Offensive Security Engineer
HybridSan Salvador, San Salvador Department, El Salvador
Job Summary
Plan, scope, and execute penetration tests across web, mobile, and cloud-based applications. Identify, exploit, validate, and document security vulnerabilities using manual and automated testing techniques. Develop testing strategies aligned with organizational security objectives and compliance requirements. Leverage threat intelligence, attacker TTPs, and emerging security trends to continuously improve testing methodologies. Collaborate with application owners, DevOps teams, and Security Engineers throughout the assessment lifecycle. Prepare clear, actionable security reports, including findings, exploitation details, risk assessments, and remediation recommendations. Support engineering teams in validating fixes and improving the overall security posture of applications.
Required Qualifications
- 3+ years of hands-on experience in Penetration Testing or Offensive Security
- Proven experience performing penetration tests for web, mobile, and cloud-based applications
- Strong knowledge of vulnerability research, exploitation techniques, and security assessment methodologies
- Hands-on experience with industry-standard security tools such as Burp Suite, Metasploit, Nmap, and custom scripting
- Familiarity with Threat Intelligence, attacker TTPs, and the MITRE ATT&CK framework
- Strong analytical, troubleshooting, and problem-solving skills
- Excellent written and verbal communication skills, with the ability to present technical findings to both technical and non-technical audiences
- Experience collaborating with Development, DevOps, and Security teams
- Advanced English proficiency
Desired Qualifications
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or a related field
- Offensive Security certifications such as OSCP, OSWE, OSCE, OSWP, eCPPT, eWPT, CEH, GPEN, GXPN, or similar
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.