Senior Red Team / Penetration Tester at Ascentech Services Limited
Confidential
Publiée il y a 1 mois · Expire dans 3 semaines
Description du poste
Role Summary
We're looking for a hands-on Senior Red Team / Penetration Tester to lead offensive security engagements that emulate sophisticated threat actors and uncover real-world risks. You'll design and execute targeted red-team operations and deep technical penetration tests across web, cloud, network, identity and physical security controls, then translate findings into prioritized remediation and measurable risk reduction.
Key Responsibilities
- Plan and execute targeted red-team engagements and penetration tests across cloud (Azure), on-premises, network, Active Directory, web applications, APIs, and container/Kubernetes environments
- Develop realistic adversary emulations (TTPs) mapped to MITRE ATT&CK and run Purple Team sessions to validate detections and playbooks
- Safely run exploit and persistence techniques in controlled environments, documenting impact, blast radius, and remediation
- Create high-quality penetration test deliverables: executive summaries, technical findings, risk ratings, proofs of concept, step-by-step remediation guidance, and detection tuning recommendations
- Work with SOC/Detection & Response teams to improve SIEM, EDR, and IDS rules and SOAR playbooks — validate detection efficacy after fixes
- Drive continuous improvement through exploit research, tooling, automation for red-team operations, and custom tooling development where needed
- Assist with threat hunting exercises and retrospective post-incident adversary TTP mapping
- Ensure legal and ethical compliance: create and follow Rules of Engagement (RoE), coordinate maintenance windows and stakeholder approvals
- Mentor junior red team and penetration testing engineers and participate in hiring and interviewing
Required Experience & Qualifications
- 2+ years of professional penetration testing and offensive security experience with a track record of end-to-end red-team engagements
- Deep, practical experience attacking Active Directory environments, Windows, Mac, and Linux post-exploitation and lateral movement techniques
Ce poste vous intéresse ?
Se connecter pour voir l'emailPas encore inscrit ? Créer un compte gratuit