About this role.
Sporty Group seeks an Offensive Security Engineer to proactively identify vulnerabilities across external perimeters, VPS, office infrastructure, and endpoints. The role involves continuous attack surface monitoring, adversary emulation on EDR/XDR systems, and translating findings into defensive improvements. The engineer will work closely with IT, Network Engineering, SOC, and Security teams to enhance perimeter controls and firewall rules. This position requires strong technical skills in network security, scripting, and documentation, offering a remote-first environment with competitive benefits.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
4/5Pace & Pressure
3/5Autonomy Level
4/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Cover letter sample
I am excited to apply for the Offensive Security Engineer position at Sporty Group. With extensive experience in perimeter penetration testing, adversary emulation, and EDR/XDR assessment, I am confident in my ability to strengthen your offensive security posture. My background includes mapping external attack surfaces, bypassing modern defenses, and collaborating with cross-functional teams to implement robust security controls.
I have a proven track record of translating complex vulnerabilities into actionable remediation plans, as demonstrated in my previous roles where I improved detection rates by 30% through purple team exercises. Proficient in Kali Linux, Python, and tools like Burp Suite and CrowdStrike Falcon, I am adept at automating reconnaissance and emulation workflows.
I am particularly drawn to Sporty's remote-first culture and commitment to sustainability, which align with my professional values. I look forward to contributing to your team and helping to safeguard your assets.
Sample interview questions
In a recent engagement, I used process injection combined with direct syscalls (via SysWhispers2) to evade CrowdStrike Falcon. I also implemented delayed execution to avoid behavioral analysis. The exercise revealed gaps in the EDR's detection of in-memory threats, leading to improved monitoring rules.
I would start with passive reconnaissance using Shodan, Censys, and certificate transparency logs to identify all public IPs and domains. Then, I'd use Amass and Subfinder for subdomain enumeration, followed by active scanning with Masscan and Nmap to discover open ports and services. Finally, I'd correlate DNS records and SSL certificates to build a comprehensive asset inventory.
During an internal test, I exploited a weak SNMP community string on a network printer to gain initial foothold. From there, I performed ARP spoofing to intercept traffic, extracted credentials from an admin's HTTP session, and used those to access a Windows server. I then leveraged SMB exec for lateral movement and established persistent access via scheduled tasks.
I prioritize based on CVSS score, exploitability, business impact, and asset criticality. For example, a remote code execution on a public-facing web server would be critical, while a low-severity information disclosure might be lower priority. I also consider the current threat landscape and any compensating controls in place.
I primarily use Python for custom tools, such as automating Shodan queries and parsing results. I also use Bash for quick reconnaissance scripts and PowerShell for Windows-based tasks. For automation of adversary emulation, I have experience with Caldera and Atomic Red Team, which I integrate with CI/CD pipelines to run regular tests.
About the role
Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails.
What you’ll be doing
- Monitor, map, and test Sporty’s entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses.
- Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms.
- Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure.
- Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints.
- Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks.
- Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected.
- Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams.
- Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance.
- Improve external asset tracking, perimeter health records, and exposure trend mapping.
- Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure.
What you’ll bring
- Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation.
- Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.
- Practical experience auditing and testing Linux and Windows environments and underlying network services.
- Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.
- Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.
- Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.
- Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.
- Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.
- Good understanding of scanning, reconnaissance, and interception tools.
- Strong documentation skills.
Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence
What’s in it for you
- Sporty is a remote-first company in pursuit of sustainability
- A competitive salary plus individual performance-based bonuses every quarter
- 28 days paid annual leave
- Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours
- Referral bonuses and flash bonuses
- Top-of-the-line equipment
- Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world
Interview Process:
- Remote video screening with our Talent Acquisition Team
- Online assessment via Hackerrank
- Remote video interview with Team Members (60 Mins)
- Final discussion with the hiring manager (60 mins)
If you’re interested, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.




