Offensive Security Analyst II
Core
Designing, building, and scaling offensive security capabilities through adversary-focused testing, attack simulation, and custom tooling development to transform a vendor-driven model to a build-first approach.
Role type
Senior IC offensive security analyst (red/purple teaming & tooling)
Builds
Custom offensive security tooling, frameworks, reusable modules, automation, and developer-consumable assets for self-validation.
Domain
Cybersecurity (Offensive Security / Red Teaming / Cloud Security)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, red teaming, purple teaming, adversary emulation, vulnerability analysis, exploit chaining, cloud security (Azure/Entra ID), identity security, scripting (Python, PowerShell, Bash), CI/CD integration, secure coding practices, API usage, data pipeline management, AI/ML-assisted testing techniques.
Preferred skills
Software engineering background, platform engineering experience, SRE experience, knowledge of MITRE ATT&CK, experience with C2 frameworks and exploit frameworks, ability to translate technical findings into actionable remediation guidance.
Technologies
Python, PowerShell, Bash, Azure/Entra ID, C2 frameworks, vulnerability scanners, exploit frameworks, CI/CD systems, APIs, cloud-native services.
Responsibilities
Conduct penetration testing, attack simulations, and threat-based assessments across on-prem, cloud, and SaaS environments; develop and maintain custom offensive security tooling and automation; execute red team and purple team exercises; validate security controls (EDR, SIEM, identity); design secure patterns and reference implementations for engineering teams; integrate security testing into CI/CD pipelines; mentor junior analysts; provide developer-friendly remediation guidance and proof-of-concepts.
Seniority
Senior, hands-on IC