IT Exposure Management – Threat Analyst (Offensive Security)
Location: REMOTE [No Second Jobs]
Visa Type: H1B1 / / Citizen / OPT’s – No Sponsorship
Contact: /
Contact Name: Sri
Position Summary
The IT Exposure Management Threat Analyst – Offensive Security is responsible for identifying, validating, prioritizing, and helping remediate cybersecurity exposures across the organization's enterprise environment.
This is a hands-on offensive security role requiring practical experience with penetration testing, vulnerability validation, adversary techniques, attack-path analysis, Kali Linux, and automated security validation platforms.
The ideal candidate will have direct experience conducting traditional penetration testing and offensive security assessments using Kali Linux, along with hands-on experience using the Horizon3.ai NodeZero platform to continuously identify and validate exploitable attack paths.
The Threat Analyst will work closely with Exposure Management, SOC, Incident Response, Security Engineering, Network, Infrastructure, Cloud, Identity, and Application Security teams to reduce the organization's attack surface and overall cyber risk.
Key Responsibilities
Exposure Management & Attack Surface Analysis
- Identify, assess, validate, and prioritize security exposures across enterprise environments.
- Conduct continuous analysis of internal and external attack surfaces.
- Identify vulnerable assets, exposed services, misconfigurations, weak controls, excessive privileges, and exploitable conditions.
- Evaluate exposures based on exploitability, business criticality, asset value, threat intelligence, and potential impact.
- Correlate vulnerabilities with known exploits, active threats, and adversary techniques.
- Track security exposures from initial discovery through remediation and validation.
- Develop recommendations to reduce the organization's attack surface and improve security resilience.
Penetration Testing & Offensive Security
- Perform hands-on penetration testing and offensive security assessments within approved scope.
- Conduct traditional network, infrastructure, server, endpoint, Active Directory, and application penetration testing.
- Perform reconnaissance, enumeration, vulnerability identification, exploitation, privilege escalation, and post-exploitation activities as authorized.
- Validate whether identified vulnerabilities are actually exploitable rather than relying solely on scanner severity.
- Demonstrate potential attack paths and business impact using controlled proof-of-concept techniques.
- Identify opportunities for lateral movement, privilege escalation, persistence, and unauthorized access.
- Document technical findings and provide actionable remediation recommendations.
- Conduct remediation validation and retesting.
Kali Linux – Hands-On Offensive Security
- Use Kali Linux as a primary offensive-security testing environment.
- Perform hands-on reconnaissance, scanning, enumeration, exploitation, and security validation.
- Utilize tools such as:
- Nmap
- Burp Suite
- Metasploit
- Wireshark
- Netcat
- Responder
- Impacket
- BloodHound
- CrackMapExec / NetExec
- Gobuster
- Nikto
- Hashcat
- John the Ripper
- Develop and execute controlled testing workflows using multiple tools to validate complex attack paths.
- Perform manual testing in addition to automated vulnerability scanning.
- Use scripting and automation to improve repeatability and efficiency of security assessments.
Horizon3.ai / NodeZero
- Utilize Horizon3.ai NodeZero to perform autonomous security validation and identify exploitable attack paths.
- Configure and execute authorized NodeZero assessments across enterprise environments.
- Analyze NodeZero findings, attack paths, vulnerabilities, compromised credentials, privilege escalation opportunities, and lateral movement paths.
- Validate automated findings through manual testing where appropriate.
- Translate NodeZero attack-path findings into actionable remediation recommendations.
- Prioritize exposures based on demonstrated exploitability and potential business impact.
- Track remediation of NodeZero findings and perform follow-up validation.
- Use Horizon3.ai results to identify weaknesses in preventative and detective security controls.
- Collaborate with infrastructure, network, identity, and security engineering teams to eliminate validated attack paths.
Attack Path Analysis
- Analyze how individual vulnerabilities can be chained together to create a meaningful security risk.
- Identify potential paths from:
- Initial access
- Credential compromise
- Privilege escalation
- Lateral movement
- Domain/enterprise compromise
- Access to critical systems
- Use offensive-security techniques to validate high-risk attack paths.
- Identify excessive privileges, insecure trust relationships, weak authentication, vulnerable services, and network segmentation weaknesses.
- Recommend controls that break or eliminate attack paths.
Vulnerability Management & Risk Prioritization
- Analyze vulnerability scanner output and identify exposures requiring remediation.
- Validate high-risk vulnerabilities through authorized exploitation.
- Prioritize vulnerabilities using:
- CVSS
- CISA KEV
- Exploit availability
- Asset criticality
- Business impact
- Threat intelligence
- Actual exploitability
- Attack-path context
- Identify vulnerabilities that present immediate or material risk to the organization.
- Partner with infrastructure and application teams to establish remediation plans.
- Retest vulnerabilities after remediation.
Threat Intelligence
- Research emerging vulnerabilities, exploits, threat actors, malware, and attack techniques.
- Monitor CVE disclosures, CISA Known Exploited Vulnerabilities, vendor advisories, and exploit intelligence.
- Determine whether emerging vulnerabilities affect organizational assets.
- Translate threat intelligence into exposure-management priorities.
- Map vulnerabilities and attack techniques to the MITRE ATT&CK framework.
