Offensive Security Consultant
Location: Johannesburg, South Africa
Employment type: Full time, permanent
Seniority: Intermediate, two years or more of hands-on penetration testing
At a glance
- Hands-on penetration testing across web applications, APIs, internal and external infrastructure, and networks, delivered with limited supervision.
- At least two years of professional offensive-security work and at least two recognised penetration-testing certifications.
- Office-based with flexible hours, plus travel to client engagements, including outside South Africa.
About RedHerd
RedHerd is a specialist cybersecurity recruitment and advisory firm. We work with consultancies, product companies, vendors and enterprise security teams across South Africa, the UK, Europe and the United States. We are recruiting this position exclusively on behalf of our client. We share their identity with you during qualification, before submitting anything. We never introduce your profile without your knowledge and consent.
About the client
Our client is an established cybersecurity consultancy that delivers offensive security and managed security services to organisations across Southern Africa and beyond. Its client base includes businesses in Portuguese- and French-speaking markets.
Engagements span varied client environments, so the work does not settle into one estate or one test type.
The role
This is an intermediate consulting seat. You run authorised assessments with limited supervision, find and validate vulnerabilities, and explain both the technical and business risk to the people who have to fix them.
You work inside agreed scopes, methodologies, legal authorisations and client confidentiality requirements. On complex engagements, you work alongside senior consultants, and structured training supports your development.
What it is not. It is not a scanner-driven role. The client wants findings validated by hand and false positives filtered out before they reach a report. It is not a senior or lead seat, and it is not a people-management position.
What you will do
- Scope-aware reconnaissance and enumeration, then exploitation and post-exploitation within the agreed rules of engagement.
- Penetration tests and vulnerability assessments across web applications, APIs, internal and external infrastructure, and networks.
- Test authentication, authorisation, session management and access control for common weaknesses.
- Validate every vulnerability by hand and demonstrate it safely, keeping operational risk to clients low.
- Use commercial and open-source tooling well, without leaning on automated scanner output.
- Keep clear, reproducible evidence and accurate engagement notes throughout.
- Write reports that cover the technical finding, the business impact, the risk rating and practical remediation.
- Present findings to technical stakeholders and help with remediation discussions.
- Retest to confirm that reported vulnerabilities have actually been fixed.
- Keep up with new offensive techniques, vulnerabilities and industry developments.
What you must bring
At least two years of hands-on penetration testing or offensive security in a professional environment. Treat that as a level, not a ceiling.
- At least two recognised penetration-testing certifications, for example OSCP, PNPT, CPTS, CRTO, CRTP, eCPPT, eWPT or eWPTX, GPEN, or equivalent practical credentials.
- Demonstrable web application and API testing with Burp Suite or similar.
- Working knowledge of internal and external network testing across Windows, Linux and Active Directory environments.
- Practical use of Nmap, Nessus or an equivalent scanner, Metasploit, Linux security tooling and common enumeration frameworks.
- A sound understanding of the OWASP Top 10, common infrastructure vulnerabilities, networking and operating systems.
- The judgement to separate exploitable vulnerabilities from false positives and explain their real impact.
- Clear, professional technical report writing in English.
- Willingness and ability to travel for client engagements, including outside South Africa.
- Legal eligibility to work in South Africa.
Useful extras
- Portuguese. A real plus here, because the client serves businesses in Mozambique.
- French. A bonus, because the client also works with businesses in French-speaking markets.
- Active Directory attack-path analysis and privilege escalation.
- Mobile, cloud, wireless or thick-client testing.
- Scripting in Python, PowerShell or Bash.
- Secure code review, or familiarity with modern development practice.
- Consulting experience, including client-facing delivery and scoping.
- Responsible disclosures, CTFs, security research or other public practical work.
- A tertiary qualification in IT, computer science, cybersecurity or a related field.
Work arrangement
Johannesburg. Primarily office-based, with flexible working hours.
Travel is required for client engagements when needed, including outside South Africa.
Package and development
Package will be discussed during the Clearing Call with RedHerd.
- Company-provided devices and the professional tooling the role needs.
- A structured training and certification path.
- Company-supported learning, lab access and certification exams.
- Exposure to varied client environments and a broad spread of offensive-security work.
Process and verification
- Apply on the job page. Submit a CV, a list of your current certifications, and answer all the screening questions. Links to public work help: technical articles, research, responsible disclosures, GitHub projects or CTF profiles.
- Clearing call with RedHerd to discuss your application, the role and the package.
- Practical technical assessment with the client, role-relevant and run in an authorised environment.
- Discussion with the team about your approach and findings.
- Reference and background checks before offer. The client runs these itself.
If a profile or CV does not fully describe confidential work, candidates are encouraged to explain their contribution without disclosing sensitive customer or employer information.
Why this role
- Varied engagements across web, API, infrastructure and network testing, rather than one repeated test type.
- A structured training and certification path, with exams and lab access paid for.
- Senior consultants to work alongside on complex engagements.
- Travel to client engagements outside South Africa.
- Company-provided devices and tooling.
Equal opportunity
Applications are considered against the skills, experience, location and verification requirements of the role. RedHerd and our clients are committed to a fair and respectful process and do not discriminate on the basis of any protected characteristic.