Senior Offensive Security Engineer

Posted 11hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior offensive security engineer testing First Advantage’s products, cloud infrastructure, networks, and people. Building adversary simulations and driving remediation to reduce enterprise risk.

Responsibilities:

  • Plan, scope, and execute internal and external penetration tests across web and mobile applications, APIs, AWS/Azure cloud, networks, and infrastructure
  • Design and run adversary emulation and red team engagements using multiple attack paths and objective-based goals
  • Partner with Security Operations, Threat Intelligence & Hunt, Detection Engineering, Vulnerability Management, Application Security, DevOps, and Product teams on purple team exercises and remediation
  • Identify, validate, and safely exploit vulnerabilities, including chaining lower-severity issues into high-impact attack paths
  • Model threat actor tactics, techniques, and procedures using the MITRE ATT&CK framework
  • Review findings, prioritize exploitability and business risk, create remediation tickets, drive fixes, and coordinate retests
  • Build and maintain custom scripts, tooling, and automation for scalable offensive testing
  • Help operationalize continuous/autonomous testing platforms
  • Produce decision-ready reports and executive summaries translating technical findings into business impact
  • Support incident response and threat hunting with offensive expertise, attack-path context, and adversary insight
  • Develop repeatable methodologies, playbooks, and metrics to mature the offensive security program

Requirements:

  • 5+ years of hands-on experience in offensive security, penetration testing, red teaming, or a closely related security engineering role
  • Demonstrated expertise across web/mobile application, API, network, infrastructure, and cloud (AWS and/or Azure) penetration testing
  • Strong understanding of exploitation and post-exploitation techniques, attack-path chaining, and objective-based adversary emulation
  • Proficiency with Burp Suite Professional, Nmap, Metasploit, Kali Linux, and vulnerability scanners
  • Proficiency in at least one scripting or programming language, such as Python, Go, PowerShell, Ruby, or Bash
  • Working knowledge of the MITRE ATT&CK framework and hands-on experience mapping engagements to adversary TTPs
  • Excellent written and verbal communication skills, with the ability to present findings to technical audiences and executive leadership
  • Advanced offensive certifications such as OSEP, OSCE³, CRTO, or GXPN are an advantage
  • Track record of original security research, CVEs, or responsible disclosures is an advantage
  • Experience with cloud-native attack techniques and container/Kubernetes (EKS/AKS) and serverless security testing is an advantage
  • Experience operating or evaluating continuous/autonomous penetration testing and breach-and-attack-simulation platforms is an advantage
  • Familiarity with detection engineering, SIEM/EDR platforms, and building purple team feedback loops into SOC content is an advantage
  • Knowledge of relevant compliance and security frameworks is an advantage
  • Experience mentoring junior engineers and helping mature an offensive security program is an advantage

Benefits:

  • Employee Impact Groups
  • FA Cares volunteer opportunities
  • Mentorship Advantage Program
  • SOAR, award-winning manager development program
  • Culture programs and benefits designed to enhance employee experience and development