IT Exposure Management Threat Analyst (Offensive Security) Location: REMOTE [No Second Jobs] Visa Type: H1B1 / / Citizen / OPT's No Sponsorship Contact: OpenKyber Contact Name: OpenKyber Position Summary The IT Exposure Management Threat Analyst Offensive Security is responsible for identifying, validating, prioritizing, and helping remediate cybersecurity exposures across the organization's enterprise environment. This is a hands-on offensive security role requiring practical experience with penetration testing, vulnerability validation, adversary techniques, attack-path analysis, Kali Linux, and automated security validation platforms. The ideal candidate will have direct experience conducting traditional penetration testing and offensive security assessments using Kali Linux, along with hands-on experience using the Horizon3.ai NodeZero platform to continuously identify and validate exploitable attack paths. The Threat Analyst will work closely with Exposure Management, SOC, Incident Response, Security Engineering, Network, Infrastructure, Cloud, Identity, and Application Security teams to reduce the organization's attack surface and overall cyber risk.
Key Responsibilities:Required Qualifications Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent professional experience. 3 7+ years of hands-on experience in penetration testing, offensive security, vulnerability management, exposure management, or cybersecurity. Demonstrated practical experience conducting penetration tests, not solely vulnerability scanning. Strong hands-on experience with Kali Linux. Strong understanding of network, system, application, cloud, and identity security. Experience with vulnerability identification, exploitation, privilege escalation, and attack-path analysis. Experience validating vulnerabilities and determining real-world exploitability. Strong understanding of MITRE ATT&CK and common adversary tactics. Ability to work independently on security assessments and complex technical investigations.
Required / Preferred Platform Experience Strongly Preferred Horizon3.ai NodeZero Kali Linux Penetration testing frameworks and methodologies Vulnerability management platforms Attack Surface Management / Exposure Management platforms
Preferred Tools & Technologies Nmap Burp Suite Metasploit BloodHound Impacket NetExec Responder Wireshark Hashcat John the Ripper Gobuster Nessus Qualys Rapid7 Tenable
Other enterprise exposure-management platforms Infrastructure & Security Knowledge Active Directory Windows Server Linux TCP/IP DNS SMB LDAP/Kerberos Network security Firewalls VPN Cloud security Azure/AWS/Google Cloud Platform Identity and access management Web applications APIs Containers Endpoint security
Preferred Certifications One or more of the following: OSCP Offensive Security Certified Professional OSCE/OSED OSEP Offensive Security Experienced Professional CRTO Certified Red Team Operator GPEN GIAC Penetration Tester GWAPT GIAC Web Application Penetration Tester Google Cloud PlatformN GIAC Cloud Penetration Tester CISSP CEH eJPT PNPT CompTIA Security+/CySA+
Key Competencies Offensive Security Penetration Testing Exposure Management Attack Surface Management Horizon3.ai NodeZero Kali Linux Vulnerability Validation Exploit Development / Exploitation Attack Path Analysis Red Team Techniques Adversary Simulation Threat Intelligence Active Directory Security Network Penetration Testing Web Application Security Cloud Security Identity Security MITRE ATT&CK Risk-Based Vulnerability Prioritization Security Control Validation Remediation Validation Technical Reporting
Success Measures Success in this role will be measured by the ability to: Identify real-world exploitable exposures before threat actors can exploit them. Reduce the organization's attack surface. Discover and eliminate high-risk attack paths. Use Horizon3.ai NodeZero to continuously validate organizational security posture. Conduct effective manual penetration testing using Kali Linux and traditional offensive-security techniques. Improve vulnerability prioritization through demonstrated exploitability and business context. Validate remediation and confirm that security weaknesses have actually been eliminated. Identify gaps in preventative and detective security controls. Improve collaboration between offensive security, SOC, Incident Response, and Security Engineering teams.
Ideal Candidate Profile The ideal candidate is a hands-on offensive security practitioner, not simply a vulnerability-management analyst. They should be comfortable sitting down with Kali Linux and traditional penetration-testing tools, manually investigating and validating vulnerabilities, and then using Horizon3.ai NodeZero to continuously identify and demonstrate exploitable attack paths across the enterprise. The candidate should think like an attacker while communicating like a security professional understanding how vulnerabilities can be chained together, how an adversary could move through an environment, what the actual business impact is, and what controls will effectively break the attack path. Hands-on experience with Horizon3.ai NodeZero + Kali Linux + traditional penetration testing is strongly preferred.
For applications and inquiries, contact:hirings@openkyber.com
...Michael J. Fitzmaurice South Dakota Veterans Home. For more information on the Department of Veteran's Affairs, please visit .The Accounting Assistant acts as a paraprofessional to accounting and fiscal professionals by performing assigned accounting practices to assist...
Overview The Physical Therapist Assistant evaluates and treats patients with a wide range of rehabilitative needs, including orthopedic... ...Level Field of Study Associate's Degree Physical Therapy Assistant Licenses/Certifications Licensed Physical Therapist...
...Job DescriptionThe Shin Lab at the Fralin Biomedical Research Institute (VTC, Virginia Tech Carilion) is seeking a full-time Research Assistant to support neuroscience projects and oversee daytoday laboratory operations. This professional research position is an excellent...
...ECS is seeking a Sr. Elastic Engineer to work in our Springfield, VA office.Please Note: This position is contingent upon additional funding.Are you passionate about building and scaling Elastic environments and eager to make an immediate technical impact? Join ECS,...
...Cloud Architect Location: Chicago, IL (Hybrid) Duration: 6-12 Months Requirements: ~ BS in Engineering, Information Technology... ..., Rancher, Kubernetes, Azure Kubernetes Service, Amazon EKS, Google GKE ~ Design and maintain hybrid, cloud infrastructure for...