Senior Red Team Engineer
Aviso de fuente externaen Confidential
The Senior Red Team Engineer is responsible for assessing the organization's security posture through adversary emulation, penetration testing, and offensive security exercises. The role...
Salario
No especificado
Ubicación
San José, Costa Rica
Tipo de empleo
Tiempo completo
Modalidad
No especificado
Senior Red Team Engineer
San José, Costa Rica
Descripción del empleo
The Senior Red Team Engineer is responsible for assessing the organization's security posture through adversary emulation, penetration testing, and offensive security exercises. The role focuses on identifying exploitable attack paths, validating defensive controls, and providing actionable recommendations to improve cyber resilience.The engineer works closely with the SOC, Security Engineering, Infrastructure, Cloud, and Application teams but does not own operational security or governance.
Responsibilities:Plan and execute internal and external penetration tests against enterprise infrastructure, cloud environments, Active Directory, web applications, APIs, and wireless networks.Conduct Red Team engagements that simulate realistic attacker techniques.Identify attack paths involving privilege escalation, lateral movement, credential compromise, and persistence.Perform vulnerability chaining to demonstrate business impact rather than reporting isolated findings.Support Purple Team exercises with the SOC to validate SIEM, EDR, and detection capabilities.Develop proof-of-concept exploits or custom scripts when existing tools are insufficient.Produce clear technical reports with practical remediation recommendations.Assist incident response teams by recreating attacker techniques when required.Stay current with emerging vulnerabilities, exploitation techniques, and adversary tradecraft.
Experience5–8 years of experience in offensive security, penetration testing, or cybersecurity engineering.Experience performing enterprise penetration tests.Ability to explain technical findings to both technical and management audiences.Familiarity with MITRE ATT&CK and common offensive security methodologies.
Required Technical SkillsStrong experience in several (not necessarily all) of the following:InfrastructureWindows Active DirectoryLinux administrationNetworking fundamentalsAzure or AWSMicrosoft 365 securityOffensive SecurityInternal penetration testingExternal penetration testingWeb application testingAPI security testingActive Directory attacksPrivilege escalationLateral movementPhishing simulation (preferred)ToolsExperience with many of the following:Burp SuiteMetasploitNmapNessus or QualysBloodHoundImpacketMimikatzNetExec (formerly CrackMapExec)WiresharkHashcatSliver or Cobalt Strike (where authorised)ScriptingWorking knowledge of one or more:PythonPowerShellBash
Nice to HaveCloud security experienceKubernetes or container securityAzure AD / Entra ID attacksCI/CD security testingBasic malware analysisPurple Team experience
Certifications (Any One)One or more of the following:OSCPPNPTCRTOCRTPGPENGXPN
Success MeasuresHigh-quality Red Team assessments delivered on schedule.Actionable findings that reduce organisational risk.Improved detection capability through Purple Team exercises.Effective communication of technical risks and remediation strategies.
¿Es tuya esta vacante?
Reclámala gratis y recibe candidatos con video en CazVid.