进攻性安全工程师
Offensive Security Engineer
关于该职位
职责:模拟真实攻击者针对我们业务的完整攻击链。作为我们的红队专家,你将从外部初始访问开始,通过钓鱼、C2、横向移动、权限提升和Active Directory域入侵,一直到对最关键资产的行动,规划并执行全范围、目标驱动的操作。你在成熟且被监控的环境中进行隐蔽操作,突破现代EDR/XDR和检测控制,并证明一个有决心的攻击者能走多远。然后,你将每项操作转化为具体的检测工程成果和防御改进,与蓝队合作。
你将做的事情
- 范围界定、计划并执行全范围红队任务和长期威胁模拟活动,映射到真实威胁行为者的TTPs和MITRE ATT&CK框架。
- 执行完整的攻击链:OSINT和侦察、初始访问(钓鱼、有效载荷传递、公开面利用)、建立和运营隐蔽C2、持久化、权限提升、横向移动和域/云接管。
- 开发和部署自定义工具、有效载荷和C2基础设施;构建和维护稳健、OPSEC安全的重定向器和命令与控制环境。
- 研究并武器化EDR/XDR规避和绕过技术——内存执行、进程注入、AMSI/ETW篡改和防御规避技术——针对CrowdStrike、SentinelOne和Microsoft Defender XDR。
- 攻克Active Directory和混合/云身份:Kerberos攻击、ACL和委派滥用、ADCS利用,以及在本地和云基础设施(AWS)之间的横向移动。
- 运行假设已入侵、内部威胁和社会工程场景,包括在范围内物理和办公网络入侵路径。
- 直接与蓝队合作,重放攻击链,验证和调整检测,可衡量地缩小检测和响应差距。
- 记录完整的攻击叙事、攻击链图示和可重复的POC步骤,让防御者能够重建并检测每个阶段。
- 将操作发现转化为IT、网络和安全团队可优先处理、可操作的修复和检测工程指导。
- 跟踪操作指标:达成的目标、检测和响应时间、停留时间、规避成功率和修复跟进情况。
- 为Sporty的红队能力发展和威胁情报做出贡献
查看英文原文
About the role
Mission: Emulate the full kill chain of the real-world adversaries that target our business. As our Red Team Expert, you plan and execute full-scope, objective-driven operations from external initial access through phishing, C2, lateral movement, privilege escalation, and Active Directory domain compromise, all the way to actions on objective against our most critical assets. You operate covertly against a mature, monitored environment, defeat modern EDR/XDR and detection controls, and prove exactly how far a determined attacker could get. You then turn every operation into concrete detection engineering wins and defensive improvements alongside our Blue Team.
What you'll be doing
- Scope, plan, and execute full-scope red team engagements and long-horizon adversary emulation campaigns mapped to real threat-actor TTPs and the MITRE ATT&CK framework.
- Execute the complete attack chain: OSINT and reconnaissance, initial access (phishing, payload delivery, public-facing exploitation), establishing and operating covert C2, persistence, privilege escalation, lateral movement, and domain/cloud takeover.
- Develop and deploy custom tooling, payloads, and C2 infrastructure; build and maintain resilient, OPSEC-safe redirector and command-and-control environments.
- Research and weaponize EDR/XDR evasion and bypass techniques — in-memory execution, process injection, AMSI/ETW tampering, and defense-evasion tradecraft — against CrowdStrike, SentinelOne, and Microsoft Defender XDR.
- Compromise Active Directory and hybrid/cloud identity: Kerberos attacks, ACL and delegation abuse, ADCS exploitation, and lateral movement across on-prem and cloud infrastructure (AWS).
- Run assumed-breach, insider-threat, and social-engineering scenarios, including physical and office-network intrusion paths where in scope.
- Work directly with the Blue Team to replay attack chains, validate and tune detections, and measurably close detection and response gaps.
- Document full attack narratives, kill-chain diagrams, and reproducible proof-of-concept steps that let defenders rebuild and detect every stage.
- Translate operational findings into prioritized, actionable remediation and detection-engineering guidance for IT, Network, and Security teams.
- Track operational metrics: objectives achieved, detection and response times, dwell time, evasion success rates, and remediation follow-through.
- Contribute to maturing Sporty's red team capability and threat-informed defense, sharing tradecraft with internal offensive and defensive staff.
What you'll bring
Experience (required)
- 5+ years of hands-on experience in offensive security, perimeter penetration testing, network security assessments, red teaming, or adversary emulation.
- Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.
- Practical experience auditing and testing Linux and Windows environments and underlying network services.
- Proven ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.
- Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.
- Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.
- Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.
- Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.
- Good understanding of scanning, reconnaissance, and interception tools.
- Strong documentation skills.
Certifications (one or more required)
- OffSec: OSCP / OSCP+, OSEP, OSWE, OSED, OSCE3 (or legacy OSCE), OSWA, OSMR, OSEE
- Hack The Box: CPTS, CBBH, CWEE, CAPE
- Red Team / Active Directory: CRTO, CRTL (Zero-Point Security); CRTP, CRTE, CRTM (Altered Security)
- GIAC: GPEN, GXPN, GWAPT, GRTP, GCPN
- Other recognized: PNPT (TCM Security), eCPPT / eWPTX / eMAPT (INE), BSCP (PortSwigger), CREST CRT / CCT, CPTE
Community and competitive track record
- Bug bounty recognition: bounty awards, hall-of-fame listings, or published CVEs through HackerOne, Bugcrowd, Intigriti, YesWeHack, or vendor-run programs.
- CTF achievements: active player on a ranked CTFtime team, Hack The Box Hall of Fame or Pro Lab completions, or finalist/podium placements in recognized competitions (DEF CON CTF, Google CTF, HTB Business CTF, SANS Holiday Hack, and similar).