Grant Thornton

Cyber Offensive Security Senior Associate

Grant Thornton • $110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field
  • 3+ years of hands-on experience in offensive security or red teaming
  • Expertise in multiple domains: network, application, cloud, and internal infrastructure testing
  • Strong understanding of adversary TTPs and frameworks like MITRE ATT&CK
  • Proficiency with industry-standard tools and command-and-control frameworks
  • Scripting skills in languages such as Python, PowerShell, or Bash
  • Excellent written and verbal communication skills for client-ready report generation

Responsibilities

  • Plan and execute comprehensive penetration tests across various environments
  • Design and run threat-informed attack simulations for client security validation
  • Conduct assume-breach engagements, collaborating on detection and response testing
  • Perform adversarial testing on AI/ML systems and LLM-enabled applications
  • Emulate tactics and procedures of relevant threat actors, mapping to frameworks
  • Produce clear, prioritized, business-relevant remediation reports for clients
  • Serve as a trusted technical advisor to help clients enhance their security posture
  • Contribute to the development of methodologies, tools, and mentoring of junior team members

Benefits

  • Empowerment to drive client security improvements from day one
  • Opportunities for professional growth within a specialized team
  • Engagements across diverse industries providing varied challenges
  • Support for developing methodology and tools in a collaborative environment
  • Mentoring opportunities fostering team development and knowledge sharing
Full Job Description
Job Description

As a Senior Offensive Security Consultant on our Cyber Defense team, you will get the opportunity to lead adversarial testing engagements for clients across a range of industries. In this role, you will simulate real-world adversaries to identify exploitable weaknesses, validate detection and response capabilities, and help clients measurably strengthen their security posture. This is a hands-on technical role with significant client interaction and ideal for someone who thrives on solving complex problems and communicating impact to both technical teams and executive stakeholders.

From day one, you'll be empowered by the greater Cyber & Risk team to help clients make the moves that will help them achieve their vision and help you achieve more, confidently.

Your day-to-day may include:
  • Penetration Testing: Plan and execute network, application, API, and cloud penetration tests, from scoping through exploitation, post-exploitation, and reporting.
  • Adversary Emulations: Design and run, threat-informed attack simulations to validate the effectiveness of client security controls and detection coverage.
  • Assume-Breach: Conduct assume-breach engagements, collaborating with defensive teams to test detection, response, and containment capabilities.
  • AI Red Teaming: Perform adversarial testing of AI/ML systems and LLM-enabled applications, including prompt injection, model manipulation, data exfiltration, and abuse-case testing.
  • Threat Emulation: Emulate the tactics, techniques, and procedures (TTPs) of relevant threat actors, mapping activity to frameworks such as MITRE ATT&CK.
  • Reporting & Communication: Produce clear, high-quality deliverables that translate technical findings into prioritized, business-relevant remediation guidance; present results to technical staff, management, and executive/board audiences.
  • Client Advisory: Serve as a trusted technical advisor, helping clients understand risk, prioritize remediation, and mature their security programs.
  • Practice Development: Contribute to methodology development, tooling, automation, and the mentoring of junior team members.

You have the following technical skills and qualifications:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field is required
  • 3+ years of hands-on experience in offensive security, penetration testing, or red teaming.
  • Demonstrated expertise across multiple domains (network, application, cloud, and/or internal infrastructure testing).
  • Strong understanding of adversary TTPs and frameworks such as MITRE ATT&CK and ATLAS and OWASP.
  • Proficiency with industry-standard tooling and command-and-control frameworks.
  • Scripting and automation skills (e.g., Python, PowerShell, Bash).
  • Experience conducting assume-breach or adversary emulation engagements.
  • Excellent written and verbal communication skills, including the ability to produce professional, client-ready reports.
  • Ability to work independently, manage multiple engagements, and meet deadlines in a client-service environment.

Preferred qualifications:
  • Relevant certifications such as OSCP, OSEP, OSWE, GPEN, GXPN, GWAPT or CREST.
  • Prior consulting or professional-services experience.
  • Cloud security testing experience across AWS, Azure, and/or GCP.
  • Experience with AI/ML or LLM security testing and adversarial techniques.
  • Familiarity with breach and attack simulation platforms.
  • Experience testing the security of D365 and integrations a plus.
  • Contributions to the security community (research, tooling, CVEs, conference talks, or publications).

#hybrid

#LI-LG1

About Grant Thornton

Grant Thornton LLP is the American member firm of Grant Thornton International, the seventh largest accounting network in the world by combined fee income. Grant Thornton LLP is the sixth largest U.S. accounting and advisory organization. The firm operates 59 offices across the US with approximately 8,500 employees, 550 partners, and produces annual revenue in excess of US$1.9 billion. During the 2022 Russian Invasion of Ukraine, The Times reported that Grant Thornton is in line to earn millions of pounds for acting as trustees in a bankruptcy case on behalf of the Russian state-owned DIA, who bypassed sanction regimes to obtain funds and assets from abroad in order to fund the war in Ukraine.
Learn more about Grant Thornton

Similar Jobs

More Jobs at Grant Thornton

More Information Technology Jobs

Find similar Cyber Offensive Security Senior Associate jobs: