Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Elastic Security Engineer

Openkyber

IT Exposure Management Threat Analyst (Offensive Security) Location: REMOTE [No Second Jobs] Visa Type: H1B1 / / Citizen / OPT's No Sponsorship Contact: OpenKyber Contact Name: OpenKyber Position Summary The IT Exposure Management Threat Analyst Offensive Security is responsible for identifying, validating, prioritizing, and helping remediate cybersecurity exposures across the organization's enterprise environment. This is a hands-on offensive security role requiring practical experience with penetration testing, vulnerability validation, adversary techniques, attack-path analysis, Kali Linux, and automated security validation platforms. The ideal candidate will have direct experience conducting traditional penetration testing and offensive security assessments using Kali Linux, along with hands-on experience using the Horizon3.ai NodeZero platform to continuously identify and validate exploitable attack paths. The Threat Analyst will work closely with Exposure Management, SOC, Incident Response, Security Engineering, Network, Infrastructure, Cloud, Identity, and Application Security teams to reduce the organization's attack surface and overall cyber risk. Key Responsibilities:

  • Exposure Management & Attack Surface Analysis Identify, assess, validate, and prioritize security exposures across enterprise environments. Conduct continuous analysis of internal and external attack surfaces. Identify vulnerable assets, exposed services, misconfigurations, weak controls, excessive privileges, and exploitable conditions. Evaluate exposures based on exploitability, business criticality, asset value, threat intelligence, and potential impact. Correlate vulnerabilities with known exploits, active threats, and adversary techniques. Track security exposures from initial discovery through remediation and validation. Develop recommendations to reduce the organization's attack surface and improve security resilience.
  • Penetration Testing & Offensive Security Perform hands-on penetration testing and offensive security assessments within approved scope. Conduct traditional network, infrastructure, server, endpoint, Active Directory, and application penetration testing. Perform reconnaissance, enumeration, vulnerability identification, exploitation, privilege escalation, and post-exploitation activities as authorized. Validate whether identified vulnerabilities are actually exploitable rather than relying solely on scanner severity. Demonstrate potential attack paths and business impact using controlled proof-of-concept techniques. Identify opportunities for lateral movement, privilege escalation, persistence, and unauthorized access. Document technical findings and provide actionable remediation recommendations. Conduct remediation validation and retesting.
  • Kali Linux Hands-On Offensive Security Use Kali Linux as a primary offensive-security testing environment. Perform hands-on reconnaissance, scanning, enumeration, exploitation, and security validation. Utilize tools such as: Nmap, Burp Suite, Metasploit, Wireshark, Netcat, Responder, Impacket, BloodHound, CrackMapExec, NetExec, Gobuster, Nikto, Hashcat, John the Ripper. Develop and execute controlled testing workflows using multiple tools to validate complex attack paths. Perform manual testing in addition to automated vulnerability scanning. Use scripting and automation to improve repeatability and efficiency of security assessments.
  • Horizon3.ai / NodeZero Utilize Horizon3.ai NodeZero to perform autonomous security validation and identify exploitable attack paths. Configure and execute authorized NodeZero assessments across enterprise environments. Analyze NodeZero findings, attack paths, vulnerabilities, compromised credentials, privilege escalation opportunities, and lateral movement paths. Validate automated findings through manual testing where appropriate. Translate NodeZero attack-path findings into actionable remediation recommendations. Prioritize exposures based on demonstrated exploitability and potential business impact. Track remediation of NodeZero findings and perform follow-up validation. Use Horizon3.ai results to identify weaknesses in preventative and detective security controls. Collaborate with infrastructure, network, identity, and security engineering teams to eliminate validated attack paths.
  • Attack Path Analysis Analyze how individual vulnerabilities can be chained together to create a meaningful security risk. Identify potential paths from: Initial access, Credential compromise, Privilege escalation, Lateral movement, Domain/enterprise compromise, Access to critical systems. Use offensive-security techniques to validate high-risk attack paths. Identify excessive privileges, insecure trust relationships, weak authentication, vulnerable services, and network segmentation weaknesses. Recommend controls that break or eliminate attack paths.
  • Vulnerability Management & Risk Prioritization Analyze vulnerability scanner output and identify exposures requiring remediation. Validate high-risk vulnerabilities through authorized exploitation. Prioritize vulnerabilities using: CVSS, CISA KEV, Exploit availability, Asset criticality, Business impact, Threat intelligence, Actual exploitability, Attack-path context. Identify vulnerabilities that present immediate or material risk to the organization. Partner with infrastructure and application teams to establish remediation plans. Retest vulnerabilities after remediation.
  • Threat Intelligence Research emerging vulnerabilities, exploits, threat actors, malware, and attack techniques. Monitor CVE disclosures, CISA Known Exploited Vulnerabilities, vendor advisories, and exploit intelligence. Determine whether emerging vulnerabilities affect organizational assets. Translate threat intelligence into exposure-management priorities. Map vulnerabilities and attack techniques to the MITRE ATT&CK framework. Provide actionable threat intelligence to SOC and Incident Response teams.
  • Adversary Simulation & Security Validation Support authorized adversary emulation and purple-team exercises. Simulate realistic attacker behaviors to validate security controls. Test preventative and detective controls against known adversary techniques. Identify security-control gaps and detection weaknesses. Work with SOC and Security Engineering teams to improve detection and prevention capabilities. Document lessons learned and develop recommendations for improving defensive controls.
  • Security Engineering Collaboration Partner with Security Engineering to remediate validated security exposures. Work with Network Engineering to address segmentation and exposed-service risks. Collaborate with Identity teams to address excessive privileges, authentication weaknesses, and Active Directory exposures. Work with Cloud Security teams to identify cloud infrastructure and identity risks. Partner with Application Security teams on application and API vulnerabilities. Provide offensive-security expertise during architecture and security-control reviews.
  • Reporting & Documentation Produce detailed penetration testing and exposure-management reports. Clearly document: Vulnerability, Attack vector, Evidence, Exploitability, Attack path, Business impact, Risk rating, Remediation recommendation. Present technical findings to security and IT stakeholders. Translate highly technical offensive-security findings into business-oriented risk statements. Maintain testing procedures, methodologies, playbooks, and documentation.

Required Qualifications Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent professional experience. 3 7+ years of hands-on experience in penetration testing, offensive security, vulnerability management, exposure management, or cybersecurity. Demonstrated practical experience conducting penetration tests, not solely vulnerability scanning. Strong hands-on experience with Kali Linux. Strong understanding of network, system, application, cloud, and identity security. Experience with vulnerability identification, exploitation, privilege escalation, and attack-path analysis. Experience validating vulnerabilities and determining real-world exploitability. Strong understanding of MITRE ATT&CK and common adversary tactics. Ability to work independently on security assessments and complex technical investigations.

Required / Preferred Platform Experience Strongly Preferred Horizon3.ai NodeZero Kali Linux Penetration testing frameworks and methodologies Vulnerability management platforms Attack Surface Management / Exposure Management platforms

Preferred Tools & Technologies Nmap Burp Suite Metasploit BloodHound Impacket NetExec Responder Wireshark Hashcat John the Ripper Gobuster Nessus Qualys Rapid7 Tenable

Other enterprise exposure-management platforms Infrastructure & Security Knowledge Active Directory Windows Server Linux TCP/IP DNS SMB LDAP/Kerberos Network security Firewalls VPN Cloud security Azure/AWS/Google Cloud Platform Identity and access management Web applications APIs Containers Endpoint security

Preferred Certifications One or more of the following: OSCP Offensive Security Certified Professional OSCE/OSED OSEP Offensive Security Experienced Professional CRTO Certified Red Team Operator GPEN GIAC Penetration Tester GWAPT GIAC Web Application Penetration Tester Google Cloud PlatformN GIAC Cloud Penetration Tester CISSP CEH eJPT PNPT CompTIA Security+/CySA+

Key Competencies Offensive Security Penetration Testing Exposure Management Attack Surface Management Horizon3.ai NodeZero Kali Linux Vulnerability Validation Exploit Development / Exploitation Attack Path Analysis Red Team Techniques Adversary Simulation Threat Intelligence Active Directory Security Network Penetration Testing Web Application Security Cloud Security Identity Security MITRE ATT&CK Risk-Based Vulnerability Prioritization Security Control Validation Remediation Validation Technical Reporting

