This position is no longer accepting applications
Closed on August 31, 2026.
This role is filled — get an email when new Information Security roles open on CybersecurityJobs.io:
Offensive Security Analyst II
Application Security
Cloud Platforms
Cybersecurity Tools
Information Security
Information Technology (IT)
InfoSec
Investigative Skills
Level II
Metasploit
Offensive Security
Penetration Testing
Security
Security Compliance
Security Testing
Vulnerability Assessment
Vulnerability Scanners
View similar jobs
Get alerted when similar jobs are posted — set up a New Information Security jobs on CybersecurityJobs.io alert.
See other roles at HEB.
Job Description
This hybrid role in Austin or San Antonio, TX focuses on offensive security testing, threat emulation, and remediation coordination for HEB.
Responsibilities
- Identify and validate vulnerabilities through network penetration testing, web and mobile app testing, source code reviews, network segmentation assessments, and wireless network evaluations.
- Assess security control effectiveness by conducting purple team exercises using both manual and automated techniques.
- Prepare and present finding reports for technical and executive audiences to support remediation efforts.
- Assist in identifying remediation options for discovered security issues.
- Collaborate with Digital Compliance, Internal Audit, business teams, and internal and external penetration testing vendors to scope, schedule, validate, and execute offensive testing programs.
- Coordinate with various stakeholders to plan and execute offensive testing activities.
- Design, develop, document, optimize, and automate Windows, Linux, virtual lab environments, and cloud-based solutions to support offensive simulations.
- Develop new offensive capabilities by designing and implementing automation and associated Windows, Linux, lab, and cloud resources.
- Research emerging threats and threat emulation methodologies, keep current on industry trends, and pursue ongoing growth in technology, business knowledge, and internal policies.
Requirements
- Minimum of 3+ years direct experience in penetration testing (web applications, hosts, networks), exploit development, fuzzing, and crafting countermeasures to identified vulnerabilities/risks.
- Strong understanding of attack surfaces across web technologies, networks, modern applications (microservices/containers), and operating systems; ability to analyze closed-source applications using various off-the-shelf or custom tools.
- Experience with tools such as Kali Linux, Metasploit, Burp Suite, Cobalt Strike, Tenable Nessus, WebInspect, IDA PRO, and Wireshark.
- Experience with scripting and development languages (e.g., Bash, PowerShell, Python, Perl, Ruby, PHP, C/C++, C#, Java, etc.).
- Experience testing across Windows, Linux, and cloud environments.
- Working knowledge of information systems security standards and practices, including access control, system hardening, log monitoring, security policies, and incident handling.
- Detail-oriented with strong problem-solving skills and the ability to anticipate potential issues.
- Excellent verbal and written communication abilities.
- Experience assessing APT threats, penetration testing, vulnerability management, attack methodologies, forensics techniques, malware analysis, attack surface comprehension, cyber threat emulation operations, and researching new APT TTPs.
- Fundamental understanding of security testing for mobile, native applications, web applications, distributed systems, and databases.
Technologies
- Kali Linux
- Metasploit
- Burp Suite
- Cobalt Strike
- Tenable Nessus
- WebInspect
- IDA PRO
- Wireshark
- Bash
- PowerShell
- Python
- Perl
- Ruby
- PHP
- C/C++
- C#
- Java
- Windows
- Linux
- Cloud
Physical Demands & Working Conditions
- Function in a fast-paced retail office environment.
- Work extended hours and may require prolonged sitting.