Offensive Security Engineer - Red / Purple Team

  • Brisbane or Sydney Based role
  • 12-month Contract
  • WFH – 3days in office and 2 days WFH

As an Offensive Security Engineer, you will Validates whether client controls, detection and logging actually catch real attacks and identifies and supports closing the gaps.
The role scopes, plans, manages and undertakes cyber hunt, penetration testing, red team, threat emulation and other technical security assurance activities across networks, applications, cloud services, end-user environments and enterprise platforms.


Responsibilities
  • Runs red and purple team engagements against critical apps, infrastructure and controls
  • Builds and maintains fit-for-purpose red team infrastructure
  • Validates controls, detection and logging; finds gaps and proves they are closed
  • Owns and matures Breach & Attack Simulation
  • Demonstrated experience planning, scoping and conducting penetration testing, cyber hunt, red team, threat emulation or similar technical security assurance activities across enterprise technology environments;
  • Strong technical knowledge of common vulnerability classes, exploitation methods, operating systems, networks, web applications, cloud services, security controls and the tools and methodologies used to assess them
  • Closes the loop: proposes remediation, new detections, log sources and controls; drives findings into the engineering backlog
  • Acts as the validation arm of threat-informed defence (ATT&CK-mapped)
Must-have
  • Hands-on offence: adversary emulation, C2, exploitation, attack-path analysis across cloud / infra / endpoint
  • Detection and logging fluency (the purple half)
  • BAS and ATT&CK
  • Python and automation; tight rules-of-engagement discipline
Bonus
  • AI coding / agentic tools (GPT-5.5 Trusted Access for Cyber, Codex, Claude Code, Copilot or similar) to find and prove exploitable vulns at repo scale
  • GitLab Ultimate; standing up AI-assisted code-analysis infrastructure
  • Detection engineering
  • Application / code security experience (SAST, DAST, SCA)

How to apply Applications are treated with absolute confidentiality. Click APPLY or contact Gary at [email protected] or an informal conversation about your next career move

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available