Offensive Security Analyst II
Deerfield Beach, FL - USA
Job Summary
Offensive Security Analyst II at JM Family Enterprises is responsible for designing building and scaling offensive security capabilities through adversaryfocused testing attack simulation and the development of custom tooling and automation.
They will support transformation of offensive security program from a predominantly tool and vendordriven model to a buildfirst approach leveraging software engineering automation and AIassisted techniques to improve the coverage depth and repeatability of offensive security activities.
Responsibilities include but are not limited to:
Conduct offensive security activities including penetration testing attack simulations threatbased assessments and control validation across onprem cloud identity and SaaS environments.
Execute and assist in the development of red team and purple team exercises collaborating with detection and response teams to validate defensive coverage.
Perform vulnerability and exploitation analysis including chaining weaknesses to demonstrate realworld attack paths and business risk.
Identify validate and responsibly disclose security weaknesses to stakeholders providing clear remediation guidance and risk context.
Design develop and maintain custom offensive security tooling (Python PowerShell Bash or similar) including frameworks reusable modules and automation that scale testing beyond pointintime assessments.
Evaluate when to build versus buy offensive security capabilities with a bias toward internal tooling where it improves flexibility visibility or speed of iteration.
Incorporate AIassisted techniques (e.g. automation chaining analysis signal prioritization) to increase testing efficiency and analyst leverage.
Contribute documentation such as test reports playbooks findings templates and executivelevel summaries.
Contribute to the longterm architecture of the offensive security program including shared libraries testing pipelines data models and reporting outputs optimized for reuse and scale.
Mentor junior analysts and contribute to team knowledge sharing.
Partner with application and platform engineering teams not only to test systems but to codesign secure patterns reference implementations and reusable testing components.
Build developerconsumable assets (templates scripts sample exploits safe test harnesses) that enable teams to selfvalidate security assumptions earlier in the SDLC.
Provide developerfriendly remediation guidance proofofconcepts and secure coding recommendations that are actionable and aligned to realworld development workflows.
Support the integration and tuning of security testing tools within CI/CD pipelines balancing detection depth with developer experience and signal quality.
Collaborate with Security Engineering and Application teams to improve selfservice security capabilities documentation and testing patterns that developers can reuse.
Participate in posttesting debriefs with developers to educate coach and improve security outcomesnot just report findings.
Qualifications:
Handson experience with penetration testing red team purple team or adversary emulation activities.
Strong understanding of Windows Active Directory Azure/Entra ID networking cloud platforms and SaaS architectures.
Experience with common offensive security tools and frameworks (e.g. C2 frameworks vulnerability scanners exploit frameworks).
Knowledge of MITRE ATT&CK kill chains and attacker tradecraft.
Experience validating security controls such as EDR SIEM identity protections email security and cloud security controls.
Strong scripting and automation skills; ability to customize or build tools to support testing objectives.
Ability to translate technical findings into clear riskbased narratives for technical and nontechnical audiences.
Strong analytical problemsolving and criticalthinking skills.
Ability to work independently while collaborating effectively in crossfunctional teams.
High attention to detail with a strong sense of ethics and responsible disclosure.
Experience working directly with software engineers to remediate vulnerabilities and improve secure development practices.
Understanding of modern SDLC and CI/CD pipelines including how security testing fits into developer workflows.
Familiarity with secure coding practices and common vulnerability classes in modern applications (web APIs cloudnative services).
Ability to communicate security findings in a way that developers can quickly understand prioritize and fix.
Mindset oriented toward enablement over enforcement with a focus on reducing friction while improving security outcomes.
Background in software engineering platform engineering or SRE with a desire to specialize in security.
Experience designing or maintaining productionquality code not just scripts.
Comfort working with APIs data pipelines CI/CD systems and cloudnative services as part of security capability development.
Curiosity and practical interest in applying AI/MLassisted techniques to security testing automation and analysis.
#LI-AM1
#LI-HYBRID
This job description may not be inclusive of all assigned duties responsibilities or aspects of the job described and may be amended at any time at the sole discretion of JM Family. All work arrangements are subject to associate performance business need and manager discretion and may be revised as necessary.
JM FAMILY IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER
JM Family Enterprises Inc. is an Equal Employment Opportunity employer. We are committed to recruiting hiring retaining and promoting qualified associates without regard any characteristic protected by law whether actual or perceived including race color creed religion national origin ancestry citizenship status age sex or gender (including pregnancy childbirth related medical conditions and lactation) gender identity gender expression sexual orientation marital status military service veteran status disability protected medical condition as defined by applicable state or local law genetic information or any other characteristic protected by applicable federal state provincial or local law.
DISABILITY ACCOMMODATIONS
If you have a disability and require a reasonable accommodation to complete the job application process please contact JM Familys Talent Acquisition department at for assistance. If you have an accommodation request for one of our recruiting events please notify us at least 72 hours prior so that we may provide assistance.
Required Experience:
IC
About Company
Jim Moran's passion for selling cars continues with JM Family. We build strong relationships with customers, partners and communities.