Cybersecurity Analyst, Offensive Security

LUMA Energy

San Juan (PR)

On-site

USD 110,000 - 150,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

LUMA Energy is seeking a Senior Red Team professional to lead offensive security engagements across IT, cloud, and OT/ICS environments in Puerto Rico. You will simulate adversaries, develop tools, and deliver actionable findings to strengthen defenses.

The role emphasizes collaboration with Blue Team and Threat Intelligence, plus adherence to RoE and regulatory requirements. A strong security mindset is essential.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology required or equivalent experience.
  • 3–6 years of offensive security, penetration testing, or Red Teaming experience.
  • Experience with cloud environments (AWS, Azure) and OT/ICS systems preferred.
  • Relevant certifications like OSCP, OSCE, GPEN, or CRTO are desired.

Responsibilities

  • Plans, executes, and leads Red Team engagements and adversary emulation within RoE.
  • Performs full-spectrum offensive operations to assess detection and response capabilities.
  • Conducts social engineering campaigns to test human vulnerabilities and awareness.
  • Executes OT/ICS assessments while preventing operational disruption.
  • Contributes to Purple Team exercises to validate detection and prevention controls.
  • Develops custom offensive tools and scripts to enhance Red Team operations.
  • Documents findings with clear remediation guidance for risk reduction.
  • Collaborates with Blue Team, Threat Intelligence, and IT/OT teams to translate insights into defenses.
  • Maintains expertise on emerging threats relevant to the energy sector.

Skills

Penetration Testing
Red Team
Cloud Security
OT/ICS Security
Social Engineering

Education

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology

Tools

Kali Linux
Metasploit
Burp Suite
Cobalt Strike
BloodHound
Nmap

Job description

Job Summary:

Leads and executes full‑scope Red Team operations to identify vulnerabilities across IT, cloud, and OT/ICS environments and evaluate organizational detection and response readiness. Translates offensive insights into measurable defensive improvements by conducting realistic adversary simulations, developing specialized tools, and delivering clear, actionable findings.

Job Description:
  • Plans, executes, and leads Red Team engagements, adversary emulation, and penetration testing across OT/ICS environments to evaluate organizational resilience within approved Rules of Engagement (RoE).

  • Performs full-spectrum offensive operations using real-world TTPs to assess and challenge detection and response capabilities.

  • Conducts social engineering campaigns (phishing, vishing, physical) to test human factors vulnerabilities and improve security awareness.

  • Executes OT/ICS assessments, follow formal safe-testing protocols and cross-team coordination to prevent operational disruption and protect critical infrastructure.

  • Participates in Purple Team exercises to validate and improve detection, response, and prevention controls

  • Develops custom offensive tools, and scripts, to enhance Red Team capabilities and automate operational processes

  • Documents technical findings with clear impact and remediation guidance to support informed decisions and drive measurable risk reduction.

  • Collaborates with Blue Team, Threat Intelligence, and IT/OT teams to translate offensive insights into actionable defensive improvements

  • Maintain expertise on emerging threats, techniques, and tools relevant to the energy sector to ensure engagements reflect current and realistic adversary behaviors.

  • Supports vulnerability assessments and after-hours operations to improve continuous threat exposure management and maintain Red Team Readiness

  • Follows established company policies, procedures, and standards to ensure full compliance with applicable laws and industry regulations.

  • Participates in storm restoration tasks and assigned drills to contribute to the safe and reliable recovery of services.

  • Performs additional tasks aligned with role expectations and qualifications to support team goals and operational flexibility.

Additional Job Description:
Education
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology.
Experience
  • 3-6 years of experience in offensive security, penetration testing, or Red Teaming.

  • Experience with cloud environments (AWS, Azure) and modern enterprise/OT systems.

Additional experience may substitute for required education when it aligns with the competencies and knowledge necessary for the role:

  • Associate’s degree in Cybersecurity, Computer Science, Information Technology may substitute when accompanied by a minimum of 5 years of experience in offensive security, penetration testing, or Red Teaming and at least 3 years of experience performing a previous Analyst role.

