Source description
About the role
Key Responsibilities: Red Teaming & Offensive Security - Lead and execute Red Team engagements, including adversary simulation, attack emulation, and stealth operations - Design and perform Advanced Persistent Threat (APT)-style simulations - Identify vulnerabilities across network, application, cloud, and endpoints - Develop and execute attack scenarios covering MITRE ATT&CK; framework - Perform social engineering, phishing, and physical security testing (if applicable) Penetration Testing - Conduct web, mobile, API, network, wireless, and infrastructure penetration testing - Perform secure code review and identify security flaws - Validate vulnerabilities and provide risk-based remediation guidance - Customize tools and scripts (Python, PowerShell, Bash) for testing Leadership & Management - Lead, mentor, and grow a team of penetration testers / red teamers - Manage project delivery, timelines, and stakeholder expectations - Prepare executive-level security reports and risk summaries - Collaborate with Blue Teams / SOC / DevSecOps teams for remediation - Drive capability maturity in offensive security practices Strategy & Governance - Develop and standardize red teaming frameworks and methodologies - Ensure compliance with standards like OWASP, NIST, ISO 27001, PCI DSS - Support security audits, risk assessments, and threat modeling - Stay updated with latest vulnerabilities, exploits, and threat landscape Required Skills & Expertise Technical Skills - Strong expertise in: - Network & Web Application Security - Active Directory attacks & privilege escalation - Exploit development (basic to intermediate) - Cloud security testing (AWS, Azure, GCP) - Hands-on with tools: - Metasploit, Burp Suite, Nmap, Nessus, Cobalt Strike, BloodHound - Kali Linux, Wireshark, OWASP ZAP - Programming/Scripting: - Python, Bash, PowerShell Certifications (Preferred) - OSCP (Offensive Security Certified Skilled) Mandatory/Highly Preferred - OSCE / OSEP / CRTO / eCPPT / CEH / CISSP (plus) Experience - 8+ years in: - Penetration Testing / Ethical Hacking - Red Team Operations - Proven experience managing large-scale security engagements - Experience working with enterprise environments and complex infrastructures Key Responsibilities: Red Teaming & Offensive Security - Lead and execute Red Team engagements, including adversary simulation, attack emulation, and stealth operations - Design and perform Advanced Persistent Threat (APT)-style simulations - Identify vulnerabilities across network, application, cloud, and endpoints - Develop and execute attack scenarios covering MITRE ATT&CK; framework - Perform social engineering, phishing, and physical security testing (if applicable) Penetration Testing - Conduct web, mobile, API, network, wireless, and infrastructure penetration testing - Perform secure code review and identify security flaws - Validate vulnerabilities and provide risk-based remediation guidance - Customize tools and scripts (Python, PowerShell, Bash) for testing Leadership & Management - Lead, mentor, and grow a team of penetration testers / red teamers - Manage project delivery, timelines, and stakeholder expectations - Prepare executive-level security reports and risk summaries - Collaborate with Blue Teams / SOC / DevSecOps teams for remediation - Drive capability maturity in offensive security practices Strategy & Governance - Develop and standardize red teaming frameworks and methodologies - Ensure compliance with standards like OWASP, NIST, ISO 27001, PCI DSS - Support security audits, risk assessments, and threat modeling - Stay updated with latest vulnerabilities, exploits, and threat landscape Required Skills & Expertise Technical Skills - Strong expertise in: - Network & Web Application Security - Active Directory attacks & privilege escalation - Exploit development (basic to intermediate) - Cloud security testing (AWS, Azure, GCP) - Hands-on with tools: - Metasploit, Burp Suite, Nmap, Nessus, Cobalt Strike, BloodHound - Kali Linux, Wireshark, OWASP ZAP - Programming/Scripting: - Python, Bash, PowerShell Certifications (Preferred) - OSCP (Offensive Security Certified Skilled) Mandatory/Highly Preferred - OSCE / OSEP / CRTO / eCPPT / CEH / CISSP (plus) Experience - 8+ years in: - Penetration Testing / Ethical Hacking - Red Team Operations - Proven experience managing large-scale security engagements - Experience working with enterprise environments and complex infrastructures
More at KPMG Assurance and Consulting Services