Offensive Security Specialist

Deep SeasSan Diego, CA
Remote

About The Position

The Offensive Security Specialist is a practicing penetration tester who independently executes client engagements across DeepSeas' core service lines. This role represents the transition from emerging practitioner to confident, self-sufficient contributor. Specialists own their engagements end-to-end within defined scope, produce client-ready deliverables without heavy oversight, and are developing the depth and breadth needed to tackle increasingly complex environments. This is the primary delivery role on the team and the foundation of the practice's capacity.

Requirements

  • 1–3 years of professional penetration testing or applied offensive security experience; strong candidates with equivalent demonstrated skills will be considered.
  • Proficiency with standard toolsets: Nmap, Metasploit, Burp Suite, Nessus/OpenVAS, BloodHound, or equivalents.
  • Solid understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, AD, VPNs) and common vulnerability classes.
  • Familiarity with at least one scripting language (Python, Bash, or PowerShell) for basic automation and tooling.
  • Exposure to cloud platforms (AWS, Azure, or GCP) and awareness of common cloud misconfiguration patterns.
  • Strong written communication with the ability to produce accurate, professional-quality findings documentation.

Nice To Haves

  • Hands-on penetration testing certification preferred. Examples include PNPT (TCM Security), OSCP (Offensive Security), CompTIA PenTest+, or eWPT/eJPT with demonstrated experience

Responsibilities

  • Conduct internal and external network penetration tests including enumeration, exploitation, lateral movement, and post-exploitation within defined scope
  • Perform web application assessments aligned to OWASP Top 10 and API security testing standards
  • Conduct basic cloud security assessments (AWS, Azure, GCP) including misconfiguration identification, IAM review, and exposed services enumeration
  • Support AI/LLM security assessments including prompt injection, model abuse scenarios, and OWASP LLM Top 10 coverage under senior guidance
  • Produce complete, client-ready findings reports with clear technical narratives, reproduction steps, risk ratings, and remediation guidance
  • Participate in client kick-off calls and debrief walkthroughs, communicating findings professionally to technical and non-technical stakeholders
  • Maintain accurate engagement documentation, time tracking, and artifact organization in project management systems
  • Pursue continuous development through assigned training, lab environments, and certification advancement
  • May be required to travel up to 50% of the time.
  • Must be a US Citizen.

Benefits

  • Opportunities for growth
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service