Lead Red Team Specialist (India)

Lead Red Team Specialist (India)

31 Jul
|
StickmanCyber
|
India

31 Jul

StickmanCyber

India

About the Role:

This is an elite, hands-on role at a boutique offensive security firm. You will serve as our Lead Red Teamer while acting as a senior technical authority on full-spectrum penetration testing engagements. We do not do "checkbox" audits or rely on automated scanners. We expect you to understand how modern defences work under the hood, write your own tooling when public exploits fail, manually audit source code, and dissect compiled binaries.

Responsibilities:

Red Teaming & Adversary Simulation

- Operational Leadership: Scope, plan, and execute multi-stage adversary simulations targeting enterprise networks. Model tactics, techniques, and procedures (TTPs) against the MITRE ATT&CK; framework.
- Infrastructure Design: Architect and deploy secure redirector networks, Domain Fronting setups, and multi-tiered Command-and-Control (C2) operational infrastructures.
- Bespoke Tooling: Design and compile custom loaders, obfuscated payloads, and post-exploitation tools in C, C++, Rust, or Go.
- Defence Evasion: Build reliable bypasses for agile memory scanning (e.g., Sleep Obfuscation), Endpoint Detection and Response (EDR) agents, Antimalware Scan Interface (AMSI), and network traffic heuristic engines.

Full-Spectrum Penetration Testing

- Active Directory & Infrastructure: Execute internal and external network assessments. You must know how to pivot through complex Active Directory forests using manual techniques (e.g., Kerberoasting, NTLM relaying, constrained delegation, and ACL exploitation).
- Web, API, and Mobile Apps: Manually audit modern web applications, REST/GraphQL APIs, and mobile apps (iOS/Android).
- Mobile Evasion: Decompile APK/IPA packages, bypass SSL pinning (using tools like Frida), and bypass jailbreak/root detection mechanisms.
- Desktop & Thick-Client Apps: Reverse-engineer and assess compiled desktop applications (C#/.NET, native C/C++,



Electron) to find local privilege escalation, memory corruption, or insecure Inter-Process Communication (IPC).
- Cloud Environments: Assess AWS, Azure, and GCP environments, focusing on IAM misconfigurations, credential exposure, and lateral movement between cloud and hybrid-cloud resources.

Code Review & Reverse Engineering

- Manual Secure Code Review: Conduct line-by-line secure code audits of raw repositories (Next.js, Node.js, Java, Python, PHP, and Golang) to identify structural vulnerabilities and logical business flaws.
- Static/Dynamic RE: Dissect closed-source binaries to trace undocumented functionality, unpack obfuscated code, or identify memory corruption vulnerabilities.

Reporting & Validation

- Write technically rigorous, markdown-based reports. Every finding must have a reproducible, step-by-step proof of concept (PoC) and realistic mitigation advice.
- Present findings clearly and professionally to client-side developers and security teams.

Technical Requirements:

- Real Experience: 6+ years of active professional experience in penetration testing and red teaming, preferably within a specialized boutique cybersecurity agency.
- Systems Knowledge: Strong familiarity with Windows and Linux operating system internals (e.g., memory management, PE/ELF structures, user-land API hooking, and direct/indirect syscalls).
- Programming Languages: Strong scripting capability (Python, Bash, PowerShell) and the ability to read and write compiled code (C, C++, Rust, or Go).
- Standard Tools: Expert-level proficiency with disassemblers/debuggers (Ghidra, IDA Pro, x64dbg, or GDB) and manual proxy interceptors (Burp Suite Professional).
- Credentials: Hands-on certifications such as OSCP/OSCP+, OSEP, OSCE, SANS GXPN, or SANS SEC535 are valued. However, we prioritize your public projects, GitHub tools, CVEs, or bug bounty portfolio over paper credentials.

📌 Lead Red Team Specialist (India)
🏢 StickmanCyber
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead red team specialist (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: lead red team specialist (india) / india