CybersecurityJobs.io
← Back to all jobs

Job Description

This hybrid role in Austin or San Antonio, TX focuses on offensive security testing, threat emulation, and remediation coordination for HEB.

Responsibilities

  • Identify and validate vulnerabilities through network penetration testing, web and mobile app testing, source code reviews, network segmentation assessments, and wireless network evaluations.
  • Assess security control effectiveness by conducting purple team exercises using both manual and automated techniques.
  • Prepare and present finding reports for technical and executive audiences to support remediation efforts.
  • Assist in identifying remediation options for discovered security issues.
  • Collaborate with Digital Compliance, Internal Audit, business teams, and internal and external penetration testing vendors to scope, schedule, validate, and execute offensive testing programs.
  • Coordinate with various stakeholders to plan and execute offensive testing activities.
  • Design, develop, document, optimize, and automate Windows, Linux, virtual lab environments, and cloud-based solutions to support offensive simulations.
  • Develop new offensive capabilities by designing and implementing automation and associated Windows, Linux, lab, and cloud resources.
  • Research emerging threats and threat emulation methodologies, keep current on industry trends, and pursue ongoing growth in technology, business knowledge, and internal policies.

Requirements

  • Minimum of 3+ years direct experience in penetration testing (web applications, hosts, networks), exploit development, fuzzing, and crafting countermeasures to identified vulnerabilities/risks.
  • Strong understanding of attack surfaces across web technologies, networks, modern applications (microservices/containers), and operating systems; ability to analyze closed-source applications using various off-the-shelf or custom tools.
  • Experience with tools such as Kali Linux, Metasploit, Burp Suite, Cobalt Strike, Tenable Nessus, WebInspect, IDA PRO, and Wireshark.
  • Experience with scripting and development languages (e.g., Bash, PowerShell, Python, Perl, Ruby, PHP, C/C++, C#, Java, etc.).
  • Experience testing across Windows, Linux, and cloud environments.
  • Working knowledge of information systems security standards and practices, including access control, system hardening, log monitoring, security policies, and incident handling.
  • Detail-oriented with strong problem-solving skills and the ability to anticipate potential issues.
  • Excellent verbal and written communication abilities.
  • Experience assessing APT threats, penetration testing, vulnerability management, attack methodologies, forensics techniques, malware analysis, attack surface comprehension, cyber threat emulation operations, and researching new APT TTPs.
  • Fundamental understanding of security testing for mobile, native applications, web applications, distributed systems, and databases.

Technologies

  • Kali Linux
  • Metasploit
  • Burp Suite
  • Cobalt Strike
  • Tenable Nessus
  • WebInspect
  • IDA PRO
  • Wireshark
  • Bash
  • PowerShell
  • Python
  • Perl
  • Ruby
  • PHP
  • C/C++
  • C#
  • Java
  • Windows
  • Linux
  • Cloud

Physical Demands & Working Conditions

  • Function in a fast-paced retail office environment.
  • Work extended hours and may require prolonged sitting.

Similar Jobs