Offensive Security Consultant
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Responsibilities
- Plan and conduct offensive security engagements ranging in size, scope, focus, and approach
- Effectively communicate findings, attack paths, recommendations, and strategy to technical and executive client stakeholders through written reports and verbal presentations
- Build scripts, tools, or methodologies to enhance offensive services
- Serve as a subject matter expert (SME) in one of the following areas: initial access, open-source intelligence analysis, adversary tradecraft, offensive Windows/Linux/macOS operations, evasion operations, or technical capability development
- Utilize common offensive security testing tools and tradecraft
- Stay up to date with cutting-edge adversary tradecraft and vulnerabilities
- Effectively communicate successes and obstacles with fellow team members and team lead(s)
- Interface with client contact(s) and staff in a constructive and professional manner
- Coordinate and prepare for internal and customer facing meetings
- Assist with scoping prospective engagements, participating in technical testing from kickoff through remediation, and mentoring less experienced staff
- Train team members in adversary Tactics, Techniques, and Procedures (TTPs) and tools
- Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, lab support, etc.)
Requirements
- Ability to travel domestically and internationally; up to an average of 25% annually
- Must be able to pass a criminal background check
- Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency
Desired Qualifications
- Working knowledge of offensive security concepts and assessments
- Working knowledge of security principles, policies, and industry best practices
- Working knowledge of Windows and *NIX-based operating systems
- Working knowledge of networking concepts
- Working knowledge of Active Directory
- Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
- Aptitude for technical writing, including assessment reports, presentations and operating procedures
- Proficient written/verbal communication and interpersonal skills
- Independently contribute to significant services and projects
- Ability to lead small teams and engagements
- Ability to manage multiple projects at once
- Ability to effectively communicate with clients, team members, and management for project delivery
- Ability to manage client projects with limited supervision
- Willingness to lead and execute offensive security service offerings (e.g., red team, penetration test, web application security assessment, cloud security assessment, offensive maturity assessment, etc.)
- Willingness to develop and deliver training content as a lead course instructor
- Willingness to mentor and train fellow consultants
Nice to Haves
- Bachelor's degree in a technical field
- Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments
- Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development)
- Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments
- Experience in technical writing
- Experience working for a service-based information security consultancy
- Experience developing and/or providing technical training
- Desire to teach and train students in offensive techniques
- Desire to travel internationally and domestically on a more frequent basis
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
Project Manager - Mobile Telco & Enterprise Software Integration
Airalo
United StatesWorkplace Technology & AI Automation Specialist
Sunriseunitedstatesinc
United StatesSenior Customer Support Engineer
CIQ
United StatesSenior Software Engineer (Technical Lead)
Bloomerang
United StatesMore Openings at SpecterOps
Explore Top Companies in this Space
Futurae
Cybersecurity / Identity & Access Management (IAM) / Multi-Factor Authentication / FinTech Security
1Password
Cybersecurity / Identity and Access Management / Software
Obsidian Security
Cybersecurity / SaaS Security Posture Management (SSPM) / AI & Identity Threat Detection
1Kosmos
Computer and Network Security / Cybersecurity / Identity Verification
SpecterOps
View Company ProfileSpecterOps is the premier, enterprise-grade cybersecurity solutions pioneer, Identity Attack Path Management innovator, and offensive tradecraft powerhouse engineered to operate as the definitive, proactive defense and threat elimination layer for global enterprises, financial institutions, and national security networks. The company completely eliminates the severe systemic friction of modern enterprise infrastructure defenseβwhere security operations center (SOC) cells struggle against complex, deeply nested privilege escalation paths, misconfigured directory service permissions, and invisible lateral adversary movements that bypass traditional endpoint detection systemsβby deploying an advanced, graph-based security ecosystem. Moving far beyond traditional, passive vulnerability scanners or generic penetration testing services, SpecterOps natively unifies real-time identity relationship mapping across Active Directory and Azure AD (Entra ID), automated security choke-point isolation, step-by-step impact-aware remediation pipelines, and elite red-teaming adversary simulations into its flagship corporate workspace, BloodHound Enterprise. As the creators and maintainers of BloodHoundβthe world's leading open-source tool for visualizing hidden directory attack paths trusted by an ecosystem of over 20,000 security expertsβthe institution empowers global security cells to enforce strict least-privilege models and dismantle millions of exploit paths with a single strategic patch. Under the hood, its sophisticated technical practiceβbacked by a massive $75 million Series B funding round led by Insight Partners along with Cisco Investments and M12βnatively orchestrates advanced graph database infrastructure pipelines, patent-protected directory services analysis loops, and secure cloud-to-edge risk profiling grids. What sets SpecterOps apart is its uncompromising dedication to replacing blind, reactive patching cycles with absolute threat-informed architectural momentum; by bridging the gap between deep offensive research and automated, deterministic enterprise hazard mitigation, the firm remains the definitive cornerstone of modern enterprise identity protection and cloud security management.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.