The Role
Conduct penetration tests, red team and purple team exercises across web applications, networks, APIs, cloud, and mobile systems. Identify and exploit vulnerabilities, develop proof-of-concept exploits and security automation, integrate offensive techniques into CI/CD pipelines, research emerging threats, validate detection capabilities, and document remediation guidance. Collaborate with SOC, DevOps, IT, engineering, and incident response teams to strengthen organizational security defenses.
Summary Generated by Built In
Role Overview:
As an Offensive Security Engineer, you will be responsible for simulating real-world
cyberattacks to identify vulnerabilities, assess risks, and improve security defenses. You will
work closely with security analysts, DevOps, and IT teams to enhance the organization's
resilience against cyber threats.
Key Responsibilities:
Penetration Testing & Red Teaming
● Conduct advanced penetration testing on web apps, networks, APIs, cloud, and mobile
applications.
● Simulate real-world attack scenarios to evaluate security defenses.
● Perform internal/external network and infrastructure security assessments.
● Execute red team exercises, including phishing simulations and social engineering
campaigns.
● Collaborate with SOC/Security teams to validate monitoring and defense effectiveness.
Vulnerability Research & Exploitation
● Identify, analyze, and exploit vulnerabilities across various systems.
● Develop custom scripts or exploits for proof-of-concept attacks.
● Work with security teams to ensure timely patching and risk mitigation.
Security Tool Development & Automation
● Develop and maintain security testing tools and automation scripts.
● Integrate offensive security techniques into CI/CD pipelines.
● Evaluate vendor security tools and features through controlled attack simulations.
● Build proof-of-concept scenarios to confirm vendor-promoted capabilities function as
intended.
Threat Hunting & Adversary Simulation
● Conduct red team and purple team exercises to test detection & response capabilities.
● Stay ahead of cyber threats by researching latest hacking trends, zero-days, and TTPs.
● Provide actionable intelligence to incident response teams.
Security Reporting & Collaboration
● Document security findings with detailed remediation steps.
● Work with engineering teams to implement security best practices.
● Contribute to security awareness training within the company.
Requirements
Required Skills & Qualifications:
● Experience: 3+ years in offensive security, penetration testing, or red teaming.
Technical Expertise:
● Strong knowledge of penetration testing tools (Burp Suite, Metasploit, Nmap, Kali Linux,
etc.).
● Deep understanding of network security, web security, and cloud security.
● Proficiency in exploit development, reverse engineering, and malware analysis.
● Experience with scripting languages (Python, Bash, PowerShell).
● Hands-on experience with Active Directory attacks, privilege escalation, and lateral
movement.
Mandatory Certifications(Baseline Requirements):
● CEH (Certified Ethical Hacker - EC - Council V13)
Preferred Certifications(Role Enhancing Credentials):
● OSCP (Offensive Security Certified Professional)
● OSWE / OSEP / OSEE (Advanced Offensive Security Certifications)
● CRTO (Certified Red Team Operator)
● GPEN (GIAC Penetration Tester)
Skills Required
- 3+ years of experience in offensive security, penetration testing, or red teaming
- Strong knowledge of penetration testing tools, including Burp Suite, Metasploit, Nmap, and Kali Linux
- Deep understanding of network security, web security, and cloud security
- Proficiency in exploit development, reverse engineering, and malware analysis
- Experience with Python, Bash, and PowerShell scripting
- Hands-on experience with Active Directory attacks, privilege escalation, and lateral movement
- CEH Certified Ethical Hacker certification, EC-Council V13
- OSCP certification
- OSWE, OSEP, or OSEE advanced offensive security certification
- CRTO Certified Red Team Operator certification
- GPEN GIAC Penetration Tester certification
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
ZYBISYS CONSULTING SERVICES LLP is an India-based IT services and consulting firm focused on helping fintech and other businesses modernize technology. It provides public, private, and hybrid cloud hosting, managed IT services, DevOps, data-center management, infrastructure support, cybersecurity, and technology consulting. Its offerings also include software development, automation, monitoring, and cloud-native solutions designed to improve scalability, operational efficiency, security, and business continuity.


.png)






