Back to search
Total Information Management Corporation Linkedin · Posted 2d ago

Offensive Security Engineer

Philippines

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

The Offensive Security Engineer will act as an elite adversary simulator, leading full-scope red team and purple team engagements to test and strengthen organizational defenses. This role combines advanced offensive techniques with deep blue team knowledge to emulate real-world threats, identify detection gaps, and drive measurable security improvements. Bridge offense and defense-making this a high-impact, high-reward position with hybrid red/purple skills.


Duties and Responsibilities

  • Plan and execute full-scope red team engagement-from initial reconnaissance/OSINT through persistence, lateral movement, privilege escalation, and objective completion (e.g., data exfil, ransomware simulation).
  • Perform advanced adversary emulation using real-world TTPs mapped to MITRE ATT&CK (including living-off-the-land, evasion of EDR/XDR, AMSI/ETW bypass).
  • Conduct purple team exercises-work side-by-side with blue teams/SOC to test detections in real-time, provide instant feedback, and help tune rules/alerts based on observed attack paths.
  • Develop and maintain custom offensive tooling (Python, Go, PowerShell, C/C++ for implants, C2 frameworks, evasion payloads).
  • Perform specialized testing: web/app exploitation, Active Directory domination, cloud attacks (AWS/Azure/GCP), mobile/wireless.


Qualifications

  • Bachelor's degree in Computer Science/Information Technology.
  • At least 3 years of Vulnerability and Penetration Testing experience.


Knowledge and Skills in

  • Networking & Protocols - Deep understanding of TCP/IP, OSI model, subnetting, routing, DNS, HTTP/HTTPS, SMP, LDAP, Kerberos, etc.
  • Operating Systems Internals - Linux, Windows, Active Directory architecture, file systems, processes, memory management.
  • Web Technologies - HTTP architecture, client/server-side languages (JavaScript, PHP, Python, .NET, Java), cookies, sessions, authentication flows.
  • Security Concepts - MITRE ATT&CK Framework, OWASP Top 10, common vulnerabilities (CVEs), defense evasion techniques, living-off-the-land.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search