporty Group - **Location:** UK (Remote available) - **Salary:** £57,024.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Microsoft Antivirus, Software System Penetration Testing, Confluence, JIRA, Automation of Tests, Bash Shell, Burp Suite, Virtual Private Servers, Linux, Domain Name System Security Extensions, Domain Name System (DNS), Emulators, Networking Hardware, IP Addressing, Internet Protocol, Python (Programming Language), Kali Linux, Network Security, Windows Servers, Network Segmentation, Network Service, Nmap, Windows PowerShell, Red Team (Cyber Security), Wireshark, Web Applications, Network Routers, Network Access Control, Firewalls (Computer Science), Git, Information Technology, Purple Team (Cyber Security), Firewall Services Module, SentinelOne Expertise, Vulnerability Analysis, Web Api - **Published:** July 9, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5793827033 ## About the Role * Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation. * Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing. * Practical experience auditing and testing Linux and Windows environments and underlying network services. * Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions. * Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems. * Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams. * Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces. * Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery. * Good understanding of scanning, reconnaissance, and interception tools. * Strong documentation skills. Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence ## Description Mission Strengthen Sporty's offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails. What you'll be doing * Monitor, map, and test Sporty's entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses. * Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms. * Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure. * Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints. * Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks. * Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected. * Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams. * Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance. * Improve external asset tracking, perimeter health records, and exposure trend mapping. * Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)