Back to jobs

    About Sentrabyte

    Sentrabyte is a dynamic and forward-thinking company focused on cybersecurity. We embrace a remote-first work culture, fostering collaboration through online platforms and attracting talent from around the globe.

    About the Position

    Introduction

    Sentrabyte is seeking a skilled and experienced Cyber Security Specialist with a strong focus on Offensive Security and Red Team operations. This remote-first role offers the opportunity to conduct comprehensive penetration testing and vulnerability assessments, playing a critical part in enhancing our overall security posture.

    Responsibilities

    • Conduct penetration testing and vulnerability assessments across various environments, including:
      • Web applications
      • APIs
      • Internal networks
      • Linux/Windows environments
    • Execute offensive security activities, such as:
      • Reconnaissance
      • Exploitation
      • Initial access
      • Privilege escalation
      • Basic lateral movement
      • Vulnerability validation
    • Identify and manually validate vulnerabilities, including, but not limited to:
      • IDOR (Insecure Direct Object References)
      • SQL Injection
      • XSS (Cross-Site Scripting)
      • SSRF (Server-Side Request Forgery)
      • File Upload Issues
      • RCE (Remote Code Execution)
      • Authentication & Authorization flaws
    • Utilize security tools effectively, such as:
      • Burp Suite
      • Nessus
      • Metasploit
      • OWASP ZAP
      • Nmap
      • ffuf
      • Custom scripts where necessary
    • Prepare clear and comprehensive technical reports, including:
      • Impact analysis
      • Exploitation methodology
      • Remediation recommendations
      • Proof-of-concept evidence
    • Collaborate with developers and internal stakeholders to continuously improve the organization's security posture.
    • Participate in Red Team simulations and real-world attack scenario assessments.

    Requirements

    • 2–5 years of practical penetration testing or offensive security experience.
    • Strong understanding of:
      • Linux systems
      • Networking fundamentals
      • HTTP protocol
      • Web application security (OWASP Top 10)
      • Common attacker techniques
    • Ability to manually validate vulnerabilities beyond automated scanner results.
    • Familiarity with:
      • Privilege escalation techniques
      • Authentication bypass methods
      • Post-exploitation basics
      • Attack chain methodology
    • Basic scripting or automation skills in at least one of the following:
      • Python
      • Bash
      • PowerShell
      • Ruby
    • Strong communication and technical reporting skills.

    Nice to Have

    • Active Directory attack exposure.
    • Bug bounty or real-world engagement experience.
    • API security testing experience.
    • Cloud security exposure.
    • Prior Red Team experience.
    • Security certifications such as:
      • OSCP (Offensive Security Certified Professional)
      • PNPT (Practical Network Penetration Tester)
      • eJPT (eLearnSecurity Junior Penetration Tester)
      • CEH (Certified Ethical Hacker)
      • CISSP (Certified Information Systems Security Professional)

    Benefits

    • Salary Range: USD $2000 – $3000 (final compensation depends on technical capability, responsibilities, and project scope).
    • Remote-first work environment.
    • Opportunity for international candidates to apply.

    About Company

    Sentrabyte is a dynamic and forward-thinking company focused on cybersecurity. We embrace a remote-first work culture, fostering collaboration through online platforms and attracting talent from around the globe.

    How to Apply

    Shortlisted candidates will undergo a comprehensive technical evaluation process, including:

    • A technical discussion with the security team.
    • A practical assessment assignment.
    • A methodology and reporting review.

    The assessment stage emphasizes practical reasoning, exploitation workflow, validation methodology, and reporting clarity, rather than solely automated scanning results. The assessment completion period is a maximum of 1 week.

    Apply Now

    Your data is only shared with Sentrabyte

    Location

    Remote

    Type

    Full-Time

    Keywords

    Cybersecurity
    Offensive Security
    Red Team
    Penetration Testing
    Vulnerability Assessment
    Web Application Security
    API Security
    Linux
    Python
    Bash
    OWASP Top 10
    Remote
    Full-Time
    Verified Company

    Cyber Security Specialist - Offensive Security / Red Team

    Sentrabyte