Success Measures Success in this role will be measured by the ability to: Identify real-world exploitable exposures before threat actors can exploit them. Reduce the organization's attack surface. Discover and eliminate high-risk attack paths. Use Horizon3.ai NodeZero to continuously validate organizational security posture. Conduct effective manual penetration testing using Kali Linux and traditional offensive-security techniques. Improve vulnerability prioritization through demonstrated exploitability and business context. Validate remediation and confirm that security weaknesses have actually been eliminated. Identify gaps in preventative and detective security controls. Improve collaboration between offensive security, SOC, Incident Response, and Security Engineering teams.

Ideal Candidate Profile The ideal candidate is a hands-on offensive security practitioner, not simply a vulnerability-management analyst. They should be comfortable sitting down with Kali Linux and traditional penetration-testing tools, manually investigating and validating vulnerabilities, and then using Horizon3.ai NodeZero to continuously identify and demonstrate exploitable attack paths across the enterprise. The candidate should think like an attacker while communicating like a security professional understanding how vulnerabilities can be chained together, how an adversary could move through an environment, what the actual business impact is, and what controls will effectively break the attack path. Hands-on experience with Horizon3.ai NodeZero + Kali Linux + traditional penetration testing is strongly preferred.

For applications and inquiries, contact:View email address on us.fitly.work

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Elastic Security Engineer in Atlanta, GA vacancy
  •  ...Embedded Systems Security Engineer Onsite in Foster City, CA | 5 days in office We are looking for an Embedded Systems Security Engineer to implement security solution to harden our next-generation embedded Linux platform. In this role, you will bridge the gap between... 
    Suggested
    Permanent employment
    Contract work
    Work at office

    Openkyber

    Atlanta, GA
    2 days ago
  •  ...Role : Security Engineer Location : Charlotte, Dallas (Hybrid) OpenKyber Role Summary Security Engineer with strong expertise in CNAPP (Wiz/Prisma), cloud security, and ETL data control validation. Responsible for end-to-end validation of security controls across ETL pipelines... 
    Suggested

    Openkyber

    Atlanta, GA
    2 days ago
  • Job DescriptionJob OverviewThe Security Engineer is responsible for the secure configuration, hardening, and ongoing operation of the AGS security control set and the systems those controls protect. The role ensures that documented security policy and technical standards... 
    Suggested
    Work experience placement

    AGS

    Atlanta, GA
    2 days ago
  •  ...description:Come join a growing team that is responsible for the design/engineering/operation of the following foundational infrastructure...  ...established strategies and patterns.Performs threat modeling, security testing, and penetration testing for the platforms and... 
    Suggested
    Permanent employment
    Full time
    Part time
    Work experience placement
    H1b
    Work at office
    Remote work
    Work visa
    Shift work
    Day shift

    Truist

    Atlanta, GA
    2 days ago
  •  ...high-performing, inclusive, and collaborative environment where you can be your best, every day.Job Summary:The Senior Network Security Engineer provides dedicated engineering capacity to accelerate Newell Brands network segmentation buildout and materially reduce... 
    Suggested
    Shift work

    Newell Brands

    Atlanta, GA
    1 day ago
  • Job DescriptionJob OverviewThe Senior Security Engineer is the senior technical implementer on the AGS security team, responsible for executing and maintaining the enterprise security control set in support of the security program strategy, roadmap, and standards set by... 
    Work experience placement

    AGS

    Atlanta, GA
    4 days ago
  •  ...thing—today and for generations to come. Job Purpose and Impact The Network Engineer - SASE will implement, operate, automate, and continuously improve Cargill's global Secure Access Service Edge (SASE) and Security Service Edge (SSE) services. This role will support... 
    Work experience placement
    Remote work

    Cargill

    Atlanta, GA
    20 hours ago
  • $10 per hour

     ...business, society, and the environment? Come join us. All security disciplines work under the umbrella of the combined PSI (Platform...  ...) team: we build the paved path and tooling that hundreds of engineers around the world rely on every day to ship. Corporate Security... 
    Work at office
    Immediate start
    Flexible hours

    Flexport

    Atlanta, GA
    3 days ago
  •  ...Identity and Access Management Engineer – Officer (IAM Security Engineer)Location: Boston and Quincy, MA and Austin, TX, Atlanta Georgia, Princeton or Clifton NJ, Berwyn, PA, Stamford CT.MoI: Video with Possible F2FClient is Cyber Identity and Access Management is looking... 

