NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs
4 days ago
Apply with autofill
Apply with autofill
Lumaenergy·4 days ago
4 days ago

Cybersecurity Analyst, Offensive Security

SanturceMid · 3-6 yearsSecurity Analyst

Sign up free to see how well your resume matches this role.

Boost your chances at lumaenergy

How you compare FREE

?
Your scoreYour score: not yet known

Must-have skills for this role

  • oscp
  • osce
  • crto
  • gpen

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Plans, executes, and leads Red Team engagements, adversary emulation, and penetration testing across OT/ICS environments to evaluate organizational resilience within approved Rules of Engagement (RoE).
  • Performs full-spectrum offensive operations using real-world TTPs to assess and challenge detection and response capabilities.
  • Conducts social engineering campaigns (phishing, vishing, physical) to test human factors vulnerabilities and improve security awareness.
  • Executes OT/ICS assessments, follow formal safe-testing protocols and cross-team coordination to prevent operational disruption and protect critical infrastructure.
  • Participates in Purple Team exercises to validate and improve detection, response, and prevention controls
  • Develops custom offensive tools, and scripts, to enhance Red Team capabilities and automate operational processes
  • Documents technical findings with clear impact and remediation guidance to support informed decisions and drive measurable risk reduction.
  • Collaborates with Blue Team, Threat Intelligence, and IT/OT teams to translate offensive insights into actionable defensive improvements
  • Maintain expertise on emerging threats, techniques, and tools relevant to the energy sector to ensure engagements reflect current and realistic adversary behaviors.
  • Supports vulnerability assessments and after-hours operations to improve continuous threat exposure management and maintain Red Team Readiness
  • Follows established company policies, procedures, and standards to ensure full compliance with applicable laws and industry regulations.
  • Participates in storm restoration tasks and assigned drills to contribute to the safe and reliable recovery of services.

What they're looking for

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology.
  • 3-6 years of experience in offensive security, penetration testing, or Red Teaming.
  • Experience with cloud environments (AWS, Azure) and modern enterprise/OT systems.
  • At least one relevant certification: OSCP, OSCE, CRTO, GPEN, or equivalent

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Job Summary:

Leads and executes full‑scope Red Team operations to identify vulnerabilities across IT, cloud, and OT/ICS environments and evaluate organizational detection and response readiness. Translates offensive insights into measurable defensive improvements by conducting realistic adversary simulations, developing specialized tools, and delivering clear, actionable findings.

Job Description:

  • Plans, executes, and leads Red Team engagements, adversary emulation, and penetration testing across OT/ICS environments to evaluate organizational resilience within approved Rules of Engagement (RoE).

  • Performs full-spectrum offensive operations using real-world TTPs to assess and challenge detection and response capabilities.

  • Conducts social engineering campaigns (phishing, vishing, physical) to test human factors vulnerabilities and improve security awareness.

  • Executes OT/ICS assessments, follow formal safe-testing protocols and cross-team coordination to prevent operational disruption and protect critical infrastructure.

  • Participates in Purple Team exercises to validate and improve detection, response, and prevention controls

  • Develops custom offensive tools, and scripts, to enhance Red Team capabilities and automate operational processes

  • Documents technical findings with clear impact and remediation guidance to support informed decisions and drive measurable risk reduction.

  • Collaborates with Blue Team, Threat Intelligence, and IT/OT teams to translate offensive insights into actionable defensive improvements

  • Maintain expertise on emerging threats, techniques, and tools relevant to the energy sector to ensure engagements reflect current and realistic adversary behaviors.

  • Supports vulnerability assessments and after-hours operations to improve continuous threat exposure management and maintain Red Team Readiness

  • Follows established company policies, procedures, and standards to ensure full compliance with applicable laws and industry regulations.

  • Participates in storm restoration tasks and assigned drills to contribute to the safe and reliable recovery of services.

