Offensive Security Consultant
פורסם 5 באוג׳ · 0 מועמדים
התפקיד במילים פשוטות
תפקיד זה כולל ביצוע מבדקי חדירות והערכות אבטחה התקפית עבור לקוחות מקומיים וגלובליים. העבודה היום-יומית כוללת בדיקות של תשתיות, אפליקציות רשת ומובייל וסביבות טכנולוגיות נוספות, לצד כתיבת דוחות טכניים והסברת הסיכונים ללקוחות.
- At least 3 years hands-on experience in infrastructure, networking, systems administration, IT operations, or related technical infrastructure domains
- At least 1 year hands-on experience in offensive security / application and infrastructure penetration testing
- Hands-on experience identifying and exploiting common security vulnerabilities across applications and infrastructure (SQLi, XSS, auth weaknesses, misconfigurations)
- Experience with Burp Suite
- Experience with Kali Linux
- Ability to conduct source code reviews, database security assessments, or additional specialized security testing activities
חולץ מתיאור המשרה · מתעדכן אוטומטית
למי זה מתאים
התפקיד מתאים למקצועני אבטחת מידע עם לפחות שנת ניסיון מעשית באבטחה התקפית ו-3 שנות ניסיון בתשתיות IT ורשתות. הוא פחות מתאים למי שחסר ניסיון טכני מעשי בתשתיות או בביצוע מבדקי חדירות.
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןOffensive Security Consultant, responsible for performing hands-on penetration tests and offensive security assessments for local and global clients.
The role includes a broad range of assessments, including white, grey, and black box testing across infrastructure, applications, and other relevant technology environments.
Educating clients on inherent security risks, providing meaningful hardening and mitigation strategies, and supporting engagements with local and global clients through clear communication, technical leadership, and high-quality deliverables.
Responsibilities:
• Perform hands-on offensive security assessments across a wide range of technologies and engagement types, including Red Team, Purple Team, external and internal network testing, web and mobile applications, thick client applications, web3 environments, and additional offensive security domains.
• Deliver end-to-end penetration testing engagements, including preparation, execution, documentation of findings, risk-based recommendations, and professional client-facing reporting.
• Collaborate with client technical teams to validate security gaps, explain findings clearly, support remediation discussions, and ensure practical, business-relevant security improvements.
• Participate in client meetings throughout the engagement lifecycle, including kickoff, scoping, technical walkthroughs, and final report presentation.
Requirements:
• At least 3 years hands-on experience in infrastructure, networking, systems administration, IT operations, or related technical infrastructure domains – Must.
• At least 1 year hands-on experience in Offensive Security, including application and/or infrastructure penetration testing – Must.
• Hands-on experience identifying and exploiting common security vulnerabilities across applications and infrastructure, such as SQL Injection, Cross-Site Scripting, authentication and authorization weaknesses, misconfigurations, insecure services, and other relevant attack vectors – Must.
• Experience with common penetration testing tools, including Burp Suite, Kali Linux, Nmap, Metasploit, Nessus, and Wireshark, and similar offensive security tools – Must.
• Good written and verbal communication skills, with the ability to document technical findings clearly, write professional assessment reports, and present risks and recommendations to technical and non-technical stakeholders – Must.
• Self-motivated, responsible, and able to manage assigned testing activities independently while working effectively as part of a consulting team – Must.
• Familiarity with offensive security methodologies and frameworks such as OWASP, PTES, MITRE ATT&CK, or similar references – Significant Advantage.
• Strong understanding of TCP/IP, networking concepts, common ports and protocols, and how they are assessed during infrastructure and network penetration tests – Significant Advantage.
• Hands-on familiarity with Active Directory environments, Windows domains, authentication flows, privilege escalation paths, and common enterprise misconfigurations – Significant Advantage.
• Proven experience in infrastructure penetration testing, including internal and external network assessments – Significant Advantage.
• Relevant professional certifications from a recognized offensive security institute – Significant Advantage.
• Familiarity with public cloud environments such as Microsoft Azure, AWS, or Google Cloud Platform, including identity, permissions, exposed services, and common cloud misconfigurations – Significant Advantage.
• Ability to conduct source code reviews, database security assessments, or additional specialized security testing activities – Advantage.
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- At least 3 years hands-on experience in infrastructure, networking, systems administration, IT operations, or related technical infrastructure domains, At least 1 year hands-on experience in offensive security / application and infrastructure penetration testing, Hands-on experience identifying and exploiting common security vulnerabilities across applications and infrastructure (SQLi, XSS, auth weaknesses, misconfigurations), Experience with Burp Suite, Experience with Kali Linux