Sr Offensive Security Engineer
First Advantage
Skill Required
Key highlights
- Senior-level offensive security position
- 5+ years required hands-on experience
- Cloud penetration testing (AWS/Azure required, container/Kubernetes serverless nice-to-have)
- MITRE ATT&CK framework expertise required
Role overview
First Advantage seeks a Senior Offensive Security Engineer for their Threat Management & Security Operations organization. This hands-on role requires thinking and operating like an adversary to find, exploit, and help remediate real-world weaknesses across products, cloud infrastructure, networks, and people. The position designs and executes penetration tests, red and purple team engagements, and adversary emulation exercises to validate detection capabilities and reduce enterprise risk at-scale. The ideal candidate partners with Security Operations, Threat Intelligence & Hunt, Vulnerability Management, Application Security, DevOps, and Product teams to turn offensive findings into prioritized, business-aligned remediation. Equal comfort with building custom tooling, chaining exploits across complex environments, and communicating impact clearly to technical teams and executive leadership is essential.
Responsibilities
- Plan, scope, and execute internal and external penetration tests across web and mobile applications, APIs, cloud (AWS/Azure), networks, and infrastructure using real-world attacker techniques.
- Design and run adversary emulation and red team engagements that combine multiple attack paths to accomplish objective-based goals, and partner with the SOC, Threat Intel & Hunt, and Detection Engineering on purple team exercises to validate and improve detection coverage.
- Identify, validate, and safely exploit vulnerabilities — including chaining lower-severity issues into high-impact attack paths — and demonstrate tangible business impact in production-representative environments.
- Model real-world threat actor tactics, techniques, and procedures (TTPs) mapped to the MITRE ATT&CK framework to test and strengthen organizational resilience, detection, and response.
- Review and validate findings for accuracy, prioritize real-world exploitability and business risk, create remediation tickets, and partner with engineering teams to drive fixes and coordinate retests within policy SLAs.
- Build and maintain custom scripts, tooling, and automation to scale offensive testing, and help operationalize continuous/autonomous testing platforms across the environment.
- Produce clear, decision-ready reports and executive summaries that translate technical findings into risk and business impact for technical stakeholders, GRC/Audit, and executive leadership.
- Support incident response and threat hunting efforts by providing offensive expertise, attack-path context, and adversary insight.
- Contribute to the maturity of the offensive security program — developing repeatable methodologies, playbooks, and metrics that demonstrate progress over time.
Requirements
- 5+ years of hands-on experience in offensive security, penetration testing, red teaming, or a closely related security engineering role.
- Demonstrated expertise across multiple domains: web/mobile application, API, network, infrastructure, and cloud (AWS and/or Azure) penetration testing.
- Strong understanding of exploitation and post-exploitation techniques, attack-path chaining, and objective-based adversary emulation.
- Proficiency with industry-standard offensive tooling such as Burp Suite Professional, Nmap, Metasploit, and Kali Linux, along with vulnerability scanners.
- Proficiency in at least one scripting or programming language (e.g., Python, Go, PowerShell, Ruby, or Bash) to build custom tools and automation.
- Working knowledge of the MITRE ATT&CK framework and hands-on experience mapping engagements to adversary TTPs.
- Excellent written and verbal communication skills, with the ability to present findings to both technical audiences and executive leadership.
Nice to have
- Advanced offensive certifications (e.g., OSEP, OSCE³, CRTO, GXPN) and a track record of original security research, CVEs, or responsible disclosures.
- Experience with cloud-native attack techniques and container/Kubernetes (EKS/AKS) and serverless security testing.
- Experience operating or evaluating continuous/autonomous pen testing and breach-and-attack-simulation platforms.
- Familiarity with detection engineering, SIEM/EDR platforms, and building purple team feedback loops into SOC content.
- Knowledge of compliance and security frameworks relevant to our environment.
- Experience mentoring junior engineers and helping mature an offensive security program.
Benefits
- Employee Impact Groups
- FA Cares volunteer opportunities
- Mentorship Advantage Program
- SOAR, award-winning manager development program
Additional details
- At First Advantage, team members are united around a noble purpose: helping organizations to safeguard their workplaces and manage risk. The company's culture is shaped by its core values — Authenticity, Curiosity, Integrity, Teamwork, Customer-Inspired — empowering team members to bring their best ideas forward, collaborate across departments, and make a real impact.
- First Advantage offers a variety of culture programs and benefits designed to enhance employee experience and development.
- Equal Employment Opportunities at First AdvantageFirst Advantage is an equal opportunity employer. We are committed to providing a workplace and recruitment process that is free from unlawful discrimination, harassment, and retaliation. Employment decisions at First Advantage are based solely on qualifications, merit, and business needs. We do not discriminate in any aspect of employment on the basis of race, color, national origin, ancestry, citizenship, religion, creed, sex, gender identity, gender expression, sexual orientation, marital or family status, pregnancy, age, physical or mental disability, medical condition, genetic information, veteran or military status, or any other characteristic protected by applicable law.
- Follow us: Facebook, Instagram, LinkedIn, X, YouTube