At @Mitigata , you'll join the offensive security team that keeps client environments honest — leading the toughest pen-test engagements, scoping recent work, owning the methodology, and mentoring the engineers coming up behind you.
About the role:
You'll lead complex engagements across cloud, web, API, mobile, thick-client and internal network testing; run advanced work like privilege escalation, lateral movement and cloud attack paths; be the client's technical anchor through debriefs and remediation; and keep the team's standards, checklists and reporting sharp.
What we're looking for:
? 5+ years hands-on offensive security with a strong VAPT track record
? Deep manual expertise across web, API,
network + at least one of cloud, mobile or thick-client
? Practical cloud pen-testing in AWS or Azure
? Proven ability to scope engagements & estimate effort accurately
? Experience mentoring/leading testers and reviewing their work
? Strong client presence — can run a debrief and handle pushback
Nice to have:
? OSCP / OSCE / OSWE / CRTP / CRTO or comparable
? Red team / adversary emulation experience
? Source-code review or DevSecOps exposure
? Published CVEs, talks, tooling or a research profile