First Advantage
Sr Offensive Security Engineer
India · Remote
About this role
What You'll Do We are seeking a highly skilled and motivated Senior Offensive Security Engineer to join our Threat Management & Security Operations organization. In this hands-on role, you will think and operate like an adversary — continuously finding, exploiting, and helping remediate real-world weaknesses across First Advantage ’s products, cloud infrastructure, networks, and people. You will design and execute penetration tests, red and purple team engagements, and adversary emulation exercises that validate our detection and response capabilities and measurably reduce enterprise risk at-scale. This role partners closely with Security Operations, Threat Intelligence & Hunt, Vulnerability Management, Application Security, DevOps, and Product teams to turn offensive findings into prioritized, business-aligned remediation. The ideal candidate is equally comfortable building custom tooling, chaining exploits across complex environments, and communicating impact clearly to both technical teams and executive leadership. Responsibilities Penetration Testing: Plan, scope, and execute internal and external penetration tests across web and mobile applications, APIs, cloud (AWS/Azure), networks, and infrastructure using real-world attacker techniques. Red & Purple Teaming: Design and run adversary emulation and red team engagements that combine multiple attack paths to accomplish objective-based goals, and partner with the SOC, Threat Intel & Hunt, and Detection Engineering on purple team exercises to validate and improve detection coverage. Exploit Development & Chaining: Identify, validate, and safely exploit vulnerabilities — including chaining lower-severity issues into high-impact attack paths — and demonstrate tangible business impact in production-representative environments. Adversary Emulation: Model real-world threat actor tactics, techniques, and procedures (TTPs) mapped to the MITRE ATT&CK framework to test and strengthen organizational resilience, detection, and response. Findings & Remediation: Review and validate findings for accuracy, prioritize real-world exploitability and business risk, create remediation tickets, and partner with engineering teams to drive fixes and coordinate retests within policy SLAs. Tooling & Automation: Build and maintain custom scripts, tooling, and automation to scale offensive testing, and help operationalize continuous/autonomous testing platforms across the environment. Reporting & Communication: Produce clear, decision-ready reports and executive summaries that translate technical findings into risk and business impact for technical stakeholders, GRC/Audit, and executive leadership. Incident Response Support: Support incident response and threat hunting efforts by providing offensive expertise, attack-path context, and adversary insight. Continuous Improvement: Contribute to the maturity of the offensive security program — developing repeatable methodologies, playbooks, and metrics that demonstrate progress over time. What You Will Need to be Successful: 5+ years of hands-on experience in offensive security, penetration testing, red teaming, or a closely related security engineering role. Demonstrated expertise across multiple domains: web/mobile application, API, network, infrastructure, and cloud (AWS and/or Azure) penetration testing. Strong understanding of exploitation and post-exploitation techniques, attack-path chaining, and objective-based adversary emulation. Proficiency with industry-standard offensive tooling such as Burp Suite Professional, Nmap, Metasploit, and Kali Linux, along with vulnerability scanners. Proficiency in at least one scripting or programming language (e.g., Python, Go, PowerShell, Ruby, or Bash) to build custom tools and automation. Working knowledge of the MITRE ATT&CK framework and hands-on experience mapping engagements to adversary TTPs. Excellent written and verbal communication skills, with the ability to present findings to both technical audience
Skills and categories
Listing provided by Himalayas. Verify availability on the source board before applying — Kartavyam aggregates public listings as they appear and does not manage this application.