Offensive Security Engineer

Posted Yesterday
Be an Early Applicant
27 Locations
Remote
Mid level
Digital Media • Fintech • Gaming • Sports
The Role
Owner of offensive security testing and continuous perimeter monitoring across external domains, IPs, DNS, VPS, and office infrastructure. Conduct adversary emulation against endpoints/EDR/XDR, scoped web/API tests, and document exploitation chains. Translate findings into defensive controls, support Purple Teaming, and improve asset tracking and remediation metrics.
Summary Generated by Built In
About the role

Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails.

What you'll be doing
  • Monitor, map, and test Sporty’s entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses.
  • Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms.
  • Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure.
  • Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints.
  • Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks.
  • Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected.
  • Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams.
  • Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance.
  • Improve external asset tracking, perimeter health records, and exposure trend mapping.
  • Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure.
What you'll bring
  • Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation.
  • Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.
  • Practical experience auditing and testing Linux and Windows environments and underlying network services.
  • Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.
  • Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.
  • Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.
  • Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.
  • Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.
  • Good understanding of scanning, reconnaissance, and interception tools.
  • Strong documentation skills.

Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence

What's in it for you
  • Sporty is a remote-first company in pursuit of sustainability
  • A competitive salary plus individual performance-based bonuses every quarter
  • 28 days paid annual leave
  • Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours
  • Referral bonuses and flash bonuses
  • Top-of-the-line equipment
  • Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world
Interview Process:
  • Remote video screening with our Talent Acquisition Team
  • Online assessment via Hackerrank
  • Remote video interview with Team Members (60 Mins)
  • Final discussion with the hiring manager (60 mins)

If you're interested, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.

Skills Required

  • Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation
  • Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing
  • Practical experience auditing and testing Linux and Windows environments and underlying network services
  • Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions
  • Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems
  • Ability to translate external exposures and technical network risks into clear, actionable fixes for IT and Security teams
  • Experience with core web vulnerabilities and scoped testing of modern API interfaces
  • Strong scripting ability in Python, PowerShell, Bash, or similar to automate mapping, emulation workflows, and asset discovery
  • Good understanding of scanning, reconnaissance, and interception tools
  • Strong documentation skills
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
1,024 Employees
Year Founded: 2013

What We Do

Sporty Group is a global consumer internet and technology company specializing in sports media, gaming, social platforms, and fintech. It creates high-scale consumer products, including sports broadcasting via SportyTV and gaming through SportyBet, serving millions of daily active users across more than 10 countries and 3 continents. The company focuses on delivering world-class user experiences at the intersection of tech and live content.

Similar Jobs

Deepgram Logo Deepgram

Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
28 Locations
150 Employees

Deepgram Logo Deepgram

Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Remote
27 Locations
150 Employees

Shield AI Logo Shield AI

Senior Bid Manager

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
In-Office or Remote
2 Locations

Pfizer Logo Pfizer

Senior Manager, IT Service Management (ITSM) Product Lead

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
5 Locations
121990 Employees
125K-232K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account