Preferred Certifications:
OSCP, OSEP, OSWE, GPEN, GXPN, GWAPT, CEH or equivalent offensive-security certifications.
Required Experience:
Minimum 3+ years of hands-on penetration testing/offensive security experience; ideally 5+ years Enterprise internal and external penetration testing Red Team / adversary simulation Active Directory and Entra ID security testing Azure and Microsoft 365 security assessments Network, web application and API penetration testing VPN, SSO/MFA and remote-access security testing Privilege escalation and lateral movement Vulnerability validation, exploitation and post-exploitation Experience following NIST SP 800-115, MITRE ATT&CK and OWASP methodologies Strong technical reporting, remediation recommendations and client presentation skills