Offensive Security Specialist | Cyber Security

Visteon Corporation

Palmela

Presencial

EUR 90 000 - 120 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Visteon Corporation in Palmela, Portugal, is seeking an experienced Offensive Security Specialist to lead red team operations and penetration testing across our global infrastructure, applications, cloud environments, and endpoints.

The role reports to the CISO and partners with SOC, GRC, and engineering teams to continuously strengthen our security posture through adversarial simulations, KPI tracking, and actionable remediation recommendations.

Qualificações

  • 5–10+ years of progressive experience in offensive security.
  • Hands-on expertise across the full attack lifecycle (network/infrastructure exploitation, web app testing).
  • Strong knowledge of MITRE ATT&CK framework and attacker TTPs.
  • Experience leading security teams, hiring, mentoring, and performance management.
  • Cloud environments (Azure, AWS, GCP) and AD/Azure AD attack paths.
  • Experience with AV/EDR evasion techniques and tooling development in Python or C.
  • Ability to produce clear, impactful technical and executive security reports.
  • Excellent communication and stakeholder management for senior leadership.

Responsabilidades

  • Design, plan, and execute advanced red team operations against Visteon environments.
  • Conduct comprehensive penetration testing across internal/external infrastructure, web and mobile apps, cloud, and endpoints.
  • Develop and maintain a red team program including rules of engagement and reporting frameworks.
  • Produce high‑quality technical and executive reports with remediation guidance.
  • Collaborate with SOC and GRC to improve detection and response capabilities.
  • Define and track KPIs; drive continuous improvement of the offensive security program.

Conhecimentos

Penetration testing
Red teaming
Threat modelling
MITRE ATT&CK
Team leadership
Cloud security
AD/Azure AD attack paths
Python/C tooling
C2 operations
Network/infrastructure exploitation
Executive reporting
Stakeholder management

Ferramentas

Metasploit
Impacket
Cobalt Strike
Burp Suite
BloodHound
Rubeus
Python
C
Azure AD
Windows/Linux

Descrição da oferta de emprego

Visteon is a global automotive technology leader, advancing mobility through innovative technology solutions that enable a software‑defined future. The company’s state‑of‑the‑art product portfolio merges digital cockpit innovations, advanced displays, AI‑enhanced software solutions, and integrated EV architecture solutions. With expertise spanning passenger vehicles, commercial transportation, and two‑wheelers, Visteon partners with global automakers to create safer, cleaner, and more connected journeys. Founded in 2000, the company employs 10,000 employees in 18 countries.

Mission of the role

Visteon is looking for an experienced Offensive Security Specialist to spearhead our red team operations and penetration testing capabilities. Reporting directly to the CISO, this hands‑on leadership role is responsible for proactively identifying and exploiting vulnerabilities across Visteon’s global infrastructure, applications, and systems – before adversaries do. The Offensive Security Lead will partner with defensive and governance teams to continuously strengthen our security posture.

