The Role
Lead and perform penetration tests and security assessments across web apps, AD, cloud, network, and infrastructure; run adversary emulation and purple team exercises with SOC/Blue team; assess identity and cloud security; tune SIEM/EDR/Identity Protection detections; prepare technical reports and present findings.
Summary Generated by Built In
- Conduct penetration testing and security assessments across web applications, internal infrastructure, Active Directory, cloud environments, and network infrastructure to identify security vulnerabilities.
- Perform adversary emulation and purple team exercises by collaborating with SOC and Blue team to validate detection capabilities and improve incident response.
- Assess the security posture of Active Directory, Microsoft Entra ID, cloud platforms (AWS, Azure, GCP), and identity infrastructure against common attack techniques.
- Support the development and tuning of detection rules for SIEM, EDR, Identity Protection, and other security monitoring platforms.
- Prepare technical reports and present security findings, risks
Requirements
- Bachelor's or associate degree in IT, Computer Science, or related field.
- At least 5+ years of experience in security design, operation or implementation
- Strong knowledge of current cyber threats, attack techniques, security controls, and enterprise IT infrastructure across Windows, Linux, Active Directory, cloud, and network environments.
- Strong understanding of the MITRE ATT&CK Framework, Cyber Kill Chain, and OWASP Top 10, with the ability to emulate attacker techniques and validate security controls.
- Experience with common penetration testing tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Mimikatz, or equivalent
Skills Required
- Bachelor's or associate degree in IT, Computer Science, or related field
- 5+ years experience in security design, operation, or implementation
- Strong knowledge of cyber threats, attack techniques, security controls across Windows, Linux, Active Directory, cloud, and network environments
- Strong understanding of MITRE ATT&CK Framework, Cyber Kill Chain, and OWASP Top 10
- Experience with penetration testing tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Mimikatz, or equivalent
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Makro PRO is an exciting new digital venture by the iconic Makro. Our proud purpose is to build a technology platform that will help make business possible for restaurant owners, hotels, and independent retailers, and open the door for sellers. Makro PRO brings together the best talent across multi-nationals to transform the B2B marketplace ecosystem. We welcome bold, energetic, and thoughtful people who share our belief in collaboration, diversity, excellence, and putting customers at the heart of our work.







