- Conduct comprehensive penetration tests across web applications, APIs, cloud environments, mobile applications, and internal infrastructure.
- Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors, including initial access, lateral movement, persistence, and data exfiltration.
- Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams.
- Partner with detection engineering, threat intelligence, and incident response teams to validate security controls and identify coverage gaps.
- Contribute adversary tradecraft insights to inform detection rule development and incident response playbooks.
- Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency.
- Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to stakeholders.