Key Objectives of the Role
  • Design, plan, and execute advanced red team operations simulating sophisticated real‑world threat actors against Visteon’s environments.
  • Conduct and oversee comprehensive penetration testing across internal and external infrastructure, web and mobile applications, cloud environments, and endpoints.
  • Develop and maintain a red team program, including rules of engagement, campaign planning, reporting frameworks, and remediation tracking.
  • Produce high‑quality technical and executive‑level reports that clearly articulate risk, findings, and actionable remediation recommendations.
  • Collaborate closely with the Security Operations and Cyber Defense team to improve detection and response capabilities through adversarial simulation.
  • Stay current with the latest offensive security techniques, tools, CVEs, and threat actor TTPs; translate findings into actionable improvements.
  • Define and track KPIs and metrics for the offensive security program and report findings to the CISO.
  • Drive continuous improvement of the overall security posture by partnering with architecture, engineering, and GRC teams.
  • Support and contribute to vulnerability management processes, including prioritization based on exploitability and business impact.
Key Performance Indicators (KPIs)
  • Red Team Coverage: at least two full red team engagements executed per year, covering critical infrastructure, applications, and cloud environments.
  • Penetration Test Throughput: all agreed penetration tests delivered on schedule, with high and critical findings reported to stakeholders within 24 hours of identification.
  • Remediation Validation: 90%+ of critical and high findings re‑tested and verified as remediated within agreed SLA windows.
  • Detection Improvement: measurable increase in blue team detection coverage for simulated TTPs, tracked per engagement via a purple team feedback loop.
  • Report Quality: executive and technical reports rated as "meets or exceeds expectations" by stakeholders for clarity, actionability, and accuracy.
  • Programme Maturity: year‑on‑year improvement in red team programme maturity, including tooling, methodology, and rules of engagement.
Key Year‑One Deliverables
  • Within 30 days: conduct a thorough assessment of Visteon’s existing offensive security capabilities, tooling, prior findings, and threat landscape; establish relationships with the SOC, GRC, and other stakeholders.
  • Within 90 days: define and publish the red team programme charter including rules of engagement, engagement templates, and reporting standards; execute first internal penetration test and deliver findings to the CISO.
  • Within 6 months: complete the first full red team engagement simulating a realistic threat actor scenario; establish a purple team feedback loop with the Security Operations team; build or adapt at least one custom offensive tool or capability tailored to Visteon’s environment.
  • Within 12 months: deliver a comprehensive offensive security programme report to the CISO covering all engagements, risk trends, remediation status, and year‑two roadmap; demonstrate measurable improvement in detection coverage attributable to red team activity.
Qualifications, Experience, and Skills
  • 5–10+ years of progressive experience in offensive security, penetration testing, or red teaming.
  • Proven hands‑on expertise across the full attack lifecycle – including network and infrastructure exploitation (Metasploit, Impacket), C2 operations (Cobalt Strike or equivalent), web application testing (Burp Suite, OWASP Top 10), Active Directory and Azure AD attack paths (BloodHound, Rubeus), and custom tooling/payload development in Python or C.
  • Deep understanding of attacker TTPs, MITRE ATT&CK framework, and red team methodologies.
  • Experience leading and managing security teams, including hiring, mentoring, and performance management.
  • Strong knowledge of network protocols, operating systems (Windows, Linux), and cloud environments (Azure, AWS, GCP).
  • Experience with AV/EDR evasion techniques and the ability to develop or adapt tooling to bypass modern endpoint defenses.
  • Demonstrated ability to produce clear, impactful technical and executive‑level security reports.
  • Excellent communication and stakeholder management skills, with experience presenting to senior leadership.
Preferred Qualifications
  • Experience with adversary simulation platforms and C2 (Command & Control) frameworks.
  • Familiarity with DevSecOps practices and application security testing in CI/CD pipelines.
  • Experience in a global, multi‑site enterprise environment.
  • Background in automotive, manufacturing, or OT/ICS environments is a plus.
  • Exposure to physical security assessments or social engineering engagements.
  • Experience working in or alongside SOC/blue team functions to improve detection coverage.
Key Behaviors
  • Evaluating Problems
  • Critical Thinking (Investigating Issues)
  • Collaboration (Building Relationships)
  • Communicating Information
  • Showing Resilience
  • Demonstrating Global Mindset
  • Processing Details
  • Driving Success
Reporting Structure
  • Reports to: Chief Information Security Officer (CISO)
  • Location: Palmela, Portugal
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Lead Red Team Offensive Security Specialist
Lead Red Team Offensive Security Specialist

Visteon Corporation • Palmela

Presencial
EUR 90 000 - 120 000
Offensive Security Manager (Penetration Testing | Red Team | Adversary Simulation)
Offensive Security Manager (Penetration Testing | Red Team | Adversary Simulation)

Thales • Maia

Presencial
EUR 70 000 - 90 000
Competitive compensation package
Continuous learning environment
Flexible working model
Devoteam Cyber Trust | Product Engineer – Security Platform
Devoteam Cyber Trust | Product Engineer – Security Platform

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 48 000 - 72 000
Penetration Tester / Red Team Analyst
Penetration Tester / Red Team Analyst

Inetum • Portugal

Híbrido
EUR 30 000 - 50 000
Devoteam Cyber Trust | Application Security Engineer | Mobility Sector
Devoteam Cyber Trust | Application Security Engineer | Mobility Sector

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 45 000 - 65 000
Devoteam Cyber Trust | Application Security - Lead | Banking Sector
Devoteam Cyber Trust | Application Security - Lead | Banking Sector

Devoteam • Portugal

Presencial
EUR 40 000 - 60 000
Red Team Consultant
Red Team Consultant

Inetum • Portugal

Híbrido
EUR 50 000 - 70 000
Cybersecurity Analyst Junior
Cybersecurity Analyst Junior

faurecia S.A. • Espargo

Presencial
EUR 22 000 - 33 000
Cybersecurity Engineer
Cybersecurity Engineer

VisionSpace • Figueira da Foz

Presencial
EUR 60 000 - 100 000
Devoteam Cyber Trust | Cyber Security Engineer
Devoteam Cyber Trust | Cyber Security Engineer

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 35 000 - 60 000
Equal opportunity employer
Diversity-focused workplace