Cybersecurity Analyst, Offensive Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+12 more
Job description
Leads and executes full-scope Red Team operations to identify vulnerabilities across IT, cloud, and OT/ICS environments and evaluate organizational detection and response readiness. Translates offensive insights into measurable defensive improvements by conducting realistic adversary simulations, developing specialized tools, and delivering clear, actionable findings., * Plans, executes, and leads Red Team engagements, adversary emulation, and penetration testing across OT/ICS environments to evaluate organizational resilience within approved Rules of Engagement (RoE).
- Performs full-spectrum offensive operations using real-world TTPs to assess and challenge detection and response capabilities.
- Conducts social engineering campaigns (phishing, vishing, physical) to test human factors vulnerabilities and improve security awareness.
- Executes OT/ICS assessments, follow formal safe-testing protocols and cross-team coordination to prevent operational disruption and protect critical infrastructure.
- Participates in Purple Team exercises to validate and improve detection, response, and prevention controls
- Develops custom offensive tools, and scripts, to enhance Red Team capabilities and automate operational processes
- Documents technical findings with clear impact and remediation guidance to support informed decisions and drive measurable risk reduction.
- Collaborates with Blue Team, Threat Intelligence, and IT/OT teams to translate offensive insights into actionable defensive improvements
- Maintain expertise on emerging threats, techniques, and tools relevant to the energy sector to ensure engagements reflect current and realistic adversary behaviors.
- Supports vulnerability assessments and after-hours operations to improve continuous threat exposure management and maintain Red Team Readiness
- Follows established company policies, procedures, and standards to ensure full compliance with applicable laws and industry regulations.
- Participates in storm restoration tasks and assigned drills to contribute to the safe and reliable recovery of services.
- Performs additional tasks aligned with role expectations and qualifications to support team goals and operational flexibility.
Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology.
Experience
- 3-6 years of experience in offensive security, penetration testing, or Red Teaming.
- Experience with cloud environments (AWS, Azure) and modern enterprise/OT systems.
Additional experience may substitute for required education when it aligns with the competencies and knowledge necessary for the role:
- Associate’s degree in Cybersecurity, Computer Science, Information Technology may substitute when accompanied by a minimum of 5 years of experience in offensive security, penetration testing, or Red Teaming and at least 3 years of experience performing a previous Analyst role.
- High School or equivalent (GED) when accompanied by a minimum of 8 years of experience in offensive security, penetration testing, or Red Teaming and at least 5 years of experience performing a previous Analyst role.
Competencies (Skills)
- Advanced Offensive Security Expertise - Demonstrates deep hands-on proficiency with penetration testing and Red Team tools (Kali Linux, Metasploit, Burp Suite, Cobalt Strike, BloodHound, Nmap) and scripting languages (Python, PowerShell, Bash) to execute realistic adversary simulations.
- Adversary Techniques & Framework Mastery - Applies extensive knowledge of MITRE ATT&CK, OWASP Top 10, and common attack vectors across network, web, cloud, identity, and OT environments to conduct targeted offensive operations.
- OT/ICS Security & Safe-Testing Practices - Utilizes strong working knowledge of ICS/SCADA/OT systems, safe-testing protocols, and cross-team coordination methods to ensure non-disruptive and secure assessments in critical infrastructure environments.
- Analytical, Reporting, and Communication Skills - Synthesizes complex technical findings into clear, accurate reports with business-impact context and actionable remediation guidance, delivering information effectively to both technical and non-technical audiences.
- Collaboration & Cross-Functional Integration - Works effectively with Blue Team, Threat Intelligence, IT, and OT partners to translate offensive insights into defensive improvements and contribute to Purple Team exercises.
- Ethical Standards & Confidentiality - Maintains high ethical principles and exercises proper judgment when handling sensitive information, demonstrating reliability and trustworthiness in all offensive security activities.
- Bilingual Fluency - Communicates clearly and professionally in both Spanish and English to coordinate with diverse teams across multiple environments.
Licenses/Certifications
- At least one relevant certification: OSCP, OSCE, CRTO, GPEN, or equivalent
Benefits & conditions
- Wet or humid: Seldom
- Working near or on moving mechanical parts: Never
- Working near or on heavy machinery: Never
- Working in high places: Never
- Exposed to fumes or airborne particles: Never
- Frequency of working in outdoor weather conditions: Never
- Work with electricity: Never
- Loud noise conditions: Seldom
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities
Walking Into The Era of Supply Chain Risks
Best Paying Jobs in Technology