donator JOBS

IT and programming

Offensive Security Engineer - remote job

Sporty Group

From EuropeRemoteEurope
Apply

The link takes you to the original advert. Donator takes no applications.

Poster to share
Posted: (15 days ago)Active until: until 19 September 2026

Offensive Security Engineer - IT and programming, remote

Sporty Group is hiring a Offensive Security Engineer. The role sits in IT and programming and is fully remote. The company hires candidates based in Europe.

The employer did not publish a figure; that is settled at interview. The advert sets no condition on working hours.

This vacancy passed an automated check: the list excludes any advert requiring a foreign work permit, visa sponsorship, a particular citizenship, or residence in a specific country.

In brief

Company
Sporty Group
Category
IT and programming
Who may apply
From anywhere in Europe
Work mode
Fully remote
Employment type
Full time
Posted
10 August 2026 (15 days ago)
Active
until 19 September 2026
Source
Jobicy

Get new IT and programming jobs by email

The board updates several times a day. We write only when a new, checked vacancy appears. No spam, no account needed.

Already subscribed? Manage your settings

New vacancies on Telegram

Every new remote vacancy, posted as it lands. No account needed.

Open the channel

@donator_jobs_en

The employer's description

About the role Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails. What you'll be doing

* Monitor, map, and test Sporty’s entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses.

* Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms.

* Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure.

* Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints.

* Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks.

* Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected.

* Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams.

* Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance.

* Improve external asset tracking, perimeter health records, and exposure trend mapping.

* Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure.

What you'll bring

* Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation.

* Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.

* Practical experience auditing and testing Linux and Windows environments and underlying network services.

* Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.

* Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.

* Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.

* Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.

* Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.

* Good understanding of scanning, reconnaissance, and interception tools.

* Strong documentation skills.

Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence What's in it for you

* Sporty is a remote-first company in pursuit of sustainability

* A competitive salary plus individual performance-based bonuses every quarter

* 28 days paid annual leave

* Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours

* Referral bonuses and flash bonuses

* Top-of-the-line equipment

* Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world

Interview Process:

* Remote video screening with our Talent Acquisition Team

* Online assessment via Hackerrank

* Remote video interview with Team Members (60 Mins)

* Final discussion with the hiring manager (60 mins)

If you're interested, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.

The text is kept in the employer's original language, because that is the language you will apply in.

This vacancy was published on Jobicy. Original advert (Jobicy)

Frequently asked questions about this job

Can I apply for Offensive Security Engineer from where I live?

Yes. Sporty Group accepts candidates for this vacancy from anywhere in Europe, so you need no work permit for a foreign country. The advert passed an automated check: had the employer required a work permit, visa sponsorship or residence in a specific country, it would not be on this board.

What pay is stated?

Sporty Group did not publish pay for this vacancy. Most remote adverts publish no figure; it is settled at interview.

How do I apply?

You apply directly to the employer, through the original advert published on Jobicy. Donator takes no applications, charges no commission and stores no CV.

What kind of vacancy is this?

A fully remote role in IT and programming. Hybrid adverts and anything requiring office attendance are not published on this board.

Free certificates for this vacancy

The free certificates that carry the most weight in this field. Each one is verified on the provider's own page.

All free certificates: IT and cloud

Similar jobs

Remote job: Offensive Security Engineer | Donator