Vulnerable Machine Engineer
Remote
Job Summary
Design and build VMs and multi-host environments from attack vectors across Linux, Windows, and Active Directory, ensuring each scenario is deterministic, reproducible, and aligned with stated learning objectives. Research relevant attack vectors for inclusion in labs and exams, then coordinate with testing and stakeholders to deploy, update, and retire content while maintaining variety across the catalogue. Create and maintain automation for timely lab creation, document every machine to allow independent rebuilds, and act as a technical reviewer for concepts and builds produced by others. Mentor engineers on build standards and provide structured feedback to ensure consistent content quality across OffSec's global lab and exam portfolio.
Required Qualifications
- OSCP minimum
- A Bachelor's Degree in Systems Engineering, Computer Science, Information Systems, and / or Information Assurance from an accredited institution/related specialized field, or equivalent practical experience
- Demonstrable Active Directory and Cloud attack-path experience
- Proficiency with infrastructure-as-code and configuration management and version control
- Scripting proficiency (Python, PowerShell, Bash)
- At least five or more years of experience as a Systems Engineer or in a Info-Sec related position
- Experience with Penetration Testing
- Experience with Bug Bounty Hunting
- Experience as a Systems Administrator with a variety of Operating Systems: MS Windows, MS Windows Based Server Systems, POSIX Server Systems, Linux and Mac Desktop Environments
- Strong written and verbal communication skills with an ability to present technical ideas clearly to both technical and non-technical audiences
Desired Qualifications
- OSCE3 preferred (or at least one OffSec 300-level cert required)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.