  • Performs additional tasks aligned with role expectations and qualifications to support team goals and operational flexibility.

Additional Job Description:

Education

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology.

Experience

  • 3-6 years of experience in offensive security, penetration testing, or Red Teaming.

  • Experience with cloud environments (AWS, Azure) and modern enterprise/OT systems.

Additional experience may substitute for required education when it aligns with the competencies and knowledge necessary for the role:

  • Associate’s degree in Cybersecurity, Computer Science, Information Technology may substitute when accompanied by a minimum of 5 years of experience in offensive security, penetration testing, or Red Teaming and at least 3 years of experience performing a previous Analyst role.

  • High School or equivalent (GED) when accompanied by a minimum of 8 years of experience in offensive security, penetration testing, or Red Teaming and at least 5 years of experience performing a previous Analyst role.

Competencies (Skills)

  • Advanced Offensive Security Expertise – Demonstrates deep hands‑on proficiency with penetration testing and Red Team tools (Kali Linux, Metasploit, Burp Suite, Cobalt Strike, BloodHound, Nmap) and scripting languages (Python, PowerShell, Bash) to execute realistic adversary simulations.

  • Adversary Techniques & Framework Mastery – Applies extensive knowledge of MITRE ATT&CK, OWASP Top 10, and common attack vectors across network, web, cloud, identity, and OT environments to conduct targeted offensive operations.

  • OT/ICS Security & Safe‑Testing Practices – Utilizes strong working knowledge of ICS/SCADA/OT systems, safe‑testing protocols, and cross‑team coordination methods to ensure non‑disruptive and secure assessments in critical infrastructure environments.

  • Analytical, Reporting, and Communication Skills – Synthesizes complex technical findings into clear, accurate reports with business-impact context and actionable remediation guidance, delivering information effectively to both technical and non-technical audiences.

  • Collaboration & Cross‑Functional Integration – Works effectively with Blue Team, Threat Intelligence, IT, and OT partners to translate offensive insights into defensive improvements and contribute to Purple Team exercises.

  • Ethical Standards & Confidentiality – Maintains high ethical principles and exercises proper judgment when handling sensitive information, demonstrating reliability and trustworthiness in all offensive security activities.

  • Bilingual Fluency – Communicates clearly and professionally in both Spanish and English to coordinate with diverse teams across multiple environments.

Licenses/Certifications

  • At least one relevant certification: OSCP, OSCE, CRTO, GPEN, or equivalent

Travel Requirements

  • No

Physical Demands

  • Stationary Position: Constantly

  • Pushing/ Pulling/ Reaching: Seldom

  • Kneel: Seldom

  • Grab: Seldom

  • Bend: Seldom

  • Lift/Carry over: 0 – 15 pounds

Working Conditions

  • Wet or humid: Seldom

  • Working near or on moving mechanical parts: Never

  • Working near or on heavy machinery: Never

  • Working in high places: Never

  • Exposed to fumes or airborne particles: Never

  • Frequency of working in outdoor weather conditions: Never

  • Work with electricity: Never

  • Loud noise conditions: Seldom

LUMA Energy is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, military status, disability, or any other characteristic protected by federal or local laws.

Company

Lumaenergy
Santurce

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Lumaenergy's careers site·first seen 18 Sept 2026·last verified 18 Sept 2026·How we source jobs

Similar jobs

  • Analista SOC N2/N3 at Accenture–match not yet calculated
  • Data Protect & InfoSec Compl Spec at Accenture–match not yet calculated
  • Information Security Analyst at wearediverse2–match not yet calculated
  • Principal Cybersecurity - Incident Response Analyst at attUSA:NC:Charlotte–match not yet calculated
  • Cyber Security Analyst SME at gditAny Location–match not yet calculated

Browse more jobs

  • Security Analyst jobs in United States
  • Security Analyst jobs in India
  • Security Analyst jobs in United Kingdom
  • Retail Sales Associate jobs in United States