CareerScanCareerScan
JobsCompanies
BlogContact
For Employers
Sign InRegister Free
CareerScanCareerScan

India's verified job platform connecting candidates directly with employers. 100% free applications with instant ATS resume scoring.

Chennai, Bengaluru & Hyderabad
Jobs by location
Jobs in ChennaiJobs in BengaluruJobs in HyderabadJobs in PuneJobs in Mumbai
Popular roles
AR Caller JobsHealthcare Medical CodingReact / Full Stack DeveloperData & Power BI AnalystCustomer Support Executive
Top companies
TCS CareersCognizant JobsInfosys OpeningsApollo HospitalsOmega Healthcare
Career services
Free ATS Resume CheckerAI Resume Builder (Free)AI Job MatcherSalary Guide & BenchmarksJob Alerts on WhatsApp
© 2026 CareerScan India. All rights reserved.256-bit SSL encrypted & verified
Back to all jobs
  1. Home
  2. Jobs
  3. Offensive Security Engineer
Sporty Group
Sporty Group

Offensive Security Engineer

Europe - Remote
5+ years exp
Full-time
Posted 2d ago
0 views
Actively Hiring Urgent Opening Direct 1-Click Apply

Check Your Resume Match Score

Scan your resume against ATS criteria for this Offensive Security Engineer role at Sporty Group.

Apply for this position

Apply on Company Website
Notice a broken link or wrong info?

Job Description

About the role

Mission: Emulate the full kill chain of the real-world adversaries that target our business. As our Red Team Expert, you plan and execute full-scope, objective-driven operations from external initial access through phishing, C2, lateral movement, privilege escalation, and Active Directory domain compromise, all the way to actions on objective against our most critical assets. You operate covertly against a mature, monitored environment, defeat modern EDR/XDR and detection controls, and prove exactly how far a determined attacker could get. You then turn every operation into concrete detection engineering wins and defensive improvements alongside our Blue Team.

What you'll be doing

  • Scope, plan, and execute full-scope red team engagements and long-horizon adversary emulation campaigns mapped to real threat-actor TTPs and the MITRE ATT&CK framework.

  • Execute the complete attack chain: OSINT and reconnaissance, initial access (phishing, payload delivery, public-facing exploitation), establishing and operating covert C2, persistence, privilege escalation, lateral movement, and domain/cloud takeover.

  • Develop and deploy custom tooling, payloads, and C2 infrastructure; build and maintain resilient, OPSEC-safe redirector and command-and-control environments.

  • Research and weaponize EDR/XDR evasion and bypass techniques — in-memory execution, process injection, AMSI/ETW tampering, and defense-evasion tradecraft — against CrowdStrike, SentinelOne, and Microsoft Defender XDR.

  • Compromise Active Directory and hybrid/cloud identity: Kerberos attacks, ACL and delegation abuse, ADCS exploitation, and lateral movement across on-prem and cloud infrastructure (AWS).

  • Run assumed-breach, insider-threat, and social-engineering scenarios, including physical and office-network intrusion paths where in scope.

  • Work directly with the Blue Team to replay attack chains, validate and tune detections, and measurably close detection and response gaps.

  • Document full attack narratives, kill-chain diagrams, and reproducible proof-of-concept steps that let defenders rebuild and detect every stage.

  • Translate operational findings into prioritized, actionable remediation and detection-engineering guidance for IT, Network, and Security teams.

  • Track operational metrics: objectives achieved, detection and response times, dwell time, evasion success rates, and remediation follow-through.

  • Contribute to maturing Sporty's red team capability and threat-informed defense, sharing tradecraft with internal offensive and defensive staff.

What you'll bring

Experience (required)

5+ years of hands-on experience

in offensive security, perimeter penetration testing, network security assessments, red teaming, or adversary emulation.

  • Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.

  • Practical experience auditing and testing Linux and Windows environments and underlying network services.

  • Proven ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.

  • Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.

  • Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.

  • Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.

  • Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.

