B

Offensive Security Specialist

BULLIT MANAGEMENT SERVICES LIMITED

Brisbane, Queensland, Australia · Full Time

Be the first to apply

Experience
Any
Salary
—
Openings
1
Posted
5 days ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

This position involves conducting offensive security operations encompassing adversary simulation, command and control (C2) activities, exploitation tactics, and attack path assessments across cloud, infrastructure, and endpoint environments. The role incorporates both offensive and defensive aspects, requiring expertise in detection and logging methodologies aligned with purple team activities. Candidates will engage in breach and attack simulation (BAS) strategies, leveraging the MITRE ATT&CK framework and scripting automation in Python within governed engagement protocols.

Key Responsibilities

  • Execute comprehensive red and purple team exercises targeting essential applications, infrastructure components, and security controls.
  • Design, implement, and sustain tailored red team operative infrastructures.
  • Assess and confirm the efficacy of security controls, detection capabilities, and logging mechanisms, while uncovering and validating any vulnerabilities to ensure resolution.
  • Lead initiatives in Breach & Attack Simulation processes, continuously evolving maturity.
  • Employ artificial intelligence to enhance the scale and precision of attack-path analysis, focusing remediation efforts effectively.
  • Develop and recommend remediation strategies including novel detection signatures, additional log source integration, and control enhancements, facilitating incorporation into engineering workflows.
  • Serve as a verification authority for threat-informed defense tactics mapped to ATT&CK, validating whether existing monitoring systems effectively detect authentic cyberattacks and identifying actionable gaps.

Required Expertise

  • Practical experience with offensive security operations such as adversary emulation, command and control management, exploitation, and security attack path analysis across multiple environments (cloud, infrastructure, endpoints).
  • Proficiency in detection tuning and logging analysis within purple team frameworks.
  • Knowledge and application of Breach & Attack Simulation methodologies alongside the MITRE ATT&CK framework.
  • Strong Python programming skills and automation of offensive procedures, adhering to rigorous rules of engagement.

Desirable Skills

  • Development using AI-based coding and agentic platforms (e.g., GPT-5.5 Trusted Access for Cyber, Codex, Claude Code, Copilot) to identify and demonstrate vulnerabilities at the repository scale.
  • Experience with GitLab Ultimate and establishing AI-supported code analysis pipelines.
  • Background in detection engineering and security validation.
  • Application security expertise, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).

Industry

Cybersecurity

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer