← 返回岗位列表中国IT/互联网fulltime

进攻性安全工程师

雇主

Sporty Group

地点

远程 · 中国

待遇

面议

工作模式

远程

截止日期

12月12日

🤖 AI 简历匹配评估

检测你的简历与该岗位的匹配度,免费

免费评估

岗位摘要

About the roleMission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations.…

岗位职责

About the role
Mission Strengthen Sporty’soffensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails.
What you'll be doing
Monitor, map, and test Sporty’s entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses.
Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms.
Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure.
Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints.
Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks.
Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected.
Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams.
Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance.
Improve external asset tracking, perimeter health records, and exposure trend mapping.
Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure.
What you'll bring
Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation.
Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.
Practical experience auditing and testing Linux and Windows environments and underlying network services.
Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.
Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.
Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.
Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.
Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.
Good understanding of scanning, reconnaissance, and interception tools.
Strong documentation skills.
Technology ExpertiseAny of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence
What's in it for you
Sporty is a remote-first company in pursuit of sustainability
A competitive salary plus individual performance-based bonuses every quarter
28 days paid annual leave
Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours
Referral bonuses and flash bonuses
Top-of-the-line equipment
Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world
Interview Process:
Remote video screening with our Talent Acquisition Team
Online assessment via Hackerrank
Remote video interview with Team Members (60 Mins)
Final discussion with the hiring manager (60 mins)
If you're interested, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.

申请条件

- 具备进攻性安全测试经验,能够主动识别外部边界、VPS、物理办公基础设施和终端防御中的漏洞
- 熟悉外部攻击面管理,包括域名、子域名、网站、公共IP地址和DNS配置的监控、测绘与测试
- 能够针对内部和办公终端执行对手模拟演练,以验证EDR、XDR和SOC监控平台的有效性
- 具备评估物理办公硬件、企业网络设备和内部边缘基础设施安全态势的能力
- 能够对外部Web应用和有限的公共API端点执行范围限定的进攻性测试
- 能够将外部发现、DNS安全态势、网络访问控制弱点和EDR模拟结果转化为可重复的防御检查
- 支持紫队验证EDR策略、边界控制、防火墙规则和网络分段按预期工作
- 能够记录多阶段网络或系统利用链,为基础设施和SOC团队提供实用、可复现的修复蓝图
- 能够为IT和网络分析师提供清晰的漏洞描述、分类步骤、严重性逻辑和升级指导
- 具备改进外部资产跟踪、边界健康记录和暴露趋势映射的能力
- 能够跟踪外部漏洞缺口、模拟成功率和修复时间线
- 具备与IT、网络工程、SOC和安全团队密切协作的能力
- 熟悉EDR/XDR系统上的对手模拟和利用技术
- 具备将进攻性安全洞察转化为调优边界控制、防火墙规则和防御护栏的能力

雇主简介

Sporty Group 是一家运营在线体育博彩和游戏平台的公司,专注于提供数字娱乐服务。

对这个岗位感兴趣?

该岗位暂未开放在线申请,顾问可为您推荐同类岗位或申请指导

咨询不收取任何费用,顾问将为您推荐合适的岗位与申请方式

投递国内企业,你的简历符合 HR 筛选标准吗?

AI 自动评估你与该岗位的匹配度,3 分钟出结果

免费评估简历匹配度

数据来源:Jobicy

岗位信息来源于公开渠道,版权归原作者所有