
// Open Role at Sporty Group
Strengthen Sporty's security posture by proactively testing and identifying vulnerabilities across external perimeters, VPS, physical infrastructure, and endpoint defenses. This role involves continuous perimeter monitoring, adversary emulation, and translating findings into robust defensive guardrails.
Mission: Emulate the full kill chain of the real-world adversaries that target our business. As our Red Team Expert, you plan and execute full-scope, objective-driven operations from external initial access through phishing, C2, lateral movement, privilege escalation, and Active Directory domain compromise, all the way to actions on objective against our most critical assets. You operate covertly against a mature, monitored environment, defeat modern EDR/XDR and detection controls, and prove exactly how far a determined attacker could get. You then turn every operation into concrete detection engineering wins and defensive improvements alongside our Blue Team.
If you're interested, we encourage you to apply! Every application is reviewed by a member of our team (AI is not used in our recruitment process), and we aim to respond within 48 hours. We are committed to maintaining a fair, secure and authentic recruitment process. Applications submitted using false, misleading or fraudulent information, including impersonated or fake profiles, will not be considered. Where reasonably necessary to protect the integrity and security of our recruitment process, we may verify a candidate’s identity and/or the accuracy of information provided during the recruitment process. Any such checks will be carried out in a proportionate and appropriate manner and in accordance with applicable data protection and employment laws.
Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation. Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing. Practical experience auditing and testing Linux and Windows environments and underlying network services. Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions. Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems. Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams. Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces. Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery. Good understanding of scanning, reconnaissance, and interception tools. Strong documentation skills. Technology expertise in Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence.