Offensive Security Engineer - Red / Purple Team

Bluefin Resources · Brisbane QLD 4000 · Contract
Posted 17d ago

Offensive Security Engineer - Red / Purple Team

Bluefin Resources
$253k - $278k
$1000 - $1100 per day
Bluefin Resources Logo
KEY POINTS WE FOUND
  • Conduct red and purple team engagements against critical applications and infrastructure.
  • Validate controls, detection, and logging to identify and close security gaps.
  • Utilise offensive security techniques including penetration testing and threat emulation.

  • Global renewable energy leader
  • Exposure to stakeholders across APAC
  • Sydney CBD - High Impact role
  • Brisbane or Sydney Based role
  • 12-month Contract
  • WFH – 3days in office and 2 days WFH

 
As an Offensive Security Engineer, you will Validates whether client controls, detection and logging actually catch real attacks and identifies and supports closing the gaps.
The role scopes, plans, manages and undertakes cyber hunt, penetration testing, red team, threat emulation and other technical security assurance activities across networks, applications, cloud services, end-user environments and enterprise platforms.
 
 
Responsibilities

  • Runs red and purple team engagements against critical apps, infrastructure and controls
  • Builds and maintains fit-for-purpose red team infrastructure
  • Validates controls, detection and logging; finds gaps and proves they are closed
  • Owns and matures Breach & Attack Simulation
  • Demonstrated experience planning, scoping and conducting penetration testing, cyber hunt, red team, threat emulation or similar technical security assurance activities across enterprise technology environments;
  • Strong technical knowledge of common vulnerability classes, exploitation methods, operating systems, networks, web applications, cloud services, security controls and the tools and methodologies used to assess them
  • Closes the loop: proposes remediation, new detections, log sources and controls; drives findings into the engineering backlog
  • Acts as the validation arm of threat-informed defence (ATT&CK-mapped)

Must-have

  • Hands-on offence: adversary emulation, C2, exploitation, attack-path analysis across cloud / infra / endpoint
  • Detection and logging fluency (the purple half)
  • BAS and ATT&CK
  • Python and automation; tight rules-of-engagement discipline

Bonus

  • AI coding / agentic tools (GPT-5.5 Trusted Access for Cyber, Codex, Claude Code, Copilot or similar) to find and prove exploitable vulns at repo scale
  • GitLab Ultimate; standing up AI-assisted code-analysis infrastructure
  • Detection engineering
  • Application / code security experience (SAST, DAST, SCA)

 
How to apply Applications are treated with absolute confidentiality. Click APPLY or contact Gary at gary@bluefinresources.com.au or an informal conversation about your next career move

Consultant

Gary@bluefinresources.com.au

Reference number: BH-62726
Profession:ICTSecurity / Cyber Security

Company: Bluefin Resources
Date posted: 24th Aug, 2026

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 40 matched
AdaptableAdversary emulationAdversary emulation platformsAi coding / agentic toolsAi-assisted code analysisApplication security (sast, dast, sca)Att&ck frameworkAttack path analysisAutomationBreach & attack simulation (bas)C2 (command and control)Cloud infrastructure securityCloud securityCode analysis infrastructureCyber huntCybersecurity frameworksDastDetection and loggingDetection engineeringExploit developmentGitlabNetwork securityNetwork security protocolsOperating systems securityPenetration testingProblem solvingPythonRed team operationsSastScaSecurity controlsSecurity controls validationSecurity infrastructure automationStakeholder engagementTeamworkThreat emulationTime managementVulnerability assessmentWeb application securityWeb application security testing

Bluefin Resources

Bluefin Resources Logo

More details

Expiring date
Offensive Security Engineer - Red / Purple Team | Bluefin Resources | HIA