Cyber Security Specialist - Offensive Security / Red Team
About Sentrabyte
Sentrabyte is a dynamic and forward-thinking company focused on cybersecurity. We embrace a remote-first work culture, fostering collaboration through online platforms and attracting talent from around the globe.
About the Position
Introduction
Sentrabyte is seeking a skilled and experienced Cyber Security Specialist with a strong focus on Offensive Security and Red Team operations. This remote-first role offers the opportunity to conduct comprehensive penetration testing and vulnerability assessments, playing a critical part in enhancing our overall security posture.
Responsibilities
- Conduct penetration testing and vulnerability assessments across various environments, including:
- Web applications
- APIs
- Internal networks
- Linux/Windows environments
- Execute offensive security activities, such as:
- Reconnaissance
- Exploitation
- Initial access
- Privilege escalation
- Basic lateral movement
- Vulnerability validation
- Identify and manually validate vulnerabilities, including, but not limited to:
- IDOR (Insecure Direct Object References)
- SQL Injection
- XSS (Cross-Site Scripting)
- SSRF (Server-Side Request Forgery)
- File Upload Issues
- RCE (Remote Code Execution)
- Authentication & Authorization flaws
- Utilize security tools effectively, such as:
- Burp Suite
- Nessus
- Metasploit
- OWASP ZAP
- Nmap
- ffuf
- Custom scripts where necessary
- Prepare clear and comprehensive technical reports, including:
- Impact analysis
- Exploitation methodology
- Remediation recommendations
- Proof-of-concept evidence
- Collaborate with developers and internal stakeholders to continuously improve the organization's security posture.
- Participate in Red Team simulations and real-world attack scenario assessments.
Requirements
- 2–5 years of practical penetration testing or offensive security experience.
- Strong understanding of:
- Linux systems
- Networking fundamentals
- HTTP protocol
- Web application security (OWASP Top 10)
- Common attacker techniques
- Ability to manually validate vulnerabilities beyond automated scanner results.
- Familiarity with:
- Privilege escalation techniques
- Authentication bypass methods
- Post-exploitation basics
- Attack chain methodology
- Basic scripting or automation skills in at least one of the following:
- Python
- Bash
- PowerShell
- Ruby
- Strong communication and technical reporting skills.
Nice to Have
- Active Directory attack exposure.
- Bug bounty or real-world engagement experience.
- API security testing experience.
- Cloud security exposure.
- Prior Red Team experience.
- Security certifications such as:
- OSCP (Offensive Security Certified Professional)
- PNPT (Practical Network Penetration Tester)
- eJPT (eLearnSecurity Junior Penetration Tester)
- CEH (Certified Ethical Hacker)
- CISSP (Certified Information Systems Security Professional)
Benefits
- Salary Range: USD $2000 – $3000 (final compensation depends on technical capability, responsibilities, and project scope).
- Remote-first work environment.
- Opportunity for international candidates to apply.
About Company
Sentrabyte is a dynamic and forward-thinking company focused on cybersecurity. We embrace a remote-first work culture, fostering collaboration through online platforms and attracting talent from around the globe.
How to Apply
Shortlisted candidates will undergo a comprehensive technical evaluation process, including:
- A technical discussion with the security team.
- A practical assessment assignment.
- A methodology and reporting review.
The assessment stage emphasizes practical reasoning, exploitation workflow, validation methodology, and reporting clarity, rather than solely automated scanning results. The assessment completion period is a maximum of 1 week.
Apply Now
Your data is only shared with Sentrabyte
Location
Remote
Type
Full-Time
Keywords
Similar Roles
Explore comparable positions
Cyber Security Specialist - Offensive Security / Red Team
Sentrabyte