About Us
At Stratascale, we are a dynamic digital and cybersecurity services company dedicated to empowering Fortune 1000 companies to effectively harness technology, drive business growth, and swiftly adapt to market changes. We champion what we call Digital Agility.
Job Overview
We are seeking a Senior Security Consultant - Offensive Security, a pivotal role in our Adversarial Operations team. You will play a key part in developing and delivering a comprehensive range of threat management consulting services, penetration testing, and operational services tailored to our diverse client base.
This position is remote, with a Home Office setup determined by Stratascale management.
Key Responsibilities
- Execute penetration tests across complex environments, addressing external, internal, web application, and other offensive security scenarios.
- Analyze and document attack surfaces, threat landscapes, and recommend vulnerability improvements based on assessments of each client’s environment.
- Conduct thorough assessments and threat modeling per industry best practices to identify control weaknesses and evaluate the effectiveness of existing safeguards.
- Carry out root cause analyses on vulnerabilities and weaknesses; propose technical solutions and remediation strategies for clients.
- Collaborate with client security teams to discuss mitigation strategies for identified vulnerabilities.
- Evaluate threat intelligence specific to client industries to inform attack path modeling.
- Help quantify and communicate business risks and the impacts of vulnerabilities to clients and their stakeholders.
- Provide expertise in remediation, cloud security, governance, compliance, and core infrastructure systems.
- Support clients with strategies, technical analysis, compliance assessments, and platform usage, including automation strategies.
- Develop and present governance models, security frameworks, compliance reports, and security assessments.
- Work closely with internal sales and technical teams to support solution sales cycles and ensure successful solution delivery.
- Identify customer needs and proactively recommend appropriate solutions while spotting areas for improvement.
- Lead consulting projects by creating and finalizing deliverables, ensuring client needs are met.
- Create training materials and conduct workforce development programs, available both in person and online.
- Engage in meetings to provide technical guidance and facilitate discussions.
- Keep abreast of new technologies, industry trends, and emerging practices.
- Collaborate with other practice leaders and mentor team members to refine capabilities.
Desired Competencies
Communication : Effectively convey intricate ideas to diverse audiences and mentor others in effective communication.Relationship Management : Build strong connections across teams and drive results through effective collaboration.Self-Starter : Independently manage complex initiatives while working with others when necessary.Negotiation Skills : Manage complex negotiations and build consensus among team members.Influence : Inspire teams to work toward shared goals.Business Acumen : Take ownership of significant business initiatives and collaborate with stakeholders to achieve results.Emotional Intelligence : Adjust emotions to suit environments and assist others in doing the same.Attention to Detail : Oversee multiple projects with precision, identifying inconsistencies and ensuring task accuracy.Follow-Up : Actively manage tasks and collaborate with others to implement follow-ups effectively.Presentation Skills : Utilize visual aids and storytelling techniques to captivate audiences during presentations.Delegation : Delegate tasks effectively across teams while ensuring clarity of roles and responsibilities.Analytical Skills : Employ advanced techniques to dissect complex issues and develop actionable insights.Critical Thinking : Synthesize information from diverse sources to guide strategic decisions.Technical Troubleshooting : Manage complex technical issues collaboratively to reach solutions.Skills and Qualifications
Expert in planning and executing penetration tests across networks, web and mobile applications, APIs, wireless, and cloud environments.Proficient in offensive security methodologies and frameworks like PTES, OWASP, and MITRE ATT&CK.Extensive hands-on experience with offensive tools and techniques for reconnaissance, exploitation, and data exfiltration.Skilled in assessing cloud services (AWS, Azure, GCP), addressing IAM misconfigurations, and providing specific remediation guidance.Strong web application testing abilities, focusing on various vulnerabilities and modern application architectures.Knowledgeable in Active Directory and Azure AD attack paths, with the ability to simulate enterprise attack scenarios effectively.Experience in social engineering tactics, including developing phishing payloads aligned with legal standards.Ability to automate testing and proof-of-concept development using scripting languages such as Python and PowerShell.Capable of producing clear and comprehensive exploit proofs-of-concept and technical reports.Experience collaborating on red / purple team initiatives and translating findings into actionable recommendations.Familiarity with vulnerability management workflows and responsible disclosure practices.Proficient in productivity tools like Word, Excel, and PowerPoint for documentation and reporting.Additional Requirements
Bachelor's Degree in a related field or equivalent work experience is required.5-7 years of hands-on penetration testing / red team experience, especially with mid-to-large enterprises.Willingness to travel for client engagements and events as necessary.Advanced industry certifications such as OSCP, OSWE, or CISSP are preferred.Strong understanding of legal and ethical standards, including client data handling practices.The estimated annual pay range for this position is $165,000 - $205,000, which includes a base salary and bonus. Compensation is based on job-related knowledge, skills, experience, and market location. Benefits may include medical, vision, dental, 401K, and flexible spending accounts.
We are an equal opportunity employer and encourage applications from all individuals regardless of gender, disability status, or veteran status.