N
Necurity Solutions•2h ago
Indeed
Offensive Security Analyst
Chennai, Tamil Nadu
Full Time
Mid Level
25000-32000
Full Job Description
**Offensive Security Analyst – Network/Web/OT Specialization**
**About the Role**
Necurity Solutions is seeking a skilled Offensive Security Analyst to join our team of genuine hackers. You will perform advanced security assessments by simulating real adversary behavior, focusing on manual exploitation, vulnerability chaining, and lateral movement across networks, web applications, and OT/ICS environments. This role demands a deep understanding of attack methodologies, including enumeration, privilege escalation, and credential-based pivoting. Your work will span enterprise and critical environments, requiring a mindset that goes beyond compliance checks to deliver impactful, evidence-backed findings.
**Key Responsibilities**
- Conduct thorough network, web application, and OT/ICS penetration tests with a focus on manual exploitation over automated tooling.
- Assess Active Directory environments for vulnerabilities like kerberoasting, delegation abuse, and ADCS/certificate attacks.
- Develop realistic attack narratives from initial footholds to domain compromise, demonstrating end-to-end exploitation.
- Test web and API targets against OWASP Top 10, identifying flaws automated scanners miss and validating exploitability.
- Evaluate OT/ICS systems with careful risk-aware testing, respecting production and safety constraints.
- Write clear, actionable reports with reproducible exploitation steps and remediation guidance.
- Present findings to technical and non-technical stakeholders, including leadership.
- Travel to client sites for on-premise assessments as required.
- Assess Active Directory environments for vulnerabilities like kerberoasting, delegation abuse, and ADCS/certificate attacks.
- Develop realistic attack narratives from initial footholds to domain compromise, demonstrating end-to-end exploitation.
- Test web and API targets against OWASP Top 10, identifying flaws automated scanners miss and validating exploitability.
- Evaluate OT/ICS systems with careful risk-aware testing, respecting production and safety constraints.
- Write clear, actionable reports with reproducible exploitation steps and remediation guidance.
- Present findings to technical and non-technical stakeholders, including leadership.
- Travel to client sites for on-premise assessments as required.
**Requirements**
**Must-Have:**
- 2–5 years of hands-on offensive security experience (penetration testing, red teaming).
- Demonstrated hacker mindset through CTF participation, bug bounty findings, or security-focused competitions.
- At least one security certification (e.g., CEH, eJPT, OSCP, OSWE).
- Strong manual testing skills to identify vulnerabilities automated tools miss.
- Proficiency in networking fundamentals, web technologies, OS, and vulnerability classes.
- Responsible handling of sensitive/production environments.
- Willingness to travel for audits.
- Excellent written and verbal communication skills.
**Nice-to-Have:**
- OT/ICS or SCADA security experience.
- Advanced certifications (e.g., OSCP, GICSP, GXPN).
- Public CTF profiles, bug bounty rankings, or original research.
- Scripting/automation skills (Python, Bash, PowerShell).
- Cloud security assessment experience (AWS/Azure/GCP).
- Community engagement (talks, open-source contributions).
- 2–5 years of hands-on offensive security experience (penetration testing, red teaming).
- Demonstrated hacker mindset through CTF participation, bug bounty findings, or security-focused competitions.
- At least one security certification (e.g., CEH, eJPT, OSCP, OSWE).
- Strong manual testing skills to identify vulnerabilities automated tools miss.
- Proficiency in networking fundamentals, web technologies, OS, and vulnerability classes.
- Responsible handling of sensitive/production environments.
- Willingness to travel for audits.
- Excellent written and verbal communication skills.
**Nice-to-Have:**
- OT/ICS or SCADA security experience.
- Advanced certifications (e.g., OSCP, GICSP, GXPN).
- Public CTF profiles, bug bounty rankings, or original research.
- Scripting/automation skills (Python, Bash, PowerShell).
- Cloud security assessment experience (AWS/Azure/GCP).
- Community engagement (talks, open-source contributions).
Company
N
Necurity Solutions
Necurity Solutions specializes in cutting-edge offensive security services, focusing on real-world adversary simulation to identify and mitigate critical vulnerabilities in enterprise and industrial s...
Chennai, Tamil Nadu
Posted on Indeed