Offensive Security Engineer – Red Team
PlexTrac · Itanagar
Job description
About the role
PlexTrac is looking for an Offensive Security Engineer to join its remote‑first Red Team. You will think like an attacker, uncover weaknesses across cloud, network, and application layers, and work closely with engineering to remediate findings.
Key responsibilities
- Plan and execute Red Team engagements across AWS, GCP, Azure, internal networks, web applications, and the SaaS product.
- Simulate realistic attack chains—from initial access to data exfiltration—using current threat‑actor techniques.
- Conduct assumed‑breach, purple‑team, and objective‑based exercises.
- Assess cloud attack surfaces such as IAM roles, storage misconfigurations, serverless functions, containers, and CI/CD pipelines.
- Test Active Directory and hybrid identity environments for advanced attack paths.
- Perform web and API testing for authentication flaws, authorization bypasses, and business‑logic vulnerabilities.
- Build, customize, and maintain offensive tools, scripts, and C2 infrastructure.
- Develop and manage Red Team infrastructure including attack servers, redirectors, and phishing platforms.
- Write detailed reports documenting attack paths, evidence, business impact, and remediation steps.
- Present findings to technical teams, leadership, and non‑technical stakeholders.
- Track remediation progress and validate that fixes close identified gaps.
- Help define the scope, methodology, and maturity of the Red Team program as it scales.
- Mentor junior team members and share knowledge across the security organization.
Required profile
- Hands‑on experience planning and executing Red Team engagements.
- Ability to produce clear, actionable technical reports.
- Experience collaborating with engineering and blue‑team counterparts.
- Willingness to mentor junior staff and contribute to security standards.
Required skills
- AWS, GCP, Azure cloud platforms
- IAM role and policy management
- Active Directory and hybrid identity security
- Web application and API security testing
- Serverless, container, and CI/CD pipeline security
- Offensive tooling, scripting, and C2 infrastructure
- Phishing platform development
- Red‑team methodologies and attack chain simulation
Questions fréquentes
Why are you reporting this job?
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 11 hours ago
Expires 1 month from now
1 views · 0 applications
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
PlexTrac
Itanagar
Related job offers
-
Cybersecurity Engineer – SOC Operations
Birlasoft Noida -
Security Engineer
Altered Security District de Bhopal -
Cybersecurity Research Engineer – Honeypot
C3iHub, IIT Kanpur District de Kanpur Nagar -
Team Leader - Security
Grand Hyatt Bambolim -
Security Guard – On-site Full-time
RAJ SECURITY SERVICE Vadodara