Offensive Security Senior Consultant
About the Role
As an Offensive Security Senior Consultant at Crowe, you will help organizations navigate an evolving threat landscape and a complex regulatory environment by delivering high-value, practical cybersecurity and risk solutions. This role is ideal for professionals who thrive in a fast-paced consulting environment, enjoy solving complex problems, and are passionate about delivering results that protect and enable business success.
At Crowe Consulting, we focus on solving problems for our clients and serving our core markets through innovative solutions. Consultants are expected to build both technical and transferable skills, think critically, and use technology—including emerging AI capabilities—to solve real business problems. You will continuously learn, collaborate across teams, and explore how tools can improve efficiency, insights, and client outcomes. As you grow, you’ll take ownership of client relationships, contribute to account strategy, and support the delivery of high-impact work.
Responsibilities
- Lead or support Offensive Security engagements including:
- Internal and external network penetration testing
- Web application penetration testing
- Wireless penetration testing
- Social engineering (phishing, telephone, onsite)
- Red teaming/Threat emulation
- Purple teaming
- Evaluate and test IT controls, application controls, security configurations, and interface/integration security.
- Provide practical recommendations for vulnerability remediation.
- Conduct cybersecurity assessments across a variety of standards/frameworks (NIST CSF, NIST 800.53, CIS, integrated control frameworks, etc.).
- Present findings and recommendations to stakeholders, including IT, Information Security, C-suite, and board-level leadership, through clear, concise written and verbal communication.
- Serve as an extension of client teams to lead or support program execution activities, including control implementation, metrics/reporting, issue remediation, and continuous improvement initiatives.
- Mentor and supervise junior consultants; contribute to team development and internal knowledge-sharing.
- Participate in practice development, including service line/methodology innovation and thought leadership.
Requirements
- Bachelor’s degree in information systems, Computer Science, Cybersecurity, Engineering, or related field.
- 2+ years of experience in cybersecurity, offensive security, or related consulting or industry roles.
- Deep working knowledge of operating systems (Windows, Linux/Unix) and databases (SQL, Oracle, etc.).
- Working knowledge of networks and the seven-layer OSI model.
- Proficiency with common offensive security tools and frameworks (e.g., Metasploit, Burp Suite, BloodHound, Nmap, etc.).
- Detection engineering or blue team operations knowledge, including evasion techniques.
- Strong scripting or programming skills.
- Experience with or curiosity about AI and automation tools in cybersecurity, including secure implementation practices and risk assessments.
Preferred Qualifications
- Progress toward or possession of certifications such as CISSP, OSCP, OSCE, or similar.
- Strong project management, critical thinking, and interpersonal skills.
- Excellent communication and technical writing skills, with the ability to tailor messages to both technical and executive audiences.
Pay
A reasonable estimate of the current range is $80,500.00 - $159,300.00 per year.
Benefits
At Crowe, we offer a comprehensive total rewards package, including:
- Exceptional people experience with a focus on well-being and career growth.
- Consistent career coaching and guidance in an inclusive, diverse culture.