Vulnerable Machine Engineer
About OffSec Founded in 2006 by the creators of Kali Linux, OffSec (formerly known as Offensive Security) is the leading provider of continuous professional and workforce development, training, and education for cybersecurity practitioners. OffSec’s distinct pedagogy and practical, hands-on learning help organizations fill the infosec talent gap by training their teams on today’s most critical skills. Become a part of our global presence and work from anywhere. With team members in over 40 countries, we believe in inspiring people of all backgrounds and communities. The OffSec team is composed of diverse, internationally published authors, conference speakers, and seasoned information technology professionals from both the private sector and governments worldwide. Excited about our mission and what we do? Apply and join us! About the Job Have you earned your OSCP, OSEP/OSED/OSWE, and gained offensive experience before and/or since then? Are you excited at the opportunity to contribute to the growth and education for the current and next generation of cybersecurity professionals? If the idea of building lab environments, to provide hands-on experience for individuals to learn and upskill, then this might be the right role for you! Duties and Responsibilities Content design and build Researches and identifies topical, relevant attack vectors suitable for inclusion in OffSec labs, exams, and/or learning content Design and build VMs and multi-host environments from vectors across Linux and Windows, including Active Directory and Cloud attack paths Designs realistic scenarios and environment narratives that make each attack path plausible and discoverable through enumeration Ensures the range of vectors in each environment is appropriate to its stated difficulty level and learning objectives Maintains variety across the catalogue so that content remains distinct as it rotates through active use Quality, integrity, and reproducibility Review labs for unintended solution paths and confirms each is solvable by the intended route within its expected time frame Validates that machines are deterministic and reproducible in an isolated environment, including reliable reset and revert behaviour Deliberate selection and use of software and OS versions, monitoring deployed components so that content behaves consistently over its lifetime Documents the steps required to complete each machine, with difficulty assessed at a level of detail that supports competency mapping and certification review Collaboration Coordinates with the relevant team(s) to deploy, update, and retire content Coordinates with testing to ensure full coverage of both newly created and updated content Coordinates with the Lab team Manager and Content Architect on vector selection and exploit implementation within courses and learning paths Coordinates and make recommendations to keep content additions consistent across products Regularly communicates content additions, changes, and retirements to relevant stakeholders Senior scope Acts as a technical reviewer for lab concepts and builds produced by other Vulnerable Machine Engineers and community contributors, providing structured, actionable feedback Support and mentor other engineers on build standards, documentation quality, and content review practice Contributes across OffSec's lab and exam portfolio as priorities require, rather than to a single product Automation and tooling Creates and maintains automation that makes lab creation timely, consistent, and repeatable Evaluates new and emerging technologies to make recommendations on their introduction into the lab estate Create and maintain documentation for every lab, to a standard that allows any team member to rebuild it from the documentation alone, without assistance Qualifications OSCP minimum, OSCE³ preferred (or at least one OffSec 300-level cert required) A Bachelor’s Degree in Systems Engineering, Computer Science, Information Systems, and / or Information Assurance from an accredited institution/related specialized field, or equivalent practical experience. Demonstrable Active Directory and Cloud attack-path experience. Proficiency with infrastructure-as-code and configuration management and version control Scripting proficiency (Python, PowerShell, Bash). At least five or more years of experience as a Systems Engineer or in a Info-Sec related position (examples), with experience reviewing or approving others' technical security content: Experience with Penetration Testing Experience with Bug Bounty Hunting Experience as a Systems Administrator with a variety of Operating Systems: MS Windows MS Windows Based Server Systems POSIX Server Systems Linux and Mac Desktop Environments Strong written and verbal communication skills with an ability to present technical ideas clearly to both technical and non-technical audiences Work Location and Hours This role is a full-time salaried position. It is a fully remote position. Work hours for this position are flexible and will be performed from a home office. Direct Reports This position has no direct reports. However, the expectations of this role are to provide technical leadership. EEO OffSec provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.