Senior Offensive Security Consultant
horizon3aiRemote (US,)Full Time2d ago
PythonGraphQLAISecurityPenetration TestingSOCComplianceSalesOperationsSupportCustomer SuccessGrowth
Job description
Senior Offensive Security Consultant
About the role
Join a cybersecurity firm focused on helping organizations proactively identify and fix exploitable weaknesses. In this position, you will conduct in-depth security assessments to uncover vulnerabilities and provide actionable insights for improvement.
Key facts
What you'll do
- Lead comprehensive penetration tests and red team exercises from initial planning through final reporting.
- Assess internal networks, web applications, APIs, cloud infrastructure, and external attack surfaces.
- Discover and demonstrate complex attack chains and business logic flaws that automated tools may miss.
- Validate findings from automated security platforms and manually reproduce identified issues.
- Produce clear, professional reports detailing risks, business impact, and remediation steps.
- Work with sales, customer success, and engineering teams to inform product development.
- Guide junior consultants and contribute to the refinement of testing methodologies and tools.
- Support assessments driven by compliance requirements while maintaining an offensive security perspective.
Requirements
- 5-10 years of current, hands-on experience in offensive security, red teaming, or penetration testing.
- Proven expertise in web application penetration testing and internal network assessments.
- Experience conducting assessments for compliance standards such as PCI DSS and SOC 2.
- Must be a U.S. Citizen.
- Excellent written and verbal communication abilities, capable of explaining technical concepts to diverse audiences.
Nice to have
- Experience with AI-assisted testing or agentic workflows.
- Contributions to security research, blogs, or the wider security community.
- Relevant certifications (e.g., OSCP, OSCE, CRTP, OSEP, GXPN).
Skills & tools
- Web Application & API Testing: Burp Suite Professional, OWASP ZAP, Postman, SQLMap, NoSQLMap, GraphQL tools.
- Internal Network & Active Directory: CrackMapExec, BloodHound, Impacket suite, Responder, NTLMRelayX, Metasploit Framework.
- Cloud & Infrastructure: Pacu, Scout Suite, Prowler, AzureHound, RoadRecon.
- General Exploitation & Productivity: Cobalt Strike, Sliver, Covenant, Nmap, Masscan, John the Ripper, Hashcat.
- Scripting: Python, PowerShell, Bash.
- Reporting: Professional security report writing.
Practical notes
- Travel is minimal, less than 10%, for occasional company or client meetings.
- U.S. Citizenship is required for participation in state and local government opportunities.