
Senior Offensive Security Consultant
Job description
Senior Offensive Security Consultant at Horizon3.ai.
About the role
Join a cybersecurity firm focused on helping organizations proactively identify and fix exploitable weaknesses. In this position, you will conduct in-depth security assessments to uncover vulnerabilities and provide actionable insights for improvement. You will own the full lifecycle of adversarial simulation, translating complex technical findings into strategic guidance that strengthens the security posture of clients. This role requires a high degree of autonomy and judgment as you tackle sophisticated engagements that span multiple attack domains. You will partner directly with clients to understand their unique risk landscapes and tailor testing approaches that align with business objectives. The work demands intellectual curiosity, disciplined methodology, and a commitment to delivering clear, defensible results under tight timelines. By influencing both technical defenders and strategic decision-makers, you will play a pivotal role in shaping the future security maturity of our customers.
Key facts
What you'll do
- Orchestrate end-to-end penetration tests and red team exercises, defining scope, objectives, and success criteria from initial planning through nuanced final reporting.
- Conduct deep assessments of internal networks, web applications, APIs, cloud infrastructure, and external attack surfaces to map the full terrain of client digital assets.
- Uncover and demonstrate complex attack chains and business logic flaws that evade automated tools, applying creative problem-solving to bypass conventional controls.
- Critically validate findings from automated security platforms by manually reproducing issues, confirming true risk and eliminating false positives with precision.
- Craft clear, professional reports that articulate risks, business impact, and remediation steps in language tailored for both technical and executive stakeholders.
- Collaborate with sales, customer success, and engineering teams to translate engagement insights into product feedback, roadmap considerations, and improved service offerings.
- Mentor junior consultants by sharing techniques, reviewing work product, and refining testing methodologies and tools to elevate the collective capability of the team.
- Support assessments driven by compliance requirements such as PCI DSS and SOC 2 while maintaining a strict offensive security perspective that prioritizes real-world risk.
- Continuously expand your expertise by exploring emerging attack vectors, evaluating new tools, and incorporating lessons learned into repeatable playbooks.
- Act as a trusted advisor to clients, translating technical findings into prioritized recommendations that align with their risk appetite and operational constraints.
Requirements
- Bring 5-10 years of current, hands-on experience in offensive security, red teaming, or penetration testing, with a demonstrable track record of successful engagements.
- Exhibit proven expertise in web application penetration testing, including both black-box and white-box methodologies, as well as thorough internal network assessments across diverse environments.
- Demonstrate experience conducting assessments for compliance standards such as PCI DSS and SOC 2, understanding the intersection of control requirements and actual risk.
- Must be a U.S. Citizen to meet regulatory and eligibility requirements for participation in state and local government opportunities.
- Communicate effectively in writing and speaking, with the ability to distill highly technical vulnerabilities into clear narratives that resonate with nontechnical audiences.
- Apply structured analytical thinking to complex problems, showing persistence in pivoting, exploring alternative paths, and validating hypotheses rigorously.
- Maintain a strong ethical foundation, adhering to rules of engagement, client confidentiality, and professional conduct at all times during assessments.
- Leverage sound judgment to prioritize testing objectives, manage scope constraints, and deliver high-value outcomes within agreed timelines and resource limits.
Nice to have
- Experience with AI-assisted testing or agentic workflows that enhance the efficiency and depth of security assessments.
- Contributions to security research, blogs, or the wider security community that demonstrate thought leadership and practical expertise.
- Relevant certifications such as OSCP, OSCE, CRTP, OSEP, or GXPN that validate advanced technical skills and commitment to the field.
Practical notes
- Travel is minimal, less than 10%, typically reserved for occasional company or client meetings that require in-person collaboration.
- U.S. Citizenship is required for participation in state and local government opportunities, ensuring compliance with contractual and regulatory conditions.
- This is a full-time engagement with a compensation range of $200,000 to $250,000 annually, supplemented by equity, reflecting the scope and impact of the role.
- The position operates remotely, allowing flexibility in work location while expecting reliable availability during core collaboration windows.
- Candidates should be prepared to engage with a diverse set of technologies and environments, adapting quickly to new tools, methodologies, and client contexts.
- The successful candidate will join a team dedicated to raising the bar in offensive security, where continuous learning, peer review, and knowledge sharing are integral to the culture.
- Assessments may require evening or occasional weekend availability to align with client maintenance windows or incident response needs, and schedules will be coordinated in advance whenever possible.
- Participation in this role requires adherence to strict documentation standards, ensuring that all testing activities, findings, and recommendations are meticulously recorded and reviewed.
- Professional development is encouraged, with support for conference attendance, training, and certification efforts that keep the team at the forefront of offensive security practices.