Conduct penetration testing and security assessments across web applications, internal infrastructure, Active Directory, cloud environments, and network infrastructure to identify security vulnerabilities.
•
Perform adversary emulation and purple team exercises by collaborating with SOC and Blue team to validate detection capabilities and improve incident response.
•
Assess the security posture of Active Directory, Microsoft Entra ID, cloud platforms (AWS, Azure, GCP), and identity infrastructure against common attack techniques.
•
Support the development and tuning of detection rules for SIEM, EDR, Identity Protection, and other security monitoring platforms.
•
Prepare technical reports and present security findings, risks
Requirements
•
Bachelor’s or associate degree in IT, Computer Science, or related field.
•
At least 5+ years of experience in security design, operation or implementation
•
Strong knowledge of current cyber threats, attack techniques, security controls, and enterprise IT infrastructure across Windows, Linux, Active Directory, cloud, and network environments.
•
Strong understanding of the MITRE ATT&CK Framework, Cyber Kill Chain, and OWASP Top 10, with the ability to emulate attacker techniques and validate security controls.
•
Experience with common penetration testing tools such as Burp Suite, Nmap, Metasploit, BloodHound, Impacket, Mimikatz, or equivalent