HimalayasHimalayas logo
PlexTracPL

Offensive Security Engineer (Red Team)

PlexTrac is a leading platform for automating penetration test reporting and vulnerability management, enabling security teams to streamline operations and enhance their cybersecurity effectiveness.

PlexTrac

Employee count: 51-200

India only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

About PlexTrac

PlexTrac is a cybersecurity SaaS platform helping security teams streamline reporting, exposure management, and remediation workflows. Our platform is used by penetration testers, red teams, consultants, enterprises, and managed security providers to operationalize security findings and improve collaboration across technical and executive stakeholders.

We are a remote-first company headquartered in the United States with distributed team members across North America, Europe, and Asia. We are committed to ownership, transparency, practical problem-solving, and building products that customers genuinely rely on.

Why This Role Matters

We build security software that helps companies protect their data. To make our product stronger, we are looking for Offensive Security Engineers (Red Team) who think like attackers. You will find weaknesses before the bad guys do, report what you find clearly, and work with our engineering team to fix it. This is a hands-on role with real influence on how we build and ship securely.

Location: Remote — India only.

Responsibilities

  • Plan and execute red team engagements across our cloud infrastructure (AWS/GCP/Azure), internal networks, web applications, and SaaS product
  • Simulate realistic attack chains — from initial access through lateral movement, credential harvesting, privilege escalation and data exfiltration — using current threat actor techniques
  • Conduct assumed breach scenarios, purple team exercises, and objective-based engagements, not just point-in-time pen tests
  • Assess cloud-specific attack surfaces: IAM roles and policies, storage misconfigurations, serverless functions, container workloads, and CI/CD pipelines
  • Test Active Directory and hybrid identity environments for common and advanced attack paths
  • Perform web and API application testing against our core product, including authentication flaws, authorization bypasses, and business logic vulnerabilities
  • Build, customize, and maintain offensive tools, scripts, and C2 infrastructure to support engagements
  • Develop and manage red team infrastructure — attack servers, redirectors, phishing platforms, and operational security controls
  • Create and maintain repeatable testing methodologies and internal playbooks the team can use and build on
  • Evaluate and improve detection coverage by working closely with our blue team — identify what's being caught, what isn't, and why
  • Write detailed reports that document attack paths, evidence, business impact, and remediation steps — clearly enough that an engineer can act on them without follow-up questions
  • Present findings to both technical teams and non-technical stakeholders, including leadership
  • Track remediation progress and validate that fixes actually close the identified gaps — not just check a box
  • Help define the scope, methodology, and maturity of our red team program as we scale
  • Contribute to internal security standards, threat models, and secure design reviews
  • Mentor junior team members and support knowledge sharing across the security org

Qualifications

  • 4+ years of hands-on experience in offensive security, penetration testing, or a red team role
  • Demonstrated ability to attack and assess cloud environments — AWS, GCP, and Azure — including IAM abuse, privilege escalation, and misconfiguration exploitation
  • Hands-on experience with container and Kubernetes security (EKS, GKE, AKS)
  • Experience testing hosted and on-prem infrastructure: servers, VPNs, Active Directory, and internal networks
  • Working knowledge of web application attack techniques (OWASP Top 10 and beyond)
  • Familiarity with MITRE ATT&CK and how to map findings to real-world threat behavior
  • Experience writing clear, well-organized findings reports for both technical and non-technical readers
  • Ability to explain technical risk to people who are not security experts
  • Comfort working independently and managing your own workload

Nice to Have

  • Experience testing SaaS products or multi-tenant cloud architectures
  • Scripting or coding ability in Python, Bash, or PowerShell
  • Familiarity with C2 frameworks such as Cobalt Strike, Brute Ratel, or Sliver
  • Experience with phishing simulations and social engineering engagements
  • Certifications such as OSCP, CRTO, CRTE, CPTS, or equivalent hands-on credentials

Tech Stack

Cloud and hosted environments, modern SaaS infrastructure, enterprise security controls, and offensive security tools for vulnerability testing and threat simulation.

Work Style

We operate as a remote-first, distributed team with a strong asynchronous culture. We value thoughtful communication, autonomy, and collaboration, with core working hours that partially overlap with U.S. Eastern Time.

Employees are administered through our EOR partner: Remote.

We’re committed to building an inclusive workplace where people from all backgrounds can thrive. We welcome applicants regardless of race, ethnicity, religion, gender identity, sexual orientation, age, disability, or background.

If you require accommodations during the interview process, please let us know: HR@plextrac.com

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Education

Bachelor degree

Experience

4 years minimum

Experience accepted in place of education

Location requirements

Hiring timezones

India +/- 0 hours

About PlexTrac

Learn more about PlexTrac and their company culture.

View company profile

PlexTrac is the market-leading pentest reporting and management automation platform, ideal for both enterprise security teams and Managed Security Service Providers (MSSPs). It is designed to improve and centralize cybersecurity teams' capabilities by providing innovative solutions that streamline critical security workflows. The platform aggregates data from a myriad of security tools, enabling organizations to effectively triage data, prioritize the most critical vulnerabilities, and manage risks more efficiently. By automating reporting with advanced AI technologies, PlexTrac stands out as a valuable tool in the cybersecurity landscape.

Founded in 2016 and headquartered in Boise, Idaho, PlexTrac aims to enhance organizations' security postures and improve collaboration among security teams. The platform supports continuous threat exposure management (CTEM) through an industry-first contextual scoring engine. This approach helps organizations not only gather insights from pentests and vulnerability assessments but also facilitates ongoing validation of their security measures. In an era where cyber threats continuously evolve, PlexTrac plays a crucial role in empowering teams to stay ahead of attackers, drive efficiencies across their security processes, and maintain a resilient security posture.

Claim this profilePlexTrac logoPL

PlexTrac

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

4 remote jobs at PlexTrac

Explore the variety of open remote roles at PlexTrac, offering flexible work options across multiple disciplines and skill levels.

View all jobs at PlexTrac

Remote companies like PlexTrac

Find your next opportunity by exploring profiles of companies that are similar to PlexTrac. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan