Offensive Security Analyst
Provide security architecture expertise to assist with architecting and implementing security monitoring solutions and applications required to protect Liberty University โs networks and systems with a focus on penetration testing ESSENTIAL FUNCTIONS AND RESPONSIBILITIES
- Provide subject-matter expertise in web application security, advising teams on secure design, testing strategy, and risk mitigation.
- Perform advanced manual and automated web application penetration testing on internally developed applications to identify, validate, and prioritize security vulnerabilities.
- Contribute to the design, rollout, and continuous improvement of the internal penetration testing program.
- Standardize penetration testing methods, documentation, workflows, reporting templates, and scoping guidelines.
- Lead pre-engagement scoping sessions and collaborate with product teams to understand application architecture, functionality, and workflows.
- Deliver clear, actionable findings and effectively communicate vulnerabilities to developers with varying security skill levels.
- Partner with development teams to remediate issues, track findings, retest fixes, and ensure proper closure of vulnerabilities.
- Stay current on emerging exploitation techniques, vulnerabilities, and defensive controls.
- Support security incident investigations by documenting findings and evaluating the scope and impact of breaches to enable effective remediation and recovery.
- Provide strategic guidance and technical expertise to design solutions that address identified security gaps, ensuring recommendations align with organizational goals and strengthen overall security posture.
- Strictly adheres to Liberty University policies, representing the University in an exemplary manner.
- Works effectively as a team member, embracing and fostering LUโs Christian model and Mission โ Training Champions for Christ.
- 20%: Develop/Lead penetration testing practice for IT security at Liberty University
- 15%: Investigate and document security breaches; assess the damage they cause
- 10%: Help design and architect solutions to identify security gaps
- 10%: Provide strategic guidance for IT security technology implementation
- 10%: Support a risk and opportunity-based approach to security services to optimize business outcomes
- 10%: Assist and empower stakeholders to design and implement information security controls to meet control intent where no existing control or design patterns exist
- 10%: Consult with department directors and management regarding security incidents
- 10%: Drive security efficiency and capacity increases
- 5%: Collaborate with different key stakeholders/departments on project implementation
SUPERVISORY RESPONSIBILITIES
None
QUALIFICATIONS AND CREDENTIALS
Education and Experience
- A Bachelor's degree in Computer Science, Information Security, Information Systems, or related field required.
- 3-5 years' relevant security experience and fluency with at least one and experience with another of the following required: JavaScript, HTML, Python, Java, C#, PowerShell.
- Experience working with any/all of the following security technologies: penetration testing tools, network traffic analysis (NTA), security information event management (SIEM), network vulnerability scanners, web application firewalls (WAF), web application scanners (WAS), domain name service (DNS) security, data loss prevention (DLP), endpoint detection and response (EDR), email security, shared storage security, security orchestration, automation and response (SOAR), intrusion protection/detection systems (IPS/IDS).
- Preferred qualifications: GIAC technical certifications (GWAPT/GPEN/GRTP), CompTIA technical certifications (Security+/CySA+/PenTest+), Cloud certifications, experience with penetration testing, intrusion detection, vulnerability scanning, system integration, and poly-nimbus security concepts.
ABILITIES AND COMPETENCIES ESSENTIAL TO THE F