Rejobs
NextEra Energy

Principal Offensive Security Analyst

成为NextEra Energy在佛罗里达州棕榈滩花园的首席进攻安全分析师。该职位涉及进行渗透测试、红队操作,并与各个团队合作以改善网络安全措施。享受一个支持性的工作环境和职业成长机会。

NextEra Energy

公司概况

NextEra Energy

美国佛罗里达州朱诺海滩

1984年

商业模式

能源

可再生能源的生产和分配

电力销售、可再生能源证书、基础设施投资

地点与地理

美国、加拿大、巴西、墨西哥、英国

公司文化

他们的使命是推动可再生能源的使用,以实现可持续的未来。

他们提供一个包容和多样化的工作环境,鼓励创新和团队合作。

他们重视员工的职业发展,提供培训和晋升机会。

活动与项目

他们正在进行多个大型风能和太阳能项目,以增加可再生能源的产量。

他们致力于开发新技术,以提高能源效率和可再生能源的利用率。

他们实施了多项可持续发展计划,旨在减少碳足迹。

职业机会

他们通常招聘工程师、项目经理和技术人员等职位。

他们提供竞争力的薪资、健康保险和退休计划。

联系信息

LinkedIn

在NextEra Energy的职业机会


最后更新于 2025-09-06 | 报告问题

NextEra Energy is seeking an experienced Offensive Security Analyst with exceptional hands-on technical skills and a strong background in utilizing red team toolsets. This role is crucial for conducting tactical offensive operations and adapting to evolving tools and methods. You will complement our existing team, recognized for their strategic planning and intelligence analysis capabilities, by providing practical, on-keyboard expertise in offensive security and threat emulation.

  • Penetration Testing: Perform comprehensive tests on enterprise systems, including on-premises and cloud environments (AWS/Azure).
  • Red Team Operations: Emulate adversary tactics to test organizational defenses, develop and use custom tools for Windows environments, and provide detailed post-exploitation reporting.
  • Collaboration & Coordination:
    • Work closely with the Vulnerability Management team to contextualize risks and prioritize remediation efforts.
    • Partner with the Threat Hunting Team to investigate signs of further exploitation following red team operations.
    • Participate in purple team exercises to enhance organizational detection and response capabilities.
  • Automation & Tool Development: Automate security tasks, manage product security testing, and create scripts or utilities to streamline repeatable processes.
  • Detection Strategies: Develop strategies to identify and respond to security threats using the kill chain model, leveraging both manual and automated approaches.
  • Solid experience in network security testing and penetration.
  • Working knowledge of Unix/Linux and Windows systems from an attacker perspective.
  • Familiarity with common ICS/SCADA architecture, including the unique separation between operational technology (OT) and traditional information technology (IT) systems.
  • Penetration Testing & Red Team Skills
    • Proficiency using common penetration testing and red team tools.
    • Web application security (OWASP Top Ten), mobile security testing, IoT devices, wireless networks.
    • Deep familiarity with advanced red teaming frameworks (Atomic Red Team, MITRE Caldera, Pentera).
    • Any GIAC (or other relevant) certifications, such as GPEN, GWAPT, GXPN, GREM, etc.
    • Demonstrable passion for learning and staying abreast of emerging tactics, techniques, and procedures (TTPs).
    • Hands-on experience in SCADA or ICS beyond a foundational level.
    • Understanding of regulatory requirements (e.g., NERC CIP) for industrial environments.

Job Overview

This job performs ongoing cybersecurity risk reviews for new and existing technologies and services and supports ongoing and new cybersecurity projects. Individuals develop requirements for and implement technical security projects and tools, as well as define the company's cybersecurity policies and control framework. This position collaborates with the company's IT department and business units to identify the need for, select, and deploy technical controls to meet specific security requirements. Employees in this role build processes and standards to ensure security requirements continue to be met.

Job Duties & Responsibilities

  • Administers, operates and monitors NextEra Energy (NEE) information security sensors, logging, alerting and other detection mechanisms to identify and respond to threats
  • Acts as subject matter expert for one or multiple assigned cybersecurity technology stacks (e.g., identity and access management, network intrusion detection and prevention, host based security tools)
  • Collaborates with security architecture to identify, evaluate and recommend new security technologies for suitability within NEE's environment and security posture
  • Communicates ongoing cybersecurity activities, priorities and risk measurements or mitigations at multiple organizational levels
  • Provides guidance for security activities and requirements in the system development life cycle (SDLC) and application development efforts. Participates in organizational projects, as required
  • Performs other job-related duties as assigned

Required Qualifications

  • High School Grad / GED
  • Bachelor's or Equivalent Experience
  • Experience: 7+ years

Preferred Qualifications

  • Certified Information Systems Aud (CISA) certification

NextEra Energy offers a wide range of benefits to support our employees and their eligible family members. Click here to learn more.

Employee Group: Exempt
Employee Type: Full Time
Job Category: Information Technology
Organization: Florida Power & Light Company
Relocation Provided: Yes, if applicable

NextEra Energy is an Equal Opportunity Employer. Qualified applicants are considered for employment without regard to race, color, age, national origin, religion, marital status, sex, sexual orientation, gender identity, gender expression, genetics, disability, protected veteran status or any other basis prohibited by law.

NextEra Energy provides reasonable accommodation in its application and selection process for qualified individuals, including accommodations related to compliance with conditional job offer requirements, consistent with federal, state, and local laws. Supporting medical or religious documentation will be required where applicable and permitted by applicable law. To request a reasonable accommodation, please send an e-mail to [email protected], providing your name, telephone number and the best time for us to reach you. Alternatively, you may call 1-844-694-4748. Please do not use this line to inquire about your application status.

NextEra Energy will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information.

NextEra Energy does not accept any unsolicited resumes or referrals from any third-party recruiting firms or agencies. Please see our policy for more information.

获取工作提醒

获取棕榈滩花园,佛罗里达州,美国地区职位机会的工作提醒

关于这个角色

2025年11月2日

全职

公司

2025年11月2日

现场

NextEra Energy

  •  棕榈滩花园,佛罗里达州,美国

7+ years

UTC-05:00

立即申请

工作已过期?

请告知 NextEra Energy 您是在 Rejobs 上找到这份工作的。这将帮助我们成长,并让更多人投身于可再生能源工作!

如何连接

查看您的连接

在 LinkedIn 上查看您在 NextEra Energy 的联系人,在申请此职位时充分利用您的人际网络

与朋友分享

形势严峻,谈话的时机已过。现在是采取行动的时候。 帮助朋友加快向可持续未来的转变。

分享这份工作 - Principal Offensive Security Analyst - 给你的朋友们,帮助他们找到一份值得自豪的职业。