sportygroup

Offensive Security Engineer

Apply Now

At a Glance

Location
Europe
Work Regime
remote
Posted
2026-07-07T03:44:49-04:00

Key Requirements

Required Skills

BashConfluenceGitJiraLinuxPython

Requirements

Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation.

Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.

Practical experience auditing and testing Linux and Windows environments and underlying network services.

Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.

Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.

Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.

Compensation & Benefits

Sporty is a remote-first company in pursuit of sustainability

A competitive salary plus individual performance-based bonuses every quarter

28 days paid annual leave

Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours

Referral bonuses and flash bonuses

Top-of-the-line equipment

Responsibilities

Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses.

The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations.

This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails.

Monitor, map, and test Sporty’s entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses.

Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms.

Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure.