Enable job alerts via email!

Offensive Security Analyst

S-RM

Cape Town

On-site

ZAR 40 000 - 80 000

Full time

7 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking Offensive Security Analysts to enhance their cybersecurity services. In this dynamic role, you will engage with clients, perform penetration testing, and help build cyber resilience. Your expertise will contribute to innovative solutions that address evolving security risks. This position offers an exciting opportunity to work across various pentesting services, collaborate with experienced teams, and develop your professional skills in a supportive environment. Join a forward-thinking company committed to becoming trusted advisors in the cybersecurity landscape.

Qualifications

  • Experience in penetration testing and vulnerability assessments.
  • Strong understanding of cybersecurity frameworks and threat landscapes.

Responsibilities

  • Engage with clients to understand cybersecurity challenges and propose solutions.
  • Perform penetration testing and deliver findings in various formats.

Skills

Penetration Testing
Vulnerability Assessments
Client Engagement
Threat Intelligence
Open Source Intelligence (OSINT)
Project Management

Education

Bachelor's Degree in Cybersecurity or related field

Tools

Web Application Testing Tools
Phishing Testing Tools
Mobile Application Testing Tools

Job description

Offensive Security Analysts support our delivery consultants in running our offensive security services. They help interpret client challenges, innovate solutions, and deliver findings. Our aim is to become trusted advisors to our clients.

You will work across the full spectrum of our pentesting services, whether point-in-time or continuous, and participate in larger engagements such as red teams. You will help our clients build cyber resilience, enhance their understanding of the threat landscape, and become better prepared to face dynamic and evolving security risks.

1.1 MAIN DUTIES AND RESPONSIBILITIES

Client Engagement and Account Management

  • Engage with clients to understand their cybersecurity challenges.
  • Translate client challenges into solutions that fit SRMs Offensive Security service offerings and value proposition.
  • Develop an understanding of delivery timelines, project resourcing requirements, and pricing.
  • Understand SRMs proposal process and lead on proposal writing and presentations in some cases.
  • Contribute to the expansion of client accounts and the winning of new business.
  • Gain an understanding of SRMs target sectors and industries.

Offensive Security

  • Perform penetration testing.

Vulnerability assessments and monitoring

  • External infrastructure
  • External Attack Surface Management
  • Web application testing
  • Phishing and spear phishing testing
  • Mobile application pentesting (Android and iOS)
  • Open Source Intelligence (OSINT) gathering
  • Configuration reviews
  • Application configuration review
  • Hardware build review
  • Firewall review

Deliver findings in various formats, including written reports, presentations, and verbal briefings.

Stay updated on threat intelligence developments, threat actor activity, and security industry advancements in mitigations and tooling.

  • Develop and deliver client threat profiles, threat assessments, and dark web analysis.

Project Management

  • Support vCISO engagements by accessing SRMs resources and expertise.
  • Collaborate with incident response, ethical hacking, and digital forensics teams to integrate services and support clients.
  • Support the delivery of retainer relationships.
  • Support the delivery of the Attack Surface Management (ASM) service.

Internal Initiatives and Strategy

  • Support internal initiatives on product development, process management, tech enablement, and exploring ways to support clients.
  • Contribute to adapting security frameworks to create innovative products.
  • Challenge existing products and services; suggest alternative approaches where appropriate.

Develop documentation and evolve testing methodologies where applicable.

Professional Development and Domain Knowledge

  • Commit to continuous professional development and expanding cybersecurity knowledge in line with personal utilization targets.
  • Complete up to one formal training course annually beyond internal sessions.
  • Share knowledge with the team, including contributing to internal training initiatives and programs.

Required Experience:

Key Skills

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.