OmDev Logo
GetYourJob
0
Publié il y a 208 jours

Offensive Technical Leader - Freelance

Entreprise
Localisation
Lille, France
Hybride
Type de contrat
Freelance
Niveau
Senior
Rémunération
650ۥ Taux journalier

Salaire du marché

Médiane du marché
500€/j
Au-dessus du marché
460€/jfourchette habituelle575€/j
Cette offre : 650€/j

Basé sur 37 offres pour ce poste (Senior, France, 3 dernières semaines). Fourchette habituelle 460€/j–575€/j, médiane 500€/j. Cette offre (650€/j) est au-dessus de la fourchette.

0vues
0clics

Description du poste

Daily rate: 650

Offensive Technical Leader - Red Team & Purple Team


Contexte de la mission

Lille

We are seeking an experienced Offensive Technical Leader to serve as the architect and lead practitioner for our Red Team and Purple Team service offerings. This is a strategic consultancy role designed for an expert who can not only execute sophisticated adversary simulations but also support the build of the operational framework, methodology, and short/middle-term strategy for these services with the Decathlon team.

The candidate will act as the "Player-Coach" driving high-end engagements while mentoring our team to elevate their technical capabilities.

The candidate will also be technical support to the other offensive service (if needed) and will have to work closely with our Offensive Lead Governance engineer on that part.

Objectifs et livrables


A. Strategy & Service Architecture

  • Methodology Development: Contribute to the design and document a standardized Red/Purple Team framework based on MITRE ATT&CK and TIBER-EU standards.

  • Service Roadmap: Contribute to the definition of the creation and/or evolution of offensive services (e.g., Breach & Attack Simulation integration, Cloud-native red teaming,....) in order to be aligned with the Decathlon context and maturity evolution.

  • Tooling Strategy: Contribute to the evaluation, strategy building and finally implementation of the "Offensive Stack," including C2 frameworks (Empire, Cobalt Strike, Havoc, Sliver), custom payload development pipelines, and infrastructure automation (Terraform/Ansible).


B. Technical Leadership & Execution

  • Lead Red Team Operations: Act as the lead operator for external and internal adversary simulations.

  • Purple Team Orchestration: Facilitate collaborative workshops between offensive (Red) and defensive (Blue/SOC) teams to identify detection gaps and improve Time-to-Detect (TTD) and Time-to-Remediate (TTR).

  • Multi-Cloud Adversary Simulation: Execute campaigns that target the "seams" between cloud providers (e.g., abusing cross-tenant trust or federated identities).

  • Evasion & Research: Stay ahead of EDR/XDR capabilities by researching and developing custom bypasses, obfuscation techniques, and "living off the land" (LotL) tactics. Oversee the development of custom C2 infrastructure that utilizes legitimate cloud services (e.g., AWS Lambda,...) as redirectors to blend in with enterprise traffic.


C. Mentorship & Support

  • Pentester Escalation Point: Serve as the "Level 3" technical support for penetration testing team and/or Lead Governance engineer.

  • Skill Uplift: Conduct internal "Deep Dive" sessions on advanced topics (e.g., Cloud offensive, CI/CD pipeline attacks, AI offensive…) aligned with the needs and strategy acted for Decathlon.

Compétences techniques requises

-


Adversary Simulation: Proven experience mimicking APT actors, including long-haul persistence, lateral movement, and data exfiltration.


Infrastructure Mastery: IAM, Active Directory and at least one or two of these topics (SAP, IoT, Mobile, Container (Docker, Kubernetes, etc)).


Cloud Mastery: Deep knowledge attacking AWS and/or GCP environments (GCP Service Accounts, Kubernetes, serverless infrastructure, …).


Development Skills: Ability to write, modify and maintain code in Python, Go, Rust, C#, or C++ for custom tool development and exploit modification.


Defensive Understanding: Strong familiarity with SIEM (Splunk, ....), EDR, and how to bypass their telemetry.


AI Offensive: Good knowledge in Adversarial Machine Learning, prompt engineering for jailbreaking, and understanding LLM context-window exploitation.

Soft Skills & Consulting

-


Executive Communication: Ability to translate a technical complex context (i.e. AD compromission) into a business risk narrative for C-suite stakeholders.


Calm Under Pressure: Experience managing the "White Cell" and deconfliction processes during high-stakes engagements.


Analytical Writing: Delivery of high-quality, actionable reports that provide value to both technical stakeholders and CISOs.


Project Management: Plan and deliver a project animated over time.


English (Technical): Written & Spoken.

Qualifications préférées

-


Certifications: OSEP, OSWE, OSCP, CRTO, GRTP, SANS training (purple, threat hunting, Cyber threat intelligence…).


Community Contribution: History of published research, CVEs, open-source offensive tools, or speaking engagements (BlackHat, DEF CON, LeHACK, etc.).


Experience: 8+ years in offensive security, with at least 2 years in a leadership or lead architect capacity.

Compétences demandées

Compétence Niveau de compétence Programmation Python Confirmé GCP Expert Active Directory Expert AWS Confirmé Gestion des identités et des accès (IAM) Expert Docker Confirmé C# Rust Confirmé

Langues

Langue Niveau Anglais Courant

Exigences du poste

Stack technique :

AWSPythonGoogle Cloud PlatformRed TeamingPurple TeamingMITRE ATT&CKIAMActive Directory

Plan d'action

Un plan personnalisé pour postuler intelligemment à cette offre.

À propos de l'entreprise

Voir toutes les offres de Salutech

Publié par

Recruteur
Recruteur

Intéressé par cette offre ?

Cliquez sur "Postuler" pour accéder à l'offre.