About the Role
Join Deloitte's Innovation Hub in Cairo as an Offensive Security Tech Lead, spearheading advanced cyber security assessments and red team operations for global clients. Deloitte, established in 1845, is the world's largest professional services network. This role sits at the intersection of technical excellence and strategic leadership, driving offensive security engagements including penetration testing, red teaming, adversary simulation, and vulnerability research across complex enterprise environments.
Core Responsibilities
- Lead and execute offensive security engagements: external/internal penetration testing, red team operations, purple team exercises, and adversary emulation campaigns
- Design and implement custom attack methodologies leveraging MITRE ATT&CK framework, C2 frameworks (Cobalt Strike, Sliver, Brute Ratel), and proprietary tooling
- Manage end-to-end engagement lifecycle: scoping, rules of engagement, execution, reporting, and executive debriefs for C-suite and technical stakeholders
- Mentor and upskill junior penetration testers and security consultants through hands-on guidance, code reviews, and knowledge-sharing sessions
- Develop and maintain offensive security tooling, exploits, and automation scripts (Python, Go, PowerShell, C#, Rust) to enhance team capabilities
- Conduct cloud and container security assessments across AWS, Azure, GCP, Kubernetes, and serverless architectures
- Perform application security testing (SAST/DAST/IAST) for web, mobile, API, and thick-client applications
- Collaborate with defensive teams (SOC, IR, Threat Hunting) to validate detection logic and improve organizational resilience
- Stay current with emerging threats, CVEs, and attack techniques; contribute to Deloitte's threat intelligence and research publications
Required Qualifications
- 7+ years progressive experience in offensive security, with 3+ years in a technical lead or senior consultant capacity
- Proven track record leading red team operations and complex penetration testing engagements for enterprise clients
- Deep expertise in adversary emulation, C2 infrastructure management, and post-exploitation techniques
- Advanced proficiency in programming/scripting: Python, Go, PowerShell, C#, or Rust for tool development and automation
- Strong command of network protocols, Active Directory/Entra ID attacks, Kerberos delegation, lateral movement, and privilege escalation
- Hands-on experience with cloud penetration testing (AWS, Azure, GCP) and container orchestration security (Kubernetes, Docker)
- Industry-recognized certifications: OSCP, OSWE, OSEP, CRTO, CRTE, or equivalent (e.g., PNPT, eCPPTX, RED TEAM OPS)
- Excellent technical reporting and executive communication skills; ability to translate risk to business impact
- Fluent in English (written and verbal); Arabic proficiency is a strong plus
Preferred Skills
- Experience with malware development, AV/EDR evasion, and custom implant development
- Background in vulnerability research and exploit development (Windows/Linux kernel, browser, RCE chains)
- Familiarity with OT/ICS/SCADA security assessments and Purdue model architectures
- Contributions to open-source offensive security tools (e.g., BloodHound, SharpSuite, Nuclei templates, PwnKit)
- Speaking experience with bug bounty hunting or responsible disclosure track record (HackerOne, Bugcrowd, Intigriti)
- Knowledge of DevSecOps pipelines and securing CI/CD (GitHub Actions, GitLab CI, Azure DevOps, Jenkins)
- Advanced degrees in Computer Science, Cyber Security, or related fields
What Makes This Opportunity Stand Out
- Global Impact: Work on high-profile engagements for Fortune 500 clients across financial services, energy, government, and technology sectors
- Innovation Hub Culture: Access to Deloitte's proprietary threat intelligence, research labs, and emerging technology sandbox environments
- Career Trajectory: Clear pathway to Senior Manager, Director, or Partner track within Deloitte's Cyber Risk practice
- Continuous Learning: Dedicated budget for certifications, conference attendance (Black Hat, DEF CON, BSides), and specialized training (OffSec, SANS, Zero-Point)
- Collaborative Ecosystem: Partner with Deloitte's Threat Intelligence, Incident Response, Cloud Security, and Identity teams on integrated client solutions
- Location Advantage: Based in Cairo's vibrant tech hub with hybrid flexibility, serving MENA and global delivery models