Offensive Security Analyst II
Job Description
This hybrid role in Austin or San Antonio, TX focuses on offensive security testing, threat emulation, and remediation coordination for HEB.
Responsibilities
- Identify and validate vulnerabilities through network penetration testing, web and mobile app testing, source code reviews, network segmentation assessments, and wireless network evaluations.
- Assess security control effectiveness by conducting purple team exercises using both manual and automated techniques.
- Prepare and present finding reports for technical and executive audiences to support remediation efforts.
- Assist in identifying remediation options for discovered security issues.
- Collaborate with Digital Compliance, Internal Audit, business teams, and internal and external penetration testing vendors to scope, schedule, validate, and execute offensive testing programs.
- Coordinate with various stakeholders to plan and execute offensive testing activities.
- Design, develop, document, optimize, and automate Windows, Linux, virtual lab environments, and cloud-based solutions to support offensive simulations.
- Develop new offensive capabilities by designing and implementing automation and associated Windows, Linux, lab, and cloud resources.
- Research emerging threats and threat emulation methodologies, keep current on industry trends, and pursue ongoing growth in technology, business knowledge, and internal policies.
Requirements
- Minimum of 3+ years direct experience in penetration testing (web applications, hosts, networks), exploit development, fuzzing, and crafting countermeasures to identified vulnerabilities/risks.
- Strong understanding of attack surfaces across web technologies, networks, modern applications (microservices/containers), and operating systems; ability to analyze closed-source applications using various off-the-shelf or custom tools.
- Experience with tools such as Kali Linux, Metasploit, Burp Suite, Cobalt Strike, Tenable Nessus, WebInspect, IDA PRO, and Wireshark.
- Experience with scripting and development languages (e.g., Bash, PowerShell, Python, Perl, Ruby, PHP, C/C++, C#, Java, etc.).
- Experience testing across Windows, Linux, and cloud environments.
- Working knowledge of information systems security standards and practices, including access control, system hardening, log monitoring, security policies, and incident handling.
- Detail-oriented with strong problem-solving skills and the ability to anticipate potential issues.
- Excellent verbal and written communication abilities.
- Experience assessing APT threats, penetration testing, vulnerability management, attack methodologies, forensics techniques, malware analysis, attack surface comprehension, cyber threat emulation operations, and researching new APT TTPs.
- Fundamental understanding of security testing for mobile, native applications, web applications, distributed systems, and databases.
Technologies
- Kali Linux
- Metasploit
- Burp Suite
- Cobalt Strike
- Tenable Nessus
- WebInspect
- IDA PRO
- Wireshark
- Bash
- PowerShell
- Python
- Perl
- Ruby
- PHP
- C/C++
- C#
- Java
- Windows
- Linux
- Cloud
Physical Demands & Working Conditions
- Function in a fast-paced retail office environment.
- Work extended hours and may require prolonged sitting.