    InterSources

    Atlanta, GA
    3 days ago
  •  ...Senior Security EngineerImmediate need for a talented Senior Security Engineer. This is a 12+months contract opportunity with long-term potential and is located in Atlanta, GA (Onsite). Please review the job description below and contact me ASAP if you are interested.... 
    Contract work
    Local area
    Immediate start

    Pyramid Corporation

    Atlanta, GA
    1 day ago
  •  ...Senior Security EngineerImmediate need for a talented Senior Security Engineer. This is a 12+ Months Contract opportunity with long-term potential and is located in Atlanta, GA. Please review the job description below and contact me ASAP if you are interested.Job ID:24... 
    Contract work
    Local area
    Immediate start

    Pyramid Consulting

    Atlanta, GA
    3 days ago
  • $150k - $251.9k

     ...We are growing rapidly and hiring top talent with leading AI skills across engineering, sales, product, marketing, and beyond as we build the leading digital operations platform..Senior Security Engineer — Cloud Security (Platform, Identity & Cryptography)PagerDuty is seeking... 
    Work at office
    Local area
    Flexible hours
    2 days per week

    PagerDuty

    Atlanta, GA
    14 hours ago
  • $198k - $368k

     ...and others. If you're as passionate about your future as we are, join our team.KPMG is currently seeking a Director, Global Security Engineering Lead to join our Global Digital Group which is part of KPMG International.Responsibilities:Own the engineering architecture,... 
    H1b
    Local area

    KPMG

    Atlanta, GA
    4 days ago
  •  ...Job Description Job Description Work Location: Fully Remote. Our direct client has an opening for an Security Engineer rec 13810 This position is up to 12 months, with the option of extension the position will be located in Columbia,SC Please send... 
    Remote work

    FHR

    Atlanta, GA
    8 days ago
  •  ...environmental impact while maximizing resource efficiency. As we continue to expand and innovate, we are seeking an experienced Security Engineer to design, implement, and operate the security controls that protect our people, systems, and operational technology across a... 
    Live out

    BrightFarms Inc

    Atlanta, GA
    a month ago
  •  ...SUMMARY: Implements, configures, monitors, and manages the internal cyber environment to ensure operational availability and security. Accountable for the day-to-day health and performance of cyber security tools and products. Accountable for all stages in asset management... 
    Permanent employment
    Temporary work
    For contractors
    Work experience placement
    For subcontractor
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours

    Georgia's Own Credit Union

    Atlanta, GA
    a month ago
  •  ...Senior PKI Security Engineer Atlanta, GA (Hybrid) GA Locals Preferred, Relocation is OK 13+ Years must Must-Needed Skills * Cyber Security * Public Key Infrastructure (PKI) * AWS PKI Services – KMS, CloudHSM, ACM, CloudFront, Secrets Manager, CloudTrail... 
    Temporary work
    Local area
    Relocation

    Delan Associates, Inc

    Atlanta, GA
    more than 2 months ago
  • $10 per hour

     ...tier-1 queue here. Detection & Response engineers own their detections end to end: you write...  ...your team is paged when they fire. The security team is spread across the globe with a...  ...modern SIEM or detection pipeline (Panther, Elastic, Splunk, or similar). What matters is... 
    Work at office
    Local area
    Immediate start
    Relocation
    Relocation package
    Flexible hours

    Flexport

    Atlanta, GA
    6 days ago
  • $72.2k - $96.4k

     ...effectively, ultimately enabling the achievement of company goals. Help Shape the Future of Enterprise Security We're looking for an Information Security Engineer to join our team in Atlanta. In this early-career role, you'll gain hands-on experience with modern... 
    Full time
    Apprenticeship
    Internship
    Local area
    Worldwide
    Flexible hours

    Dolby Laboratories, Inc.

