TI e programação
Offensive Security Engineer - vaga remota
Sporty Group
O link leva ao anúncio original. Donator não recebe candidaturas.
Offensive Security Engineer - TI e programação, remoto
A empresa Sporty Group está com uma vaga aberta de Offensive Security Engineer. A posição fica na área de TI e programação e é totalmente remota. A empresa contrata candidatos que estejam na Europa.
A empresa não publicou nenhum valor, isso é acertado na entrevista. O anúncio não impõe condição nenhuma de horário.
Esta vaga passou por uma verificação automática: anúncios que exigem autorização de trabalho estrangeira, patrocínio de visto, uma nacionalidade específica ou residência em um país indicado não entram na lista.
Em resumo
- Empresa
- Sporty Group
- Área
- TI e programação
- Quem pode se candidatar
- De qualquer país da Europa
- Formato de trabalho
- Totalmente remota
- Tipo de contrato
- Tempo integral
- Publicada
- 10 de agosto de 2026 (há 14 dias)
- Ativa
- até 19 de setembro de 2026
- Fonte
- Jobicy
Novas vagas de TI e programação por e-mail
O quadro é atualizado várias vezes por dia. Só escrevemos quando aparece uma vaga nova e já verificada. Sem spam e sem precisar de conta.
Já assinou? Gerenciar as configurações
Descrição da empresa
About the role Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails. What you'll be doing
* Monitor, map, and test Sporty’s entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses.
* Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms.
* Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure.
* Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints.
* Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks.
* Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected.
* Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams.
* Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance.
* Improve external asset tracking, perimeter health records, and exposure trend mapping.
* Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure.
What you'll bring
* Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation.
* Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.
* Practical experience auditing and testing Linux and Windows environments and underlying network services.
* Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.
* Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.
* Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.
* Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.
* Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.
* Good understanding of scanning, reconnaissance, and interception tools.
* Strong documentation skills.
Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence What's in it for you
* Sporty is a remote-first company in pursuit of sustainability
* A competitive salary plus individual performance-based bonuses every quarter
* 28 days paid annual leave
* Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours
* Referral bonuses and flash bonuses
* Top-of-the-line equipment
* Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world
Interview Process:
* Remote video screening with our Talent Acquisition Team
* Online assessment via Hackerrank
* Remote video interview with Team Members (60 Mins)
* Final discussion with the hiring manager (60 mins)
If you're interested, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.
O texto permanece no idioma original da empresa, porque é nesse mesmo idioma que você vai se candidatar.
Perguntas frequentes sobre esta vaga
Posso me candidatar à vaga de Offensive Security Engineer de onde eu moro?
Sim. Para esta vaga, Sporty Group aceita candidatos de qualquer país da Europa, então você não precisa de autorização de trabalho de outro país. O anúncio passou por uma verificação automática: se a empresa exigisse autorização de trabalho, patrocínio de visto ou residência em um país específico, ele não estaria neste quadro.
Qual é a remuneração informada?
Para esta vaga, Sporty Group não divulgou remuneração. A maioria dos anúncios remotos não publica valor, isso é acertado na entrevista.
Como eu me candidato?
Você se candidata diretamente à empresa, pelo anúncio original publicado em Jobicy. Donator não recebe candidaturas, não cobra comissão e não guarda currículos.
Que tipo de vaga é esta?
Uma vaga totalmente remota na área de TI e programação. Anúncios híbridos e tudo o que exige presença no escritório não são publicados neste quadro.
Certificados gratuitos para esta vaga
Os certificados gratuitos que mais pesam nesta área. Cada um é conferido na própria página da instituição que o emite.
Applied Skills (scenario-based credentials)
exam is free tooMicrosoft · ~1 h
Microsoft's only free verifiable credential: a lab task in 30-45 minutes, with no proctor, no ID check and no card. Retakes are allowed.
It has to be finished in one session; there is no save and resume.
strong brandOCI Foundations Associate
exam is free tooOracle · ~12 h
A rare case where the certification exam itself is free and needs no Pearson VUE: you sit it inside MyLearn. Take the 2026 track, not the 2025 one.
Oracle's pages load via JS; confirm the $0 on the final step of registration.
strong brandValid: 18-24 monthsCS50x: Introduction to Computer Science
certificateHarvard CS50 · ~100 h
Harvard's own branded certificate is free once you pass every problem set and the final project. The edX verified certificate is a separate paid product and is not needed.
strong brandCS50P: Programming with Python
certificateHarvard CS50 · ~60 h
Same mechanism as CS50x: at least 70% on every assignment plus a final project. The certificate does not expire.
strong brand
Vagas parecidas
Executive Director, Lifecycle Leader
$290k - $330k por anoIovance Biotherapeutics · hoje
NovaDe qualquer lugarApplied Researcher - All Levels
$89k - $287k por anoMiris · hoje
NovaDe qualquer lugarMachine LearningSenior Full-Stack Engineer
Private Identity · hoje
NovaDe qualquer lugarPythonSenior Full Stack Engineer
Fueled · hoje
NovaDe qualquer lugarReactTypeScript