  • Good understanding of scanning, reconnaissance, and interception tools.

  • Strong documentation skills.

Certifications (one or more required)

  • OffSec: OSCP / OSCP+, OSEP, OSWE, OSED,

OSCE3 (or legacy OSCE)

, OSWA, OSMR, OSEE

  • Hack The Box:

CPTS

, CBBH, CWEE, CAPE

  • Red Team / Active Directory: CRTO, CRTL (Zero-Point Security); CRTP, CRTE, CRTM (Altered Security)

  • GIAC: GPEN, GXPN, GWAPT, GRTP, GCPN

  • Other recognized: PNPT (TCM Security), eCPPT / eWPTX / eMAPT (INE), BSCP (PortSwigger), CREST CRT / CCT, CPTE

Community and competitive track record

  • Bug bounty recognition: bounty awards, hall-of-fame listings, or published CVEs through HackerOne, Bugcrowd, Intigriti, YesWeHack, or vendor-run programs.
  • CTF achievements: active player on a ranked CTFtime team, Hack The Box Hall of Fame or Pro Lab completions, or finalist/podium placements in recognized competitions (DEF CON CTF, Google CTF, HTB Business CTF, SANS Holiday Hack, and similar).

What’s in it for you

  • Sporty is a remote first company in pursuit of sustainability

  • A competitive salary + individual performance based bonuses every quarter

  • 28 days paid annual leave

  • Our core working hours are 10am-3pm in your local time zone with flexibility outside of this

  • Referral bonuses & flash bonuses

  • Top of the line equipment

  • Annual company retreats to provide great internal networking opportunities

Interview process

  • Remote video screening with our Talent Acquisition Team 

  • Offline Take home assignment

  • Remote video interview with Team Members (60 Mins)

  • Final discussion with the hiring manager (60 mins)

If you're interested, we encourage you to apply! Every application is reviewed by a member of our team (AI is not used in our recruitment process), and we aim to respond within 48 hours. We are committed to maintaining a fair, secure and authentic recruitment process. Applications submitted using false, misleading or fraudulent information, including impersonated or fake profiles, will not be considered. Where reasonably necessary to protect the integrity and security of our recruitment process, we may verify a candidate’s identity and/or the accuracy of information provided during the recruitment process. Any such checks will be carried out in a proportionate and appropriate manner and in accordance with applicable data protection and employment laws.

Frequently Asked Questions

How to apply for Offensive Security Engineer at Sporty Group?

Click the "Apply on Company Website" button on this page to submit your application directly on the employer's official portal.

What is the salary for this role?

Salary details will be discussed during the interview.

What experience is required?

5+ years of experience is required.

Is this position still open?

Yes, currently active and accepting applications.

ApplicationActively Hiring
Apply on Company Website
Broken link or expired?
Sporty Group

Sporty Group

.

Visit Company Website

More jobs at Sporty Group

Analytics Implementation Consultant

Europe - Remote

Backend Software Engineering Team Lead

Europe - Remote

Data Analyst (Europe)

Europe - Remote

Share this Opening

Job Alerts for security

Receive email alerts whenever new security roles in Europe - Remote are posted.

Set Free Alert →

Similar Openings

Explore related active roles in security

View all
UrgentActively Hiring
Doppel
Product Security
Doppel Verified
7+ years
₹12.1L – ₹13.8L/mo
US Remote
securityFull-timeRemote
Posted 19h ago
Apply Now
UrgentActively Hiring
Immersivelabs
Solutions Consultant (Cyber Security) - Portugal
Immersivelabs Verified
2+ years
₹1,245/mo
Portugal
securityFull-time
Posted 19h ago
Apply Now
UrgentActively Hiring
Teciem
Job Role – IAM and PAM Security Lead
Teciem Verified
8+ years
Salary not disclosed
TCMi - Bengaluru
securityFull-time
Posted 19h ago
Apply Now

Offensive Security Engineer

Sporty Group · Europe - Remote

Apply on Company Website