    Atlanta, GA
    a month ago
  • Position Description & Qualifications Are you an Information System Security Engineer (ISSE) looking for a place where you can make an impact every day? Serco is the place for you! Join our Defense team supporting our CNIC program in this exciting role based out of Naples... 
    Full time
    Contract work
    Part time
    Interim role
    Local area
    Flexible hours

    Serco

    Atlanta, GA
    3 days ago
  • $218.4k - $365.2k

     ...are the future of Salesforce.We are seeking a transformative security leader who can evolve Slack's security posture from protecting...  ...agents are first-class actors. As Senior Director of Security Engineering, you will lead a globally distributed security organization and... 
    Full time
    Shift work

    Salesforce

    Atlanta, GA
    1 day ago
  • $105.4k - $207.8k

    Position Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking... 
    Work experience placement
    Local area
    Remote work

    Deloitte

    Atlanta, GA
    1 day ago
  • $111.64k - $186.06k

     ...first AI-driven digital work platform, built to support flexible, secure, work-from anywhere experiences. We integrate industry-leading...  ...? This is a hands-on application security role for an engineer who can own well-scoped work and deliver it independently. You’... 
    Work experience placement
    Work at office
    Local area
    Remote work
    Worldwide
    Visa sponsorship
    Flexible hours
    3 days per week

    Omnissa, LLC in

    Atlanta, GA
    3 days ago
  • $200k - $275k

     ...exceptional talent to meet the complex needs of our clients in a fast-paced and dynamic legal landscape. We are seeking a skilled Security Architect to design, implement, and oversee security solutions that protect our organization’s infrastructure, applications, and data... 
    Full time
    Work at office
    Local area
    Worldwide
    Flexible hours

    King & Spalding

    Atlanta, GA
    2 days ago
  •  ...Required)Work Shift:1st shift (United States of America)Please review the following job description:Manages large, technical information security projects, programs, and processes aligned with organizational goals and regulatory requirements. Conducts advanced threat analysis... 
    Full time
    Part time
    Shift work
    Day shift

    Truist

    Atlanta, GA
    20 hours ago
  •  ...Job Description Job Description Cloud Security Engineer Location: Atlanta, GA Employment Type: Full Time Position Overview: We are seeking an experienced and detail-oriented Cloud Security Engineer to join our team in Atlanta, GA. This hybrid role... 
    Full time
    Remote work

    TIER4 GROUP

    Atlanta, GA
    a month ago
  • $100k - $110k

     ...Senior Cloud Security Engineer (L2) ~202603592 ~Atlanta, Georgia, United States ~United States ~Full time View favourites Description The Sr. Cloud Security Engineer plays a key role in securing the organization’s multi-cloud environment by enhancing... 
    Full time
    Temporary work
    Local area
    Visa sponsorship
    Work visa
    Flexible hours

    WTW

    Atlanta, GA
    more than 2 months ago
  •  ...have on the food service industry. There's a seat at our table for you... Position Summary Position Summary: The Cloud Security Engineer defines, documents, and implements infrastructure and application security best practices and standards in the cloud. Integrates... 
    Work at office
    Remote work
    Monday to Friday

    Intercity Packers Ltd.

    Atlanta, GA
    3 days ago
  •  ...range of IT expertise addresses our clients’ needs by providing industry leading, state-of-the-art information technology and cyber security services and solutions. We focus on delivering business solutions that exceed our customers’ vision, mission, and long-term... 
    Contract work
    Local area

    Xtreme Solutions Corporate

    Atlanta, GA
    17 days ago
  • Junior Penetration Tester Anywhere Type: Contract-to-Hire Category: Security Industry: Government Workplace Type: Remote Standard Hours: Open Reference ID: JN -092026-108605 Date Posted: 09/15/2026 Shortcut: Description Recommended Jobs Description: Remote... 
    Hourly pay
    Permanent employment
    Contract work
    Local area
    Remote work

    Eliassen Group

    Atlanta, GA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Elastic Security Engineer. Be the first to apply!