1

Freelance Offensive Security Engineer Jobs in Michigan

Showing results 21-26

Freelance Offensive Security Engineer information

What is a freelance offensive security engineer?

Freelance Offensive Security Engineers are independent cybersecurity professionals who specialize in identifying and exploiting vulnerabilities within computer systems, networks, and applications. They are hired by organizations on a contract basis to conduct penetration testing, red teaming, and security assessments to help improve the organization's defenses. Unlike in-house employees, freelancers work for multiple clients and often bring a diverse range of experience from different industries. Their primary goal is to simulate real-world attacks and provide detailed reports with recommendations to enhance security posture.

What are the key skills and qualifications needed to thrive as a freelance offensive security engineer?

To thrive as a Freelance Offensive Security Engineer, you need deep expertise in penetration testing, vulnerability assessment, and cybersecurity best practices, often backed by certifications like OSCP or CEH. Familiarity with tools such as Metasploit, Burp Suite, Nmap, and scripting languages like Python is typically required. Strong problem-solving skills, self-motivation, and effective client communication set standout professionals apart in this field. These competencies are crucial for identifying and mitigating security risks while maintaining client trust and delivering high-value security assessments.

What are some common challenges faced by freelance offensive security engineers when working with multiple clients?

Freelance Offensive Security Engineers often juggle multiple projects for different clients, which can make time management and prioritization challenging. Each client may have unique security requirements, varying network environments, and distinct expectations for deliverables. Additionally, staying updated on the latest vulnerabilities and attack techniques is crucial, as clients rely on your expertise for thorough assessments. Clear communication and diligent documentation are essential to ensure that findings and recommendations are understood and actionable for each client.

What is the difference between Freelance Offensive Security Engineer vs Penetration Tester?

AspectFreelance Offensive Security EngineerPenetration Tester
CertificationsOSCP, CEH, OSWEOSCP, CEH, GPEN
Work EnvironmentProject-based, remote or on-site, client-specificTypically consulting, testing environments, often on-site or remote
Employer/Industry UsageFreelance, cybersecurity firms, consultingSecurity firms, internal security teams, consulting

Freelance Offensive Security Engineers and Penetration Testers both focus on identifying security vulnerabilities. However, Freelance Offensive Security Engineers often work on broader offensive security projects, including red teaming and security architecture, while Penetration Testers primarily conduct targeted vulnerability assessments. The roles overlap but differ in scope and depth of engagement.

What are the most commonly searched types of Offensive Security Engineer jobs in Michigan?

The most popular types of Offensive Security Engineer jobs in Michigan are:

What are popular job titles related to Freelance Offensive Security Engineer jobs in Michigan?

For Freelance Offensive Security Engineer jobs in Michigan, the most frequently searched job titles are:

What job categories do people searching Freelance Offensive Security Engineer jobs in Michigan look for?

The top searched job categories for Freelance Offensive Security Engineer jobs in Michigan are:

What cities in Michigan are hiring for Freelance Offensive Security Engineer jobs?

Cities in Michigan with the most Freelance Offensive Security Engineer job openings:

Cybersecurity Analyst (AWS Cloud Security)

Barton Malow

Southfield, MI

Full-time

Re-posted 24 days ago


Barton Malow rating

7.4

Company rating: 7.4 out of 10

Based on 10 frontline employees who took The Breakroom Quiz


Job description

Position Summary

The Cybersecurity Analyst is responsible for contributing to a variety of cybersecurity functions within the organization. This position is pivotal in maintaining and growing a proactive cybersecurity posture within the organization by promptly addressing security events, helping contribute to our cybersecurity roadmap, and ensuring that all stakeholders are well-informed about potential threats and preventive measures. The ideal candidate for this position is someone with a great technical foundation in cybersecurity, networking, and systems who is hungry to expand on their skills to contribute to an enterprise's overall cybersecurity program.

Key Job Responsibilities

  • Investigate and respond to tickets generated by the organization's Managed Detection and Response (MDR) provider.
  • Actively engage in incident response and root cause analysis. Participate in incident response activities to analyze and remediate cyber threats.
  • Perform internal security audits to assess the organization's security posture, identify potential weaknesses, and recommend corrective measures.
  • Monitor and assess the security of cloud environments (AWS), including review of IAM policies, roles, and permissions to enforce least-privilege access and identify misconfigurations or privilege escalation paths.
  • Analyze cloud security telemetry - including AWS CloudTrail, GuardDuty, Security Hub, CloudFormation Guard and CloudWatch - to detect, investigate, and respond to suspicious activity and policy violations.
  • Educate and raise awareness among the user community about various security threats, best practices, and measures to mitigate risk.
  • Prioritize risk reduction and remediation tasks to support a vulnerability management program.
  • Develop and maintain technical procedures and playbooks focused on incident handling.
  • Communicate effectively with technical and non-technical teams while working to improve overall cybersecurity effectiveness.
  • Participate in tabletop exercises designed to simulate potential cybersecurity incidents.
  • Conduct research, analysis, and correlation of events across a wide variety of data sources.
  • Demonstrate the ability to effectively leverage AI and LLMs to drive value while proactively identifying and mitigating emerging risks.

Required Knowledge, Education, Experience, Skills, And Abilities

  • Bachelor's degree in computer science, cybersecurity or related field or equivalent work experience.
  • 2-3 years of experience in security operations, vulnerability management, security engineering, incident response, or offensive security required.
  • Conceptual and technical knowledge of modern IT environments such as server configuration/architecture, cloud, database management/configuration, networking protocols/designs, and access management/access controls.
  • Working knowledge of AWS security fundamentals, including IAM (users, roles, policies, permission boundaries, and federation), the shared responsibility model, and core security services such as CloudTrail, GuardDuty, Security Hub, Config, and KMS.
  • Familiarity with cloud identity and access management concepts - least-privilege design, role assumption (STS), policy evaluation logic, and detecting over-permissioned or stale credentials.
  • Experience monitoring cloud environments for security events and correlating cloud logs with broader SIEM/MDR data sources is preferred.
  • Strong technical skills with knowledge of a wide variety of tools, and technologies, and experience deploying and monitoring these capabilities to identify cyber threats.
  • Knowledge of common cybersecurity frameworks and how to apply them, e.g., NIST 2.0 CSF, MITRE ATT&CK (including the ATT&CK Cloud matrix).
  • Demonstrated interpersonal skills and ability to work effectively and collaboratively with a wide range of stakeholders.
  • Demonstrated confidence and ease in delivering clear, effective verbal and written communication.
  • Experience in scripting and programming languages such as PowerShell, Bash, or Python is preferred.
  • Cybersecurity training or certifications from organizations such as CompTIA, TCM, SANS/GIAC, OffSec, ISC(2) is preferred; AWS certifications (e.g., AWS Certified Security - Specialty or Solutions Architect Associate) are a plus.

" This position is not eligible for visa sponsorship (e.g., H-1B). Applicants must be currently authorized to work in the United States on a permanent basis and reside within a reasonable commuting distance of Southfield, Michigan location." 


What Barton Malow employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom