Technical Skills
- 3+ years of hands-on penetration testing / offensive security experience
- Strong understanding of:
oWeb vulnerabilities (OWASP Top 10, API security issues)
oInternal network and infrastructure attack techniques
oActive Directory exploitation (Kerberoasting, delegation abuse, ACL misconfigurations, NTLM relay)
oPrivilege escalation on Windows and Linux
- Experience using core offensive tools:
oBurp Suite, Nmap, Metasploit
oBloodHound, CrackMapExec, Impacket
- Solid understanding of foundational concepts:
oTCP/IP, DNS, HTTP(S)
oAuthentication (Kerberos, NTLM, OAuth2, SSO)
oLinux & Windows environments
oBash, PowerShell, and basic Python scripting
- Strong reporting skills (technical clarity + business impact)
Soft Skills
- Excellent verbal and written communication skills
- Ability to explain risks to both technical and non-technical stakeholders
- Self-driven, curious, and proactive
- Effective time management across multiple engagements
- Professional client-facing demeanor