Sporty Group logo

Offensive Security Engineer

Sporty Group

Remote
Full-time
Mid Level
Salary not listedPosted 2mo ago

Real job — pulled straight from Sporty Group’s careers page · Verified July 17, 2026 · No reposts.

Job description

Sporty Group is hiring a Offensive Security Engineer — a full-time, remote role. Apply directly on Sporty Group's careers page below.

Offensive Security Engineer

Location: Europe - Remote

Department: IT & IS

About the role

Mission: Emulate the full kill chain of the real-world adversaries that target our business. As our Red Team Expert, you plan and execute full-scope, objective-driven operations from external initial access through phishing, C2, lateral movement, privilege escalation, and Active Directory domain compromise, all the way to actions on objective against our most critical assets. You operate covertly against a mature, monitored environment, defeat modern EDR/XDR and detection controls, and prove exactly how far a determined attacker could get. You then turn every operation into concrete detection engineering wins and defensive improvements alongside our Blue Team.

What you'll be doing

  • Scope, plan, and execute full-scope red team engagements and long-horizon adversary emulation campaigns mapped to real threat-actor TTPs and the MITRE ATT&CK framework.
  • Execute the complete attack chain: OSINT and reconnaissance, initial access (phishing, payload delivery, public-facing exploitation), establishing and operating covert C2, persistence, privilege escalation, lateral movement, and domain/cloud takeover.
  • Develop and deploy custom tooling, payloads, and C2 infrastructure; build and maintain resilient, OPSEC-safe redirector and command-and-control environments.
  • Research and weaponize EDR/XDR evasion and bypass techniques — in-memory execution, process injection, AMSI/ETW tampering, and defense-evasion tradecraft — against CrowdStrike, SentinelOne, and Microsoft Defender XDR.
  • Compromise Active Directory and hybrid/cloud identity: Kerberos attacks, ACL and delegation abuse, ADCS exploitation, and lateral movement across on-prem and cloud infrastructure (AWS).
  • Run assumed-breach, insider-threat, and social-engineering scenarios, including physical and office-network intrusion paths where in scope.
  • Work directly with the Blue Team to replay attack chains, validate and tune detections, and measurably close detection and response gaps.
  • Document full attack narratives, kill-chain diagrams, and reproducible proof-of-concept steps that let defenders rebuild and detect every stage.
  • Translate operational findings into prioritized, actionable remediation and detection-engineering guidance for IT, Network, and Security teams.
  • Track operational metrics: objectives achieved, detection and response times, dwell time, evasion success rates, and remediation follow-through.
  • Contribute to maturing Sporty's red team capability and threat-informed defense, sharing tradecraft with internal offensive and defensive staff.

What you'll bring

Experience (required)

  • 5+ years of hands-on experience in offensive security, perimeter penetration testing, network security assessments, red teaming, or adversary emulation.
  • Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.
  • Practical experience auditing and testing Linux and Windows environments and underlying network services.
  • Proven ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.
  • Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.
  • Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.
  • Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.
  • Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.
  • Good understanding of scanning, reconnaissance, and interception tools.
  • Strong documentation skills.

Certifications (one or more required)

  • OffSec: OSCP / OSCP+, OSEP, OSWE, OSED, OSCE3 (or legacy OSCE), OSWA, OSMR, OSEE
  • Hack The Box: CPTS, CBBH, CWEE, CAPE
  • Red Team / Active Directory: CRTO, CRTL (Zero-Point Security); CRTP, CRTE, CRTM (Altered Security)
  • GIAC: GPEN, GXPN, GWAPT, GRTP, GCPN
  • Other recognized: PNPT (TCM Security), eCPPT / eWPTX / eMAPT (INE), BSCP (PortSwigger), CREST CRT / CCT, CPTE

Community and competitive track record

  • Bug bounty recognition: bounty awards, hall-of-fame listings, or published CVEs through HackerOne, Bugcrowd, Intigriti, YesWeHack, or vendor-run programs.
  • CTF achievements: active player on a ranked CTFtime team, Hack The Box Hall of Fame or Pro Lab completions, or finalist/podium placements in recognized competitions (DEF CON CTF, Google CTF, HTB Business CTF, SANS Holiday Hack, and similar).

Get Penetration Tester jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Anyone Ai logo

Python Developer - Remote in Spain

Spain
✓ From careers page· 19h ago
Anyone Ai logo

Python Developer (Ecuador)

Remote
✓ From careers page· 19h ago
Anyone Ai logo

Python Developer - Remote in Portugal

Portugal
✓ From careers page· 19h ago
Anyone Ai logo

Python Developer (Colombia)

Remote
✓ From careers page· 19h ago

Frequently asked questions

Is Offensive Security Engineer at Sporty Group a remote job?

Yes, Offensive Security Engineer at Sporty Group is a remote position. This role is open to remote candidates.

What skills are required for Offensive Security Engineer at Sporty Group?

The required skills for Offensive Security Engineer at Sporty Group include: Python, PowerShell, Bash, DNS, Linux, Windows Server, Git, JIRA, Confluence.

What is the seniority level for Offensive Security Engineer at Sporty Group?

Offensive Security Engineer at Sporty Group is a Mid Level level position.

How do I apply for Offensive Security Engineer at Sporty Group?

You can view the full description and apply for Offensive Security Engineer at Sporty Group on EchoJobs: https://echojobs.io/job/sporty-group-offensive-security-engineer-kqwi9.