Sporty Group

Offensive Security Engineer

Europe full-time Mid Salary not listed
full-time Mid level Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

About the role
Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations. This role works closely with IT, Network Engineering, SOC, and Security teams to convert external discovery, adversary emulation on EDR/XDR systems, and exploitation insights into tuned perimeter controls, firewall rules, and robust defensive guardrails.
What you'll be doing

Monitor, map, and test Sporty’s entire external attack surface, including all Sporty Group external domains, subdomains, websites, and public IP addresses.

Conduct adversary emulation exercises against internal and office endpoints to validate the effectiveness of EDR, XDR, and SOC monitoring platforms.

Evaluate the security posture of physical office hardware, corporate network equipment, and internal edge infrastructure.

Perform scoped offensive testing on external-facing web applications and limited, public-facing API endpoints.

Translate external discovery, DNS security posture, network access control weaknesses, and EDR emulation findings into repeatable defensive checks.

Support our Purple Team validate that EDR policies, perimeter controls, firewall rules, and network segmentation work as expected.

Document multi-stage network or system exploitation chains to provide practical, reproducible remediation blueprints for infrastructure and SOC teams.

Support IT and Network analysts with clear vulnerability descriptions, triage steps, severity logic, and escalation guidance.

Improve external asset tracking, perimeter health records, and exposure trend mapping.

Track external vulnerability gaps, emulation success rates, remediation times, asset health, and perimeter exposure.

What you'll bring

Experience in offensive security, perimeter penetration testing, network security assessments, or adversary emulation.

Strong understanding of external asset discovery, DNS configuration vulnerabilities, and public IP network routing.

Practical experience auditing and testing Linux and Windows environments and underlying network services.

Ability to perform adversary emulation and bypass techniques against modern EDR/XDR solutions.

Familiarity with testing physical office network hardware, routers, switches, firewalls, and workplace IT systems.

Ability to turn external exposures and technical network risks into clear, actionable fixes for IT and Security teams.

Experience with core web vulnerabilities and limited, scoped testing of modern API interfaces.

Strong scripting ability in Python, PowerShell, Bash, or similar to automate perimeter mapping, emulation workflows, and asset discovery.

Good understanding of scanning, reconnaissance, and interception tools.

Strong documentation skills.

Technology Expertise Any of the following: Kali Linux toolset, Nmap, Shodan, Censys, Masscan, Amass, Dig/DNS testing tools, Wireshark, Burp Suite, OWASP ZAP, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Atomic Red Team, Caldera, Python, PowerShell, Bash, VPS environments (Linux/Windows Server OS), Firewalls, Routers, Git, Jira, Confluence
What's in it for you

Sporty is a remote-first company in pursuit of sustainability

A competitive salary plus individual performance-based bonuses every quarter

28 days paid annual leave

Core working hours of 10am-3pm in your local time zone, with flexibility outside of these hours

Referral bonuses and flash bonuses

Top-of-the-line equipment

Annual company retreats that provide opportunities to connect and collaborate with colleagues from around the world

Interview Process:

Remote video screening with our Talent Acquisition Team

Online assessment via Hackerrank

Remote video interview with Team Members (60 Mins)

Final discussion with the hiring manager (60 mins)

If you're interested, we encourage you to apply. Every application is reviewed by a member of our team, and we aim to respond within 48 hours.

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Mid
Technology & IT API integration Human Resources Python Remote Collaboration Writing Mid level

Likely questions

  1. Tell us about work you have done that is close to the Offensive Security Engineer role.
  2. How would you approach your first 30 days at Sporty Group?
  3. Which of API integration, Human Resources and Python have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you handle busy days, changing priorities, or pressure at work?

Prepare before the call

  • A recent example that proves your experience with API integration, Human Resources and Python.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Offensive Security Engineer role because I can bring practical experience in API integration, Human Resources and Python, learn the team quickly, and contribute to the outcomes Sporty Group needs from this hire.

Related jobs.

More roles from this company or category.