- Provide actionable threat intelligence to SOC and Incident Response teams.
Adversary Simulation & Security Validation
- Support authorized adversary emulation and purple-team exercises.
- Simulate realistic attacker behaviors to validate security controls.
- Test preventative and detective controls against known adversary techniques.
- Identify security-control gaps and detection weaknesses.
- Work with SOC and Security Engineering teams to improve detection and prevention capabilities.
- Document lessons learned and develop recommendations for improving defensive controls.
Security Engineering Collaboration
- Partner with Security Engineering to remediate validated security exposures.
- Work with Network Engineering to address segmentation and exposed-service risks.
- Collaborate with Identity teams to address excessive privileges, authentication weaknesses, and Active Directory exposures.
- Work with Cloud Security teams to identify cloud infrastructure and identity risks.
- Partner with Application Security teams on application and API vulnerabilities.
- Provide offensive-security expertise during architecture and security-control reviews.
Reporting & Documentation
- Produce detailed penetration testing and exposure-management reports.
- Clearly document:
- Vulnerability
- Attack vector
- Evidence
- Exploitability
- Attack path
- Business impact
- Risk rating
- Remediation recommendation
- Present technical findings to security and IT stakeholders.
- Translate highly technical offensive-security findings into business-oriented risk statements.
- Maintain testing procedures, methodologies, playbooks, and documentation.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent professional experience.
- 3–7+ years of hands-on experience in penetration testing, offensive security, vulnerability management, exposure management, or cybersecurity.
- Demonstrated practical experience conducting penetration tests, not solely vulnerability scanning.
- Strong hands-on experience with Kali Linux.
- Strong understanding of network, system, application, cloud, and identity security.
- Experience with vulnerability identification, exploitation, privilege escalation, and attack-path analysis.
- Experience validating vulnerabilities and determining real-world exploitability.
- Strong understanding of MITRE ATT&CK and common adversary tactics.
- Ability to work independently on security assessments and complex technical investigations.
Required / Preferred Platform Experience
Strongly Preferred
- Horizon3.ai NodeZero
- Kali Linux
- Penetration testing frameworks and methodologies
- Vulnerability management platforms
- Attack Surface Management / Exposure Management platforms
Preferred Tools & Technologies
- Nmap
- Burp Suite
- Metasploit
- BloodHound
- Impacket
- NetExec
- Responder
- Wireshark
- Hashcat
- John the Ripper
- Gobuster
- Nessus
- Qualys
- Rapid7
- Tenable
- Other enterprise exposure-management platforms
Infrastructure & Security Knowledge
- Active Directory
- Windows Server
- Linux
- TCP/IP
- DNS
- HTTP/HTTPS
- SMB
- LDAP/Kerberos
- Network security
- Firewalls
- VPN
- Cloud security
- Azure/AWS/Google Cloud Platform
- Identity and access management
- Web applications
- APIs
- Containers
- Endpoint security
Preferred Certifications
One or more of the following:
- OSCP – Offensive Security Certified Professional
- OSCE/OSED
- OSEP – Offensive Security Experienced Professional
- CRTO – Certified Red Team Operator
- GPEN – GIAC Penetration Tester
- GWAPT – GIAC Web Application Penetration Tester
- Google Cloud PlatformN – GIAC Cloud Penetration Tester
- CISSP
- CEH
- eJPT
- PNPT
- CompTIA Security+/CySA+
Key Competencies
- Offensive Security
- Penetration Testing
- Exposure Management
- Attack Surface Management
- Horizon3.ai NodeZero
- Kali Linux
- Vulnerability Validation
- Exploit Development / Exploitation
- Attack Path Analysis
- Red Team Techniques
- Adversary Simulation
- Threat Intelligence
- Active Directory Security
- Network Penetration Testing
- Web Application Security
- Cloud Security
- Identity Security
- MITRE ATT&CK
- Risk-Based Vulnerability Prioritization
- Security Control Validation
- Remediation Validation
- Technical Reporting
Success Measures
Success in this role will be measured by the ability to:
- Identify real-world exploitable exposures before threat actors can exploit them.
- Reduce the organization's attack surface.
- Discover and eliminate high-risk attack paths.
- Use Horizon3.ai NodeZero to continuously validate organizational security posture.
- Conduct effective manual penetration testing using Kali Linux and traditional offensive-security techniques.
- Improve vulnerability prioritization through demonstrated exploitability and business context.
- Validate remediation and confirm that security weaknesses have actually been eliminated.
- Identify gaps in preventative and detective security controls.
- Improve collaboration between offensive security, SOC, Incident Response, and Security Engineering teams.
Ideal Candidate Profile
The ideal candidate is a hands-on offensive security practitioner, not simply a vulnerability-management analyst.
They should be comfortable sitting down with Kali Linux and traditional penetration-testing tools, manually investigating and validating vulnerabilities, and then using Horizon3.ai NodeZero to continuously identify and demonstrate exploitable attack paths across the enterprise.
The candidate should think like an attacker while communicating like a security professional understanding how vulnerabilities can be chained together, how an adversary could move through an environment, what the actual business impact is, and what controls will effectively break the attack path.
Hands-on experience with Horizon3.ai NodeZero + Kali Linux + traditional penetration testing is strongly preferred.
Contact: /