Offensive Security Team Lead
Offensive Security Team Lead
coach & connect- Posted 2 hours ago
- Be among the first 10 applicants
Job Description
About the role:
One of Our client is a focused cybersecurity service provider in the region, with a team experience that spans over 15 years are looking for Offensive Security Team Lead
Key Responsibilities- Lead and mentor a team of penetration testers and red team operators, setting technical direction and quality standards.
- Plan and execute advanced penetration tests, red team engagements, and adversary emulation exercises across networks, web/mobile applications, cloud environments, and physical/social engineering vectors.
- Conduct manual exploitation, source code review, and custom exploit/tooling development for identified vulnerabilities.
- Design and run purple team exercises in partnership with the Blue Team/SOC to validate detection and response capabilities.
- Own the offensive security roadmap, including tooling, methodology (e.g., MITRE ATT&CK-aligned), and scope of engagements.
- Deliver clear, actionable technical reports and executive summaries to stakeholders and leadership.
- Track emerging threats, TTPs, and 0-day/N-day research relevant to the organization's attack surface.
- Collaborate with engineering teams on secure development practices and remediation validation.
- Manage vendor relationships for third-party pentests and red team tooling.
- Contribute to and enforce rules of engagement, safety protocols, and legal/compliance requirements for offensive testing.
Requirements
Required Qualifications
- 7+ years in offensive security, penetration testing, or red teaming, including 2+ years in a leadership or team-lead capacity.
- Deep expertise in exploitation techniques, web application security, network penetration testing, and post-exploitation/lateral movement.
- Proficiency in scripting/exploit development (Python, C/C++, PowerShell, or similar).
- Strong understanding of Windows/Linux internals, Active Directory attack paths, and cloud security (AWS/Azure/GCP).
- Excellent written and verbal communication skills for technical and executive audiences.
- Experience building or scaling an offensive security function.
- OSWE – OffSec Web Expert.
- OSEE – OffSec Exploitation Expert.
- OSCE³ – OffSec Certified Expert.
- CPENT – Certified Penetration Testing Professional.
- LPT (Master) – Licensed Penetration Tester.
- CEPT – Certified Exploitation Penetration Tester.
- GXPN – GIAC Exploit Researcher and Advanced Penetration Tester.
More Info
Key Skills
exploitation techniques
post-exploitation lateral movement
Active Directory attack paths
exploit development
