IT and programming
Offensive Security Engineer - remote job
Sporty Group
The link takes you to the original advert. Donator takes no applications.
New vacancies on Telegram
Every new remote vacancy, posted as it lands.
@donator_jobs_en
Offensive Security Engineer - IT and programming, remote
Sporty Group is hiring a Offensive Security Engineer. The role sits in IT and programming and is fully remote. The company hires candidates based in Europe.
The employer did not publish a figure; that is settled at interview. The advert sets no condition on working hours.
This vacancy passed an automated check: the list excludes any advert requiring a foreign work permit, visa sponsorship, a particular citizenship, or residence in a specific country.
In brief
- Company
- Sporty Group
- Category
- IT and programming
- Who may apply
- From anywhere in Europe
- Work mode
- Fully remote
- Employment type
- Full time
- Posted
- 12 September 2026 (28 days ago)
- Active
- until 22 October 2026
- Source
- Jobicy
Get new IT and programming jobs by email
The board updates several times a day. We write only when a new, checked vacancy appears. No spam, no account needed.
Already subscribed? Manage your settings
About this job
About the Role
In this key position, you'll be essential in fortifying Sporty’s defensive security framework by conducting thorough and proactive vulnerability assessments of our external infrastructure, including virtual private servers (VPS), physical office networks, and endpoint protection systems. As an Offensive Security Engineer, you'll lead comprehensive perimeter security testing, continuous monitoring, and reconnaissance of all Sporty Group external domains, websites, and public IP addresses. You'll collaborate closely with IT, Network Engineering, Security Operations Center (SOC), and Security teams to refine our external security measures, ensuring robust and effective defense mechanisms.
What You'll Be Doing
- External Security Testing: You'll meticulously monitor, map, and test the full extent of Sporty’s external attack surface, encompassing all external domains, subdomains, websites, and public IP addresses. - Adversary Emulation Exercises: Engage in simulated attacks against internal endpoints to verify the efficacy of our Endpoint Detection and Response (EDR) and XDR systems, as well as our SOC monitoring platforms. - Physical and Network Security Audit: Evaluate the security posture of our physical office hardware, network equipment, and internal edge infrastructure. - Web Application and API Testing: Conduct targeted offensive testing on external web applications and public API endpoints. - Defensive Strategy Development: Convert findings from external and network security assessments into actionable defensive strategies, including firewall rules and other protective measures. - Purple Team Collaboration: Work alongside our Purple Team to ensure that our EDR policies, perimeter controls, and firewall rules are functioning as intended. - Exploitation Documentation: Document multi-stage network or system exploitation scenarios to provide detailed remediation guidelines for IT and Security teams. - Vulnerability Support: Assist IT and Network analysts with clear descriptions of vulnerabilities, triage steps, and escalation protocols. - Security Gap Analysis: Track and report on external vulnerability gaps, success rates of emulations, remediation times, asset health, and perimeter exposure trends.
What You'll Bring
- Offensive Security Expertise: Proven experience in offensive security, perimeter penetration testing, and network security assessments. - Discovery and Vulnerability Knowledge: A solid understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing. - Technical Proficiency: Practical experience in auditing and testing Linux and Windows environments, as well as underlying network services. - Advanced Emulation Skills: Ability to conduct advanced adversary emulation and bypass techniques against modern EDR and XDR solutions. - Physical Network Testing: Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems. - Clear Recommendations: Transform technical risks into clear, actionable recommendations for IT and Security teams. - Web and API Testing: Experience with core web vulnerabilities and limited API interface testing. - Automation Skills: Strong scripting abilities in Python, PowerShell, Bash, or similar tools for perimeter mapping, emulation workflows, and asset discovery. - Tool Proficiency: Knowledge of scanning, reconnaissance, and interception tools, including Kali Linux, Nmap, Shodan, Censys, and others.
Technology Expertise
You should be proficient in any of the following tools and technologies:
- Kali Linux - Nmap - Shodan - Censys - Masscan - Amass - DNS testing tools - Wireshark - Burp Suite - OWASP ZAP - Microsoft Defender XDR - CrowdStrike Falcon - SentinelOne - Atomic Red Team - Caldera - Python - PowerShell - Bash - VPS environments (Linux/Windows Server OS) - Firewalls, Routers - Git, Jira, Confluence
What's in It for You
Sporty is committed to sustainability and offers a remote-first work environment with a competitive salary, individual performance-based bonuses, and 28 days of paid annual leave. Our flexible working hours are 10am-3pm in your local time zone, with additional flexibility outside these hours. We provide top-tier equipment, referral bonuses, and flash bonuses. Additionally, we host annual company retreats that foster global collaboration and connection among our team members.
Interview Process
- Video Screening: Initial review by our Talent Acquisition Team. - Online Assessment: Technical evaluation using Hackerrank. - Video Interview: 60-minute interview with team members. - Final Interview: 60-minute discussion with the hiring manager.
If you're eager to join us, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.
Donator wrote this description from the employer's advert. See the employer's original.
Frequently asked questions about this job
Can I apply for Offensive Security Engineer from where I live?
Yes. Sporty Group accepts candidates for this vacancy from anywhere in Europe, so you need no work permit for a foreign country. The advert passed an automated check: had the employer required a work permit, visa sponsorship or residence in a specific country, it would not be on this board.
What pay is stated?
Sporty Group did not publish pay for this vacancy. Most remote adverts publish no figure; it is settled at interview.
How do I apply?
You apply directly to the employer, through the original advert published on Jobicy. Donator takes no applications, charges no commission and stores no CV.
What kind of vacancy is this?
A fully remote role in IT and programming. Hybrid adverts and anything requiring office attendance are not published on this board.
Free certificates for this vacancy
The free certificates that carry the most weight in this field. Each one is verified on the provider's own page.
Applied Skills (scenario-based credentials)
exam is free tooMicrosoft · ~1 h
Microsoft's only free verifiable credential: a lab task in 30-45 minutes, with no proctor, no ID check and no card. Retakes are allowed.
It has to be finished in one session; there is no save and resume.
strong brandOCI Foundations Associate
exam is free tooOracle · ~12 h
A rare case where the certification exam itself is free and needs no Pearson VUE: you sit it inside MyLearn. Take the 2026 track, not the 2025 one.
Oracle's pages load via JS; confirm the $0 on the final step of registration.
strong brandValid: 18-24 monthsCS50x: Introduction to Computer Science
certificateHarvard CS50 · ~100 h
Harvard's own branded certificate is free once you pass every problem set and the final project. The edX verified certificate is a separate paid product and is not needed.
strong brandCS50P: Programming with Python
certificateHarvard CS50 · ~60 h
Same mechanism as CS50x: at least 70% on every assignment plus a final project. The certificate does not expire.
strong brand
Similar jobs
Software UX/UI Design Lead - REMOTE
Gorin Systems · today
NewFrom anywhereFull Stack Laravel / React Developer
Gorin Systems · today
NewFrom anywhereReactPHPExecutive Director - CLEAR Global
CLEAR Global · today
NewFrom anywhereInterpreter - Independent Contractor
Goodwill SOLAC · yesterday
NewFrom anywhere
