Jobs · Information Technology

Lead Information Security Analyst

Burtch Works · United States · 5 days ago
RemoteRemoteInformation TechnologyFull-time
Job Title: Lead Information Security Analyst Location: Remote, United States About The Company Our client is a large, highly regulated financial services organization with a long-standing commitment to helping individuals and families achieve financial clarity and confidence. They continue to invest in technology, cybersecurity, and risk management capabilities and offer an environment where experienced security professionals can influence enterprise security strategy, partner across technical and business teams, and help strengthen organizational resilience. Job Summary We are looking for a Lead Information Security Analyst - Red Team / Offensive Security to join our client's Information Security Risk Management team. The ideal candidate is a senior-level, hands-on adversary emulation professional with deep offensive security expertise and strong analytical judgment. This role will identify, validate, and safely exploit vulnerabilities, determine how individual weaknesses can be chained into realistic attack paths, and define which findings represent the greatest real-world risk. The successful candidate will combine technical offensive testing with risk-based prioritization, clear remediation guidance, and effective communication with technical teams and leadership. Key Responsibilities Adversary Emulation: Plan, scope, and execute internal red team engagements and targeted penetration tests in alignment with the client's Penetration Testing Program and Rules of Engagement. Emulate real-world adversaries to test security controls, detection capabilities, and defensive operations. Offensive Testing & Validation: Perform reconnaissance, scanning, enumeration, exploitation, and post-exploitation analysis using established offensive tooling and frameworks such as NIST SP 800-115, the OWASP Testing Guide, and MITRE ATT&CK. Validate scanner findings, confirm true exploitability, eliminate false positives, and safely demonstrate impact through non-destructive techniques. Vulnerability Chaining & Criticality Elevation: Analyze discrete vulnerabilities and misconfigurations to determine how they can be combined into multi-stage attack paths or 'gadget chains.' Document how lower-severity findings can collectively create High or Critical exposure through privilege escalation, lateral movement, data access, or other material business impact. Risk-Based Prioritization: Review the active vulnerability landscape and recalibrate effective criticality based on exploitability, chainability, exploit maturity, asset exposure, privileged or Tier-0/1 access, and business impact. Serve as a technical decision authority on which vulnerabilities require expedited remediation. Reporting, Guidance & Purple Team Collaboration: Produce clear attack narratives, prioritized findings, and actionable remediation guidance for technical teams and executive stakeholders. Immediately escalate critical vulnerabilities, mentor less-experienced analysts, and partner with SOC and defensive teams to improve detection coverage. AI-Assisted Offensive Security: Apply AI/LLM-based tools such as Copilot, Claude, ChatGPT, or comparable models to accelerate vulnerability research, exploit analysis, attack-path identification, proof-of-concept development, testing scripts, payload refinement, and reporting. Maintain sound technical validation and judgment when using AI-generated outputs. Adversarial AI Awareness: Understand emerging adversarial uses of AI and AI-enabled attack techniques and incorporate relevant scenarios into authorized adversary-emulation activities. Requirements Education: Bachelor's degree in Computer Science, Information Security, Mathematics, a related field, or equivalent experience. Experience: Typically 5 or more years of applicable offensive security, red team, penetration testing, or closely related experience. Skills: Demonstrated hands-on expertise with offensive tooling and exploitation frameworks; proven ability to validate and safely exploit vulnerabilities; experience chaining multiple vulnerabilities into realistic, high-impact attack paths; strong understanding of vulnerability management, CVSS, and risk-based prioritization; and demonstrated proficiency using AI tools and techniques to identify, validate, and chain current vulnerabilities. Communication: Excellent written and verbal communication skills, including the ability to translate complex offensive-security findings into clear, actionable guidance for technical teams and executive stakeholders. Leadership: Ability to operate with sound judgment in ambiguous situations, challenge assumptions, influence cross-functional partners, mentor less-experienced analysts, and drive measurable improvements in security posture and resilience. Preferred Qualifications Certifications: Offensive security certifications such as OSCP, OSEP, OSWE, GXPN, GPEN, CRTO, or equivalent. Industry Experience: Experience working within a regulated financial services environment such as banking or insurance. Technical Breadth: Familiarity with AWS and Azure, Active Directory attack paths, container or host escape techniques, purple teaming, and improving SOC/EDR detection coverage. AI & Automation: Experience integrating AI and automation into offensive-security workflows, including research, vulnerability validation, attack-path analysis, proof-of-concept development, and reporting. Benefits Competitive Salary: Compensation will be discussed based on experience and engagement structure. Health and Wellness: Comprehensive benefits are available based on employment and engagement structure. Work-Life Balance: Remote work environment with flexibility appropriate to the role and business needs. Professional Development: Opportunity to expand offensive-security expertise while influencing a developing enterprise security program. Additional Perks: Opportunity to work with experienced cybersecurity professionals in a highly regulated enterprise environment and contribute directly to security strategy and

Similar jobs