The posting
- Design and execution of complex penetration tests and Red Team engagements.
- Testing of web applications, APIs, mobile applications, and cloud environments.
- Assessment of large-scale internal and external infrastructure.
- Execution of attacks against Active Directory and corporate networks.
- Performing privilege escalation, lateral movement, and persistence simulations.
- Development of custom scripts, exploits, and automation tools.
- Simulation of realistic attacks based on the MITRE ATT&CK framework.
- Mentoring junior team members and quality control of deliverables.
- Presentation of technical and executive-level reports to clients.
- Collaboration with Blue Teams for purple-team exercises and improving detections.
Requirements
- At least 3–5 years of professional experience in penetration testing or Red Teaming.
- Advanced knowledge of web application, API, and network infrastructure testing.
- Proven experience in Active Directory attacks and Windows environments.
- Experience in cloud security assessments, preferably AWS, Azure, or GCP.
- Very good knowledge of exploitation, privilege escalation, and post-exploitation techniques.
- Ability to develop tools using Python, PowerShell, C#, Go, or an equivalent language.
- Familiarity with Burp Suite, Cobalt Strike, BloodHound, and related tools.
- Strong ability to write technical and management reports.
- Ability to manage projects independently and communicate with clients.
- OSCP, OSEP, OSWE, CRTO, or an equivalent certification will be considered a significant asset.



