Red Team Security Engineer

Aviso de fuente externaen Outsourcing Services International | OSI

GENERAL DESCRIPTION Red Team capability is a core requirement for this position. Equally important is the ability to build and maintain automation across SIEM, SOAR, security tooling, API...

Fuente externa - sin verificarhace 3 semanasVigente hasta: 31 oct 2026

Enlace de postulación no disponible

Salario

No especificado

Ubicación

Antiguo Cuscatlán, El Salvador

Tipo de empleo

Tiempo completo

Modalidad

No especificado

Red Team Security Engineer

Antiguo Cuscatlán, El Salvador

Enlace de postulación no disponible

Descripción del empleo

GENERAL DESCRIPTION
Red Team capability is a core requirement for this position. Equally important is the ability to build and maintain automation across SIEM, SOAR, security tooling, APIs, and analyst workflows. The engineer will also participate in security analyst activities as operational needs require, including alert investigation, incident response, threat hunting, detection engineering, and security platform support.
The ideal candidate is comfortable moving between offensive and defensive security: conducting an adversary simulation one day, developing automated investigation or response workflows the next, and supporting an active security investigation when needed.
ESSENTIAL DUTIES AND RESPONSIBILITIES
Red Team & Offensive SecurityPlan and execute authorized Red Team engagements that simulate realistic threat actors and attack paths. Conduct reconnaissance, exploitation, privilege escalation, lateral movement, persistence, and other adversary techniques within approved rules of engagement. Assess security controls across endpoints, identity platforms, networks, applications, cloud environments, and security infrastructure. Perform attack-path analysis and identify opportunities where multiple weaknesses can be combined to create material business risk. Develop and maintain offensive security tools, scripts, payloads, and testing infrastructure. Apply the MITRE ATT&CK framework to Red Team planning, execution, reporting, and detection validation. Test the organization’s ability to prevent, detect, investigate, and respond to adversary activity. Partner with Blue Team/Security Operations personnel to conduct purple-team exercises and improve defensive capabilities. Clearly document attack paths, evidence, business impact, control gaps, and recommended remediation. Validate remediation and control improvements through follow-up testing.
Security Automation & Engineering Identify repetitive or manual security processes and convert them into reliable automated workflows. Design, develop, maintain, and improve SIEM and SOAR automation supporting investigation, enrichment, containment, response, and case management. Build integrations between security platforms using APIs, webhooks, scripts, and other automation technologies. Develop automated enrichment workflows incorporating endpoint, identity, network, cloud, threat intelligence, vulnerability, and asset information. Automate common analyst activities such as indicator enrichment, alert triage, evidence collection, account investigation, endpoint investigation, case creation, notification, and response actions. Develop reusable scripts and tools using technologies such as Python, PowerShell, REST APIs, JSON, and Git-based development workflows. Implement appropriate testing, logging, error handling, documentation, access controls, and change management for security automation. Measure automation effectiveness, including analyst time saved, investigation time, response time, false-positive reduction, and workflow reliability. Continuously identify opportunities to reduce analyst workload while improving security coverage and response consistency.
Detection & Security Operations Translate Red Team activity and emerging adversary techniques into actionable detection opportunities. Perform detection validation and identify gaps between expected and actual security telemetry. Improve alert quality through tuning, enrichment, correlation, suppression, and automation. Conduct threat hunting based on adversary behaviors, threat intelligence, Red Team findings, and observed environmental risks.
Security Analyst & Incident Response ResponsibilitiesAs operational requirements dictate, this position will also perform security analyst responsibilities, including: Investigate security alerts and suspicious activity across endpoint, identity, network, email, cloud, and application environments. Perform alert triage, evidence collection, scoping, escalation, containment, and remediation activities. Support incident response investigations and coordinate technical response actions. Analyze endpoint, authentication, network, cloud, and other security telemetry. Investigate suspicious users, systems, processes, files, domains, IP addresses, and other indicators. Document investigations and maintain appropriate case records. Assist other security team members during significant incidents, high alert volumes, or other operational security events.
REQUIREMENTS Demonstrated hands-on experience performing Red Team, penetration testing, adversary simulation, or offensive security engineering. Strong understanding of attacker methodologies, attack paths, and post-exploitation techniques. Experience with Windows and Active Directory security, including common identity and privilege escalation attack techniques. Experience testing network, endpoint, identity, application, and/or cloud security controls. Working knowledge of the MITRE ATT&CK framework. Hands-on experience with offensive security tools and frameworks. Demonstrated scripting or software development experience, preferably with Python and/or PowerShell. Experience integrating systems through REST APIs, JSON, webhooks, or similar technologies. Experience with SOAR platforms or equivalent security workflow automation. Understanding of security operations, alert triage, incident investigation, and incident response processes. Ability to analyze security telemetry and distinguish legitimate activity from potentially malicious behavior. Experience using version control systems such as Git. Strong technical documentation and communication skills.
PREFERRED QUALIFICATIONS
Experience operating in both offensive security and Security Operations/Blue Team roles. Experience conducting purple-team exercises and translating offensive techniques into defensive detections. Experience with cloud security and offensive testing within AWS and Azure Experience with Microsoft Entra ID, Microsoft 365, or other modern identity platforms. Experience developing production-quality security automation or internal security tooling. Experience with infrastructure-as-code, CI/CD, containers, or other modern engineering practices. Experience working with EDR/XDR, vulnerability management, threat intelligence, email security, identity security, and network security technologies. Familiarity with detection engineering methodologies and detection-as-code. Relevant certifications such as OSCP, OSEP, CRTO, CRTP, GPEN, GXPN, GCIH, GCIA, or equivalent practical experience.

¿Es tuya esta vacante?

Reclámala gratis y recibe candidatos con video en CazVid.

Empleos similares