Offensive Security Analyst, Senior Specialist
Job in
Dallas, Dallas County, Texas, 75201, USA
Listed on 2026-06-12
Listing for:
Vanguard
Full Time
position Listed on 2026-06-12
Job specializations:
-
IT/Tech
Cybersecurity, IT Consultant, Systems Engineer, Security Manager
Job Description & How to Apply Below
This is a hands-on role focused on traditional offensive security methods - you'll use well-known and custom tools to emulate sophisticated threat actors, improve our security posture, and reduce risk.
Key Responsibilities:
* Red Team Operations & Adversary Simulation:
Participate in full-scope red team engagements, contributing across the kill-chain (reconnaissance, exploitation, lateral movement, data exfiltration, etc.). Occasionally lead targeted adversary simulations at moderate scope (e.g., a spear-phishing campaign or an endpoint compromise scenario, using phishing or malware implants). Emulate real threat actor TTPs aligned with frameworks like MITRE ATT&CK to test our detection and response capabilities.
* Collaborative Remediation & Purple Team Support:
Work closely with defensive teams - such as developers, system engineers, and security operations - to ensure discovered issues are understood and remediated effectively. Provide actionable technical guidance to fix vulnerabilities (e.g., code remediation suggestions for development teams). Support purple team exercises by sharing attacker perspective knowledge and helping defensive teams validate alerts and improve detection rules.
* Reporting & Communication:
Document each engagement thoroughly, producing clear and detailed penetration test reports that explain findings, their severity, and recommended mitigations. Communicate technical details to both technical and non-technical audiences; for instance, explaining a complex exploit in layman's terms to business stakeholders or summarizing red team outcomes in executive readouts.
* Continuous Learning & Tooling:
Continuously research emerging vulnerabilities, new exploit techniques, and security trends in the offensive domain. Keep offensive toolkit sharp - use and refine tools like Burp Suite, OWASP ZAP, Metasploit, Kali Linux, etc., and create custom scripts (in Python, Power Shell, Bash, etc.) to automate routine tasks or develop new exploits. Share knowledge with peers, help mentor junior analysts, and contribute to the team's playbooks and knowledge base.
* * Technical Offensive Security
Experience:
5+ years of hands-on penetration testing and/or red teaming experience. Proven track record of identifying and exploiting vulnerabilities across web applications (deep knowledge of OWASP Top 10), networks, and cloud services. Familiarity with shell scripting and programming (Python, Power Shell, Bash) for exploit development and automation. Strong understanding of network protocols, operating systems, identity management, and security architecture.
* Adversary Mindset & Frameworks:
Demonstrated ability to think like an attacker to anticipate and craft creative exploitation scenarios. Familiarity with frameworks and methodologies like MITRE ATT&CK, PTES (Penetration Testing Execution Standard), and relevant compliance standards (NIST, ISO), ensuring tests are realistic and comprehensive.
* * Communication & Teamwork:
Strong written and verbal communication skills to produce high-quality reports and articulate risk to stakeholders. Experience collaborating with defensive teams (security operations, appsec, IT engineering) to help them understand issues and prioritize fixes. A team-oriented approach: open to knowledge sharing, learning from others, and contributing positively to the team's success.
Preferred Qualifications:
* Offensive security certifications such as OSCP, OSWE, OSWA, GPEN, GWAPT, or similar, demonstrating validated skills in penetration testing.
* Experience performing threat modeling and incorporating attacker perspective into security design reviews.
* Familiarity with cloud platforms (AWS, Azure,…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×