Skip to content

Open nowPosted 119 days ago

Senior Penetration Engineer (Red Team Lead)

shamrocktc114 open roles

Where
Overland Park, KS, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Penetration Engineer (Red Team Lead)shamrocktc · Overland Park, KS, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on shamrocktc's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 119 days ago

The posting

About the Role We are seeking a Senior Security Engineer to simulate real-world adversaries and identify high-impact vulnerabilities across enterprise and cloud environments. This role focuses on executing realistic adversary simulations, penetration testing, and attack path analysis, partnering closely with defensive teams to improve detection and response capabilities. The ideal candidate is a hands-on offensive security professional with deep expertise in exploitation, post-exploitation, and adversary tactics. What You’ll Do

Plan and execute advanced red team engagements across enterprise environments. Emulate real-world threat actors using MITRE ATT&CK-aligned techniques. Chain vulnerabilities into realistic attack paths with business impact. Simulate multi-stage attacks to evaluate organizational resilience. Conduct penetration testing across: Web applications and APIs, cloud environments (IAM abuse, misconfigurations), identity systems (Active Directory / Entra ID) and internal networks and endpoints Identify and exploit vulnerabilities to demonstrate real-world risk. Perform lateral movement, persistence, and privilege escalation activities. Test and bypass security controls and detection mechanisms. Operate and customize command-and-control (C2) frameworks: Cobalt Strike, Sliver, Mythic, or equivalent Develop scripts, payloads, and tooling to support operations. Validate cloud security posture controls through adversarial techniques. Exploit identity misconfigurations, exposed credentials, and privilege escalation paths. Assess real-world impact of cloud exposure risks. Partner with SOC and blue teams to conduct purple team exercises. Help improve detection rules, alert quality, and response capabilities. Provide insight into attacker techniques to enhance defensive strategies. Deliver clear, actionable reports with: Risk-prioritized findings, attack path analysis, and practical remediation guidance Translate technical findings into business-relevant risk insights.

What You’ll Bring

6-8+ years in offensive security, penetration testing, or red teaming. Proven experience executing full-scope red team engagements. Strong expertise in: Exploitation (web, network, identity systems), post-exploitation and lateral movement and privilege escalation techniques Experience with C2 frameworks and evasion techniques. Deep understanding of MITRE ATT&CK framework. Strong scripting or programming skills (Python, PowerShell, C#, etc.).

What Will Set You Apart

Experience with cloud penetration testing (AWS, Azure, GCP). Background in exploit development or custom tooling. Certifications such as OSCP, OSEP, CRTO, OSCE.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against shamrocktc's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on shamrocktc's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    shamrocktc's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.