Summary
District Tech Group Incorporated is seeking an Offensive Security & Code Analysis Engineer to help clients strengthen their defenses by identifying vulnerabilities. This role involves conducting penetration testing, code reviews, and security assessments while combining hands-on technical testing with strategic security consulting.
Responsibilities
- Conduct penetration testing of web applications, networks, and cloud environments
- Perform source code security reviews and static/dynamic analysis
- Identify and exploit vulnerabilities in client applications and infrastructure
- Develop detailed reports with findings, risk ratings, and remediation guidance
- Create proof-of-concept exploits and demonstrations
- Research emerging attack techniques and develop new testing methodologies
- Collaborate with development teams on secure coding practices
- Present findings to technical and executive audiences
- Contribute to red team engagements and adversary simulations
Skills
- 3+ years of experience in penetration testing or offensive security
- Strong knowledge of web application vulnerabilities (OWASP Top 10)
- Experience with penetration testing tools (Burp Suite, Metasploit, Nmap, etc.)
- Proficiency in at least one programming language (Python, JavaScript, C/C++)
- Understanding of secure coding practices and common code vulnerabilities
- Knowledge of network protocols, Active Directory, and cloud environments
- Excellent report writing and communication skills
- Strong analytical and creative problem-solving abilities
- Offensive security certifications (OSCP, OSWE, GPEN, or equivalent)
- Bug bounty experience or CVE publications
- Experience with mobile application security testing
- Cloud security testing experience (AWS, Azure, GCP)
- Familiarity with DevSecOps and CI/CD security integration
- Reverse engineering or malware analysis experience
Qualifications
Must Haves
- 3+ years of experience in penetration testing or offensive security
- Strong knowledge of web application vulnerabilities (OWASP Top 10)
- Experience with penetration testing tools (Burp Suite, Metasploit, Nmap, etc.)
- Proficiency in at least one programming language (Python, JavaScript, C/C++)
- Understanding of secure coding practices and common code vulnerabilities
- Knowledge of network protocols, Active Directory, and cloud environments
- Excellent report writing and communication skills
- Strong analytical and creative problem-solving abilities
Nice to Haves
- Offensive security certifications (OSCP, OSWE, GPEN, or equivalent)
- Bug bounty experience or CVE publications
- Experience with mobile application security testing
- Cloud security testing experience (AWS, Azure, GCP)
- Familiarity with DevSecOps and CI/CD security integration
- Reverse engineering or malware analysis experience
Benefits
- Fully remote work environment
- Health, dental, and vision insurance
- Professional development and certification support
- Access to the latest security tools and training
- Opportunity to work on diverse and challenging engagements
- Flexible scheduling options
- Performance bonuses