
// Open Role at Sporty Group
Strengthen Sporty's security posture by proactively testing and identifying vulnerabilities across external perimeters, VPS, physical infrastructure, and endpoint defenses. This role involves continuous perimeter monitoring, adversary emulation, and translating findings into robust defensive guardrails.
Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails.
Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence
If you're interested, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.
Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation. Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing. Practical experience auditing and testing Linux and Windows environments and underlying network services. Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions. Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems. Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams. Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces. Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery. Good understanding of scanning, reconnaissance, and interception tools. Strong documentation skills. Technology expertise in Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence.