layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
San Antonio, Texas
Source: H-E-B careers · View original posting
From H-E-B's posting. “We” and “our” refer to the employer.
Responsibilities Job Summary: As a Staff Offensive Security Analyst, you'll provide consultative and hands on services by performing technical planning and testing of Digital assets, systems, processes, and employees. Key Responsibilities & Essential Functions: Analytics / Information Technology: Works with Digital Compliance, Internal Audit, business teams, and internal and external penetration testing vendors to scope / configure / validate solutions to support penetration testing.
Identifies and validates vulnerabilities by performing network penetration, web and mobile app testing, source code reviews, network segmentation testing, and wireless network assessments. Validates security control capability effectiveness by performing red and purple team testing using manual and automated capabilities. Writes and presents finding reports for both technical and executive audiences to support stakeholder remediation activities. Facilitates and supports efforts to identify remediation solutions to security findings.
Designs / develops / documents / optimizes / automates / implements Windows, Linux, virtual lab environments, virtual, and cloud solutions to support penetration testing. Works with business teams to identify remediation solutions to security findings. Develops, documents guidelines, and procedures. Builds / maintains pen testing vendor partnerships to further H-E-B mission and goals.
Research / stays up to date on emerging threats and threat emulation methodologies; maintains current knowledge of industry trends and standards; ensures continued personal growth in technology, business knowledge, and H-E-B policies and platforms. Coaches / mentors team Partners The responsibilities and essential functions outlined above describe the general nature and level of work assigned to this position. This is not an exhaustive list of all duties, responsibilities, and skills required.
Duties and responsibilities may be modified at any time based on business needs. Employees may be required to perform other job-related tasks as requested by their supervisor, subject to reasonable accommodations. Qualifications & Key Requirements: Work Experience: 7+ years of experience in penetration testing (web application, host, network), exploit development, and fuzzing and designing countermeasures to identified security vulnerabilities and risks.
Experience assessing APT threats, in penetration testing, vulnerability management, attack methodologies, forensics analysis techniques, malware analysis, attack surface comprehension, cyber threat emulation operations, cyber advanced threat emulation team operations and research, identification, and verification of new APT TTPs Experience with modern AI and Large Language Model (LLM) technologies, including how AI can be leveraged to enhance offensive security testing, security tooling, and threat simulation activities.
Experience in penetration and vulnerability testing tools (e.g., Kali Linux, Metasploit, Burp Suite, Cobalt Strike, Tenable Nessus, Web Inspect, IDA Pro, Wireshark) Experience developing red team applications, tools, and infrastructure (e.g., implants, exploits, C2) Experience testing APIs and integration techniques Experience in scripting and development languages (e.g., Bash, PowerShell, Python, Perl, Ruby, PHP, C/C++, C#, Java) Knowledge/Skills/Abilities: Advanced working knowledge of info systems security standards and practices
(e.g., access control and system hardening, system audit and log file monitoring, security policies, incident handling) and of attack surfaces in web technologies, networks, modern applications (microservices, containers), and operating systems Advanced working understanding of security assessment frameworks (e.g., PCI, HIPAA, GDPR) and security knowledge related to testing mobile, native applications, web applications, and distributed and database systems.
Advanced problem-solving skills Advanced verbal / written communication skills Ability to analyze potential future issues. Ability to analyze closed source applications using several off-the-shelf or custom developed tools. Detail-oriented Education: A related degree or comparable formal training, certification, or work experience Licenses/Certifications: One or more professional security certifications (e.g., OSCP, OSWP, CRTO, GPEN, GXPN, GWAPT, CISSP) (preferred) Physical Demands & Working Conditions: Function in a fast-paced,
retail, office environment Work extended hours / sit for extended periods. The work environment characteristics described here are representative of those a Partner encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. JDSECURITY
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted:
The Hartford · Hartford, CT; Hartford CT- Home Office; Scottsdale, AZ-Raintree Drive; San Antonio - Wiseman Blvd; Alpharetta, GA; Naperville, IL- W. Diehl Road; United States…
Stanley Consultants · San Antonio, TX
ZOLL · US CO Broomfield; US MN Minnetonka; US PA Pittsburgh Gamma; Broomfield, CO; San Antonio, TX; US PA Pittsburgh Anchor; Orlando, FL; US MA Wilmington; Raleigh, N…
Wells Fargo · SAN ANTONIO, TX; 145786-TX-Building 203, San Antonio Ops Center
USAA · San Antonio Home Office I; Phoenix Campus (Main); Tampa Campus; CVA,VA-Crossways I & II; Colorado Springs Campus; Tampa Crosstown; Plano Legacy
Frost Bank · San Antonio, TX - One Frost