Overview
The Offensive Security Engineer manages scheduling, scoping, tracking and coordination for internal penetration testing and offensive security engagements, and assists with the company’s Bug Bounty program.
What you'll do
- Manage the penetration testing schedule, including monitoring ad-hoc requests and pre-defined assessments and assigning tests to available testers.
- Organize individual testing engagements by assisting with tester assignment, scoping, communication with application and asset owners, and project management tracking.
- Ensure that all stages of testing engagements are completed within agreed timeframes.
- Ensure that findings from performed tests are entered into the findings tracking system and communicated to impacted stakeholders.
- Track open findings by following up with assignees and gathering information around remediation plans.
- Produce reports and metrics around finding resolution status.
- Manage the process of retesting and ensure that open findings are adequately retested and remediated prior to issue closure.
- Assist with the company’s Bug Bounty program by triaging submitted reports.
- Enter validated Bug Bounty findings into the findings tracking system and communicate them to impacted stakeholders.
What you'll need
- 3+ years experience working in Information Security, with a focus on Vulnerability Management, Application Security, or Offensive Security.
- 2+ years of project management related experience in tracking and coordinating significant work efforts with a large number of external dependencies.
- Ability to make quick decisions and resolve complex technical problems.
- Ability to manage through shift changes and effectively transition open and unresolved issues.
- Ability to adapt, learn new technologies, develop new processes, and improve procedures.
- Excellent documentation skills.
- Ability to write, read, interpret, and edit complex documents and correspondence with team members and stakeholders.
- Excellent verbal and written communication skills.
- Ability to work peak, off-peak, weekend, and holiday shifts.
- Ability to communicate and respond to communication effectively with client, associates, and stakeholders.
- Ability to perform problem-solving and use logic and creative thought processes to resolve complex technical problems.
Nice to have
- Bachelor’s Degree or equivalent in Information Security, Engineering, or Computer Science.
- Experience working with JIRA and other work management tools.
- Knowledge of common security vulnerabilities and corresponding remediation approaches.
- Advanced understanding of OWASP, the MITRE ATT&CK framework, Atlas, and the software development lifecycle (SDLC).
- Knowledge of Linux, Mac, and Windows operating systems; AWS and Azure cloud environments; and cloud-native resources such as containers, Kubernetes, microservices, and serverless functions.
- Knowledge in security of operating systems, networking and protocols, firewalls, databases and middleware applications, forensics, scripting and programing.
- Good communication skills and ability to work with all stakeholders, internal and external, finding, advising and implementing the best solutions.
- Strong organization skills.
Details
- Location: Hyderabad.
- Ability to work peak, off-peak, weekend, and holiday shifts.
Read the full description and apply on the company’s own careers page.