Sporty Group - Offensive Security Engineer
Requirements
• Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation. • Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing. • Practical experience auditing and testing Linux and Windows environments and underlying network services. • Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions. • Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems. • Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams. • Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces. • Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery. • Good understanding of scanning, reconnaissance, and interception tools. • Strong documentation skills. • Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence
Responsibilities
• Monitor, map, and test Sporty’s entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses. • Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms. • Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure. • Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints. • Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks. • Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected. • Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams. • Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance. • Improve external asset tracking, perimeter health records, and exposure trend mapping. • Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure.
Benefits
• Sporty is a remote-first company in pursuit of sustainability • A competitive salary plus individual performance-based bonuses every quarter • 28 days paid annual leave • Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours • Referral bonuses and flash bonuses • Top-of-the-line equipment • Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world • Interview Process: • Remote video screening with our Talent Acquisition Team • Online assessment via Hackerrank • Remote video interview with Team Members (60 Mins) • Final discussion with the hiring manager (60 mins) • If you're interested, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT