Cybersecurity Analyst, Offensive Security

LUMA Energy
United States
8 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Languages
English, Spanish
Job source

Tech stack

Amazon Web Services Software System Penetration Testing Microsoft Azure Bash Shell Burp Suite Cyber Security Supervisory Control and Data Acquisition (SCADA) Python (Programming Language) Kali Linux Nmap Open Web Application Security Windows PowerShell
+12 more
Phishing Red Team (Cyber Security) Systems Integration Scripting Cloud Platform System Mitre Att&ck Cyber Threat Analysis Information Technology Metasploit Purple Team (Cyber Security) Blue Team (Cyber Security) Vulnerability Analysis

Job description

Leads and executes full-scope Red Team operations to identify vulnerabilities across IT, cloud, and OT/ICS environments and evaluate organizational detection and response readiness. Translates offensive insights into measurable defensive improvements by conducting realistic adversary simulations, developing specialized tools, and delivering clear, actionable findings., * Plans, executes, and leads Red Team engagements, adversary emulation, and penetration testing across OT/ICS environments to evaluate organizational resilience within approved Rules of Engagement (RoE).

  • Performs full-spectrum offensive operations using real-world TTPs to assess and challenge detection and response capabilities.
  • Conducts social engineering campaigns (phishing, vishing, physical) to test human factors vulnerabilities and improve security awareness.
  • Executes OT/ICS assessments, follow formal safe-testing protocols and cross-team coordination to prevent operational disruption and protect critical infrastructure.
  • Participates in Purple Team exercises to validate and improve detection, response, and prevention controls
  • Develops custom offensive tools, and scripts, to enhance Red Team capabilities and automate operational processes
  • Documents technical findings with clear impact and remediation guidance to support informed decisions and drive measurable risk reduction.
  • Collaborates with Blue Team, Threat Intelligence, and IT/OT teams to translate offensive insights into actionable defensive improvements
  • Maintain expertise on emerging threats, techniques, and tools relevant to the energy sector to ensure engagements reflect current and realistic adversary behaviors.
  • Supports vulnerability assessments and after-hours operations to improve continuous threat exposure management and maintain Red Team Readiness
  • Follows established company policies, procedures, and standards to ensure full compliance with applicable laws and industry regulations.
  • Participates in storm restoration tasks and assigned drills to contribute to the safe and reliable recovery of services.
  • Performs additional tasks aligned with role expectations and qualifications to support team goals and operational flexibility.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology.

Experience

  • 3-6 years of experience in offensive security, penetration testing, or Red Teaming.
  • Experience with cloud environments (AWS, Azure) and modern enterprise/OT systems.

Additional experience may substitute for required education when it aligns with the competencies and knowledge necessary for the role:

  • Associate’s degree in Cybersecurity, Computer Science, Information Technology may substitute when accompanied by a minimum of 5 years of experience in offensive security, penetration testing, or Red Teaming and at least 3 years of experience performing a previous Analyst role.
  • High School or equivalent (GED) when accompanied by a minimum of 8 years of experience in offensive security, penetration testing, or Red Teaming and at least 5 years of experience performing a previous Analyst role.

Competencies (Skills)

  • Advanced Offensive Security Expertise - Demonstrates deep hands-on proficiency with penetration testing and Red Team tools (Kali Linux, Metasploit, Burp Suite, Cobalt Strike, BloodHound, Nmap) and scripting languages (Python, PowerShell, Bash) to execute realistic adversary simulations.
  • Adversary Techniques & Framework Mastery - Applies extensive knowledge of MITRE ATT&CK, OWASP Top 10, and common attack vectors across network, web, cloud, identity, and OT environments to conduct targeted offensive operations.
  • OT/ICS Security & Safe-Testing Practices - Utilizes strong working knowledge of ICS/SCADA/OT systems, safe-testing protocols, and cross-team coordination methods to ensure non-disruptive and secure assessments in critical infrastructure environments.
  • Analytical, Reporting, and Communication Skills - Synthesizes complex technical findings into clear, accurate reports with business-impact context and actionable remediation guidance, delivering information effectively to both technical and non-technical audiences.
  • Collaboration & Cross-Functional Integration - Works effectively with Blue Team, Threat Intelligence, IT, and OT partners to translate offensive insights into defensive improvements and contribute to Purple Team exercises.
  • Ethical Standards & Confidentiality - Maintains high ethical principles and exercises proper judgment when handling sensitive information, demonstrating reliability and trustworthiness in all offensive security activities.
  • Bilingual Fluency - Communicates clearly and professionally in both Spanish and English to coordinate with diverse teams across multiple environments.

Licenses/Certifications

  • At least one relevant certification: OSCP, OSCE, CRTO, GPEN, or equivalent

Benefits & conditions

  • Wet or humid: Seldom
  • Working near or on moving mechanical parts: Never
  • Working near or on heavy machinery: Never
  • Working in high places: Never
  • Exposed to fumes or airborne particles: Never
  • Frequency of working in outdoor weather conditions: Never
  • Work with electricity: Never
  • Loud noise conditions: Seldom

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · World Congress 2022

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all