  • High School or equivalent (GED) when accompanied by a minimum of 8 years of experience in offensive security, penetration testing, or Red Teaming and at least 5 years of experience performing a previous Analyst role.

Competencies (Skills)
  • Advanced Offensive Security Expertise – Demonstrates deep hands‑on proficiency with penetration testing and Red Team tools (Kali Linux, Metasploit, Burp Suite, Cobalt Strike, BloodHound, Nmap) and scripting languages (Python, PowerShell, Bash) to execute realistic adversary simulations.

  • Adversary Techniques & Framework Mastery – Applies extensive knowledge of MITRE ATT&CK, OWASP Top 10, and common attack vectors across network, web, cloud, identity, and OT environments to conduct targeted offensive operations.

  • OT/ICS Security & Safe ‑ Testing Practices – Utilizes strong working knowledge of IC… (full text continues as in original)

  • Analytical, Reporting, and Communication Skills – Synthesizes complex technical findings into clear, accurate reports with business-impact context and actionable remediation guidance, delivering information effectively to both technical and non-technical audiences.

  • Collaboration & Cross ‑ Functional Integration – Works effectively with Blue Team, Threat Intelligence, IT, and OT partners to translate offensive insights into defensive improvements and contribute to Purple Team exercises.

  • Ethical Standards & Confidentiality – Maintains high ethical principles and exercises proper judgment when handling sensitive information, demonstrating reliability and trustworthiness in all offensive security activities.

  • Bilingual Fluency – Communicates clearly and professionally in both Spanish and English to coordinate with diverse teams across multiple environments.

Licenses/Certifications
  • At least one relevant certification: OSCP, OSCE, CRTO, GPEN, or equivalent
Travel Requirements
  • No
Physical Demands
  • Stationary Position: Constantly

  • Pushing/ Pulling/ Reaching: Seldom

  • Kneel: Seldom

  • Grab: Seldom

  • Bend: Seldom

  • Lift/Carry over: 0 – 15 pounds

Working Conditions
  • Wet or humid: Seldom

  • Working near or on moving mechanical parts: Never

  • Working near or on heavy machinery: Never

  • Working in high places: Never

  • Exposed to fumes or airborne particles: Never

  • Frequency of working in outdoor weather conditions: Never

  • Work with electricity: Never

  • Loud noise conditions: Seldom

LUMA Energy is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, military status, disability, or any other characteristic protected by federal or local laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Defense Specialist
Cyber Defense Specialist

LUMA Energy • San Juan (PR)

On-site
USD 95,000 - 130,000
Senior System Security Specialist
Senior System Security Specialist

Compunnel, Inc. • Baltimore (MD)

On-site
USD 120,000 - 150,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Red Team Operator
Red Team Operator

SoTalent • United States

On-site
USD 100,000 - 130,000
Competitive compensation and performance incentives
Comprehensive health and wellness benefits
401(k) with employer match
+3
Security Engineer II - Offensive Track
Security Engineer II - Offensive Track

Flywire1 • Boston (MA)

On-site
USD 110,000 - 150,000
Offensive Cyber Operations Lead
Offensive Cyber Operations Lead

WorkNovas LLC • Tampa (FL)

Hybrid
USD 140,000 - 190,000
Junior Offensive Cyber Security Specialist
Junior Offensive Cyber Security Specialist

Kids for the Future • Tampa (FL)

On-site
USD 70,000 - 100,000
Security Engineer II
Security Engineer II

Healthcare Outcomes Performance Co. (HOPCo) • Phoenix (AZ)

On-site
USD 120,000 - 170,000
Cybersecurity Technologist
Cybersecurity Technologist

Exxon Mobil • Spring (TX)

On-site
USD 140,000 - 230,000
Pension Plan
Savings Plan
Workplace Flexibility
+2