JM Family
Offensive Security Analyst II
Florida - Deerfield Beach · Mid
Sponsorship not specifiedDetected 30 days ago
PythonBashPowerShellAzureCloud PlatformsCI/CDSite Reliability EngineeringPlatform EngineeringMachine LearningData EngineeringCybersecurityPenetration TestingSIEM
About the role
- All work arrangements are subject to associate performance, business need and manager discretion, and may be revised as necessary.
- JM FAMILY IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER JM Family Enterprises, Inc. is an Equal Employment Opportunity employer.
Responsibilities
- Perform vulnerability and exploitation analysis, including chaining weaknesses to demonstrate real‑world attack paths and business risk.
- Identify, validate, and responsibly disclose security weaknesses to stakeholders, providing clear remediation guidance and risk context.
- Design, develop, and maintain custom offensive security tooling (Python, PowerShell, Bash, or similar), including frameworks, reusable modules, and automation that scale testing beyond point‑in‑time assessments.
- Evaluate when to build versus buy offensive security capabilities, with a bias toward internal tooling where it improves flexibility, visibility, or speed of iteration.
- Partner with application and platform engineering teams not only to test systems, but to co‑design secure patterns, reference implementations, and reusable testing components.
- Build developer‑consumable assets (templates, scripts, sample exploits, safe test harnesses) that enable teams to self‑validate security assumptions earlier in the SDLC.
- Support the integration and tuning of security testing tools within CI/CD pipelines, balancing detection depth with developer experience and signal quality.
- Offensive Security Analyst II at JM Family Enterprises is responsible for designing, building, and scaling offensive security capabilities through adversary‑focused testing, attack simulation, and the development of custom tooling and automation.
- Collaborate with Security Engineering and Application teams to improve self‑service security capabilities, documentation, and testing patterns that developers can reuse.
Requirements
- Hands‑on experience with penetration testing, red team, purple team, or adversary emulation activities.
- Strong understanding of Windows, Active Directory, Azure/Entra ID, networking, cloud platforms, and SaaS architectures.
- Experience with common offensive security tools and frameworks (e.g., C2 frameworks, vulnerability scanners, exploit frameworks).
- Knowledge of MITRE ATT&CK, kill chains, and attacker tradecraft.
- Experience validating security controls such as EDR, SIEM, identity protections, email security, and cloud security controls.
- Ability to translate technical findings into clear risk‑based narratives for technical and non‑technical audiences.
- Ability to work independently while collaborating effectively in cross‑functional teams.
- Experience working directly with software engineers to remediate vulnerabilities and improve secure development practices.
- Familiarity with secure coding practices and common vulnerability classes in modern applications (web, APIs, cloud‑native services).
- Ability to communicate security findings in a way that developers can quickly understand, prioritize, and fix.
- Strong scripting and automation skills
- ability to customize or build tools to support testing objectives.
- Strong analytical, problem‑solving, and critical‑thinking skills.
- High attention to detail with a strong sense of ethics and responsible disclosure.
- Understanding of modern SDLC and CI/CD pipelines, including how security testing fits into developer workflows.
Benefits
- Execute and assist in the development of red team and purple team exercises, collaborating with detection and response teams to validate defensive coverage.
Visa & Work Authorization
- tic protected by law – whether actual or perceived – including race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth, related medical conditions
Apply directly at JM Family →Create a free account for alerts like thisView JM Family immigration profile
This listing is sourced directly from JM Family's careers page and normalized into a canonical job model.