donator JOBS

IT 与编程

Offensive Security Engineer(远程职位)

Sporty Group

限欧洲远程Europe
申请

链接会跳转到原始招聘信息。Donator 不代收申请。

发布时间: (14 天前)有效期: 截至 2026年9月19日

Offensive Security Engineer:「IT 与编程」类别,完全远程

这条招聘信息来自 Sporty Group,岗位是 Offensive Security Engineer。职位属于「IT 与编程」类别,完全远程。公司招的是居住在欧洲的候选人。

公司没有公布具体数字,这一项会在面试时谈定。对工作时间,招聘信息没有提出任何条件。

这个职位通过了自动核查:凡是要求外国工作许可、签证担保、特定国籍,或者必须居住在指定国家的招聘信息,都不会进入列表。

要点

公司
Sporty Group
类别
IT 与编程
谁可以申请
来自欧洲任何国家
工作方式
完全远程
用工形式
全职
发布时间
2026年8月10日 (14 天前)
有效期
截至 2026年9月19日
来源
Jobicy

新职位邮件提醒:IT 与编程

职位板每天更新数次。只有出现新的、已核查的职位时才会写信。不发垃圾邮件,也不需要注册账号。

已经订阅过了? 管理订阅设置

公司发布的职位描述

About the role Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails. What you'll be doing

* Monitor, map, and test Sporty’s entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses.

* Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms.

* Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure.

* Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints.

* Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks.

* Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected.

* Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams.

* Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance.

* Improve external asset tracking, perimeter health records, and exposure trend mapping.

* Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure.

What you'll bring

* Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation.

* Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.

* Practical experience auditing and testing Linux and Windows environments and underlying network services.

* Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.

* Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.

* Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.

* Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.

* Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.

* Good understanding of scanning, reconnaissance, and interception tools.

* Strong documentation skills.

Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence What's in it for you

* Sporty is a remote-first company in pursuit of sustainability

* A competitive salary plus individual performance-based bonuses every quarter

* 28 days paid annual leave

* Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours

* Referral bonuses and flash bonuses

* Top-of-the-line equipment

* Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world

Interview Process:

* Remote video screening with our Talent Acquisition Team

* Online assessment via Hackerrank

* Remote video interview with Team Members (60 Mins)

* Final discussion with the hiring manager (60 mins)

If you're interested, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.

职位正文保留公司发布时的原文,因为投递的时候用的也是同一种语言。

该职位发布于 Jobicy. 原始招聘信息 (Jobicy)

关于这个职位的常见问题

我可以在自己居住的地方申请「Offensive Security Engineer」这个职位吗?

可以。对于这个职位,Sporty Group 接受来自欧洲任何国家的候选人,所以你不需要其他国家的工作许可。这条招聘信息通过了自动核查:如果雇主要求工作许可、签证担保,或者必须居住在某个特定国家,它就不会出现在本站。

标明的报酬是多少?

对于这个职位,Sporty Group 没有公布报酬。多数远程招聘信息不给出具体数字,这件事会在面试时谈定。

怎么申请?

你通过发布在 Jobicy 上的原始招聘信息,直接向雇主提交申请。Donator 不代收申请,不收取佣金,也不保存简历。

这是什么类型的职位?

这是「IT 与编程」类别中的一个完全远程职位。混合办公的招聘信息,以及任何需要到办公室的职位,本站都不会发布。

适合这个职位的免费证书

这个领域里分量最重的几张免费证书。每一张都在发证方自己的页面上核实过。

全部免费证书:「IT and cloud」

相似职位

远程职位:Offensive Security Engineer | Donator