Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Grant Thornton

Cyber Offensive Security Senior Associate

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
75
out of 100
Average of individual scores

Were these scores useful?

Job Description

As a Senior Offensive Security Consultant on our Cyber Defense team, you will get the opportunity to lead adversarial testing engagements for clients across a range of industries. In this role, you will simulate real-world adversaries to identify exploitable weaknesses, validate detection and response capabilities, and help clients measurably strengthen their security posture. This is a hands-on technical role with significant client interaction and ideal for someone who thrives on solving complex problems and communicating impact to both technical teams and executive stakeholders. From day one, you'll be empowered by the greater Cyber & Risk team to help clients make the moves that will help them achieve their vision and help you achieve more, confidently.
Your day-to-day may include:
Penetration Testing:
Plan and execute network, application, API, and cloud penetration tests, from scoping through exploitation, post-exploitation, and reporting.
Adversary Emulations:
Design and run, threat-informed attack simulations to validate the effectiveness of client security controls and detection coverage.
Assume-Breach:
Conduct assume-breach engagements, collaborating with defensive teams to test detection, response, and containment capabilities.
AI Red Teaming:
Perform adversarial testing of AI/ML systems and LLM-enabled applications, including prompt injection, model manipulation, data exfiltration, and abuse-case testing.
Threat Emulation:
Emulate the tactics, techniques, and procedures (TTPs) of relevant threat actors, mapping activity to frameworks such as
MITRE ATT&CK.
Reporting & Communication:
Produce clear, high-quality deliverables that translate technical findings into prioritized, business-relevant remediation guidance; present results to technical staff, management, and executive/board audiences.
Client Advisory:
Serve as a trusted technical advisor, helping clients understand risk, prioritize remediation, and mature their security programs.
Practice Development:
Contribute to methodology development, tooling, automation, and the mentoring of junior team members. You have the following technical skills and qualifications: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field is required 3+ years of hands-on experience in offensive security, penetration testing, or red teaming. Demonstrated expertise across multiple domains (network, application, cloud, and/or internal infrastructure testing). Strong understanding of adversary TTPs and frameworks such as MITRE ATT&CK and ATLAS and OWASP. Proficiency with industry-standard tooling and command-and-control frameworks. Scripting and automation skills (e.g., Python, PowerShell, Bash). Experience conducting assume-breach or adversary emulation engagements. Excellent written and verbal communication skills, including the ability to produce professional, client-ready reports. Ability to work independently, manage multiple engagements, and meet deadlines in a client-service environment.
Preferred qualifications:
Relevant certifications such as OSCP, OSEP, OSWE, GPEN, GXPN, GWAPT or CREST. Prior consulting or professional-services experience. Cloud security testing experience across AWS, Azure, and/or GCP. Experience with AI/ML or LLM security testing and adversarial techniques. Familiarity with breach and attack simulation platforms. Experience testing the security of D365 and integrations a plus. Contributions to the security community (research, tooling, CVEs, conference talks, or publications). #hybrid #LI-LG1

Benefits

  • Dental Insurance