← Takaisin työpaikkoihin

Senior Vulnerable Machine Engineer

  • Etätyö
  • Ruotsi
  • Englanti
  • Julkaistu 10.09.26 15:58

About OffSecFounded in 2006 by the creators of Kali Linux, OffSec (formerly known as Offensive Security) is the leading provider of continuous professional and workforce development, training, and education for cybersecurity practitioners.OffSec’s distinct pedagogy and practical, hands-on learning help organizations fill the infosec talent gap by training their teams on today’s most critical skills. Become a part of our global presence and work from anywhere. With team members in over 40 countries, we believe in inspiring people of all backgrounds and communities. The OffSec team is composed of diverse, internationally published authors, conference speakers, and seasoned information technology professionals from both the private sector and governments worldwide. Excited about our mission and what we do? Apply and join us! About The JobHave you earned your OSCP, OSEP/OSED/OSWE, and gained offensive experience before and/or since then? Are you excited at the opportunity to contribute to the growth and education for the current and next generation of cybersecurity professionals?If the idea of building lab environments, to provide hands-on experience for individuals to learn and upskill, then this might be the right role for you! Duties And ResponsibilitiesContent design and buildResearches and identifies topical, relevant attack vectors suitable for inclusion in OffSec labs, exams, and/or learning contentDesign and build VMs and multi-host environments from vectors across Linux and Windows, including Active Directory and Cloud attack pathsDesigns realistic scenarios and environment narratives that make each attack path plausible and discoverable through enumerationEnsures the range of vectors in each environment is appropriate to its stated difficulty level and learning objectivesMaintains variety across the catalogue so that content remains distinct as it rotates through active useQuality, integrity, and reproducibilityReview labs for unintended solution paths and confirms each is solvable by the intended route within its expected time frameValidates that machines are deterministic and reproducible in an isolated environment, including reliable reset and revert behaviourDeliberate selection and use of software and OS versions, monitoring deployed components so that content behaves consistently over its lifetimeDocuments the steps required to complete each machine, with difficulty assessed at a level of detail that supports competency mapping and certification reviewCollaborationCoordinates with the relevant team(s) to deploy, update, and retire contentCoordinates with testing to ensure full coverage of both newly created and updated contentCoordinates with the Lab team Manager and Content Architect on vector selection and exploit implementation within courses and learning pathsCoordinates and make recommendations to keep content additions consistent across productsRegularly communicates content additions, changes, and retirements to relevant stakeholdersSenior scopeActs as a technical reviewer for lab concepts and builds produced by other Vulnerable Machine Engineers and community contributors, providing structured, actionable feedbackSupport and mentor other engineers on build standards, documentation quality, and content review practiceContributes across OffSec's lab and exam portfolio as priorities require, rather than to a single productAutomation and toolingCreates and maintains automation that makes lab creation timely, consistent, and repeatableEvaluates new and emerging technologies to make recommendations on their introduction into the lab estateCreate and maintain documentation for every lab, to a standard that allows any team member to rebuild it from the documentation alone, without assistance QualificationsOSCP minimum, OSCE³ preferred (or at least one OffSec 300-level cert required)A Bachelor’s Degree in Systems Engineering, Computer Science, Information Systems, and / or Information Assurance from an accredited institution/related specialized field, or equivalent practical experience.Demonstrable Active Directory and Cloud attack-path experience.Proficiency with infrastructure-as-code and configuration management and version controlScripting proficiency (Python, PowerShell, Bash).At least five or more years of experience as a Systems Engineer or in a Info-Sec related position (examples), with experience reviewing or approving others' technical security content:Experience with Penetration TestingExperience with Bug Bounty HuntingExperience as a Systems Administrator with a variety of Operating Systems:MS WindowsMS Windows Based Server SystemsPOSIX Server SystemsLinux and Mac Desktop EnvironmentsStrong written and verbal communication skills with an ability to present technical ideas clearly to both technical and non-technical audiences Work Location and HoursThis role is a full-time salaried position. It is a fully remote position. Work hours for this position are flexible and will be performed from a home office. Direct ReportsThis position has no direct reports. However, the expectations of this role are to provide technical leadership. EEOOffSec provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.