Offensive Security Engineer - Red / Purple Team

Bluefin Resources · Brisbane QLD 4000 · Contract
Posted 18d ago

Offensive Security Engineer - Red / Purple Team

Bluefin Resources
$253k - $278k
$1000 - $1100 per day
Bluefin Resources Logo
KEY POINTS WE FOUND
  • Lead red and purple team engagements against critical applications and infrastructure.
  • Validate client controls and logging to ensure they catch real attacks.
  • Propose remediation and drive findings into the engineering backlog.

  • Leading Insurance Group
  • Can be based in Sydney / Melbourne / Brisbane
  • $120/130k + super / Hybrid model
  • Brisbane or Sydney Based role
  • 12-month Contract
  • WFH – 3days in office and 2 days WFH

 
As an Offensive Security Engineer, you will Validates whether client controls, detection and logging actually catch real attacks and identifies and supports closing the gaps.
The role scopes, plans, manages and undertakes cyber hunt, penetration testing, red team, threat emulation and other technical security assurance activities across networks, applications, cloud services, end-user environments and enterprise platforms.
 
 
Responsibilities

  • Runs red and purple team engagements against critical apps, infrastructure and controls
  • Builds and maintains fit-for-purpose red team infrastructure
  • Validates controls, detection and logging; finds gaps and proves they are closed
  • Owns and matures Breach & Attack Simulation
  • Demonstrated experience planning, scoping and conducting penetration testing, cyber hunt, red team, threat emulation or similar technical security assurance activities across enterprise technology environments;
  • Strong technical knowledge of common vulnerability classes, exploitation methods, operating systems, networks, web applications, cloud services, security controls and the tools and methodologies used to assess them
  • Closes the loop: proposes remediation, new detections, log sources and controls; drives findings into the engineering backlog
  • Acts as the validation arm of threat-informed defence (ATT&CK-mapped)

Must-have

  • Hands-on offence: adversary emulation, C2, exploitation, attack-path analysis across cloud / infra / endpoint
  • Detection and logging fluency (the purple half)
  • BAS and ATT&CK
  • Python and automation; tight rules-of-engagement discipline

Bonus

  • AI coding / agentic tools (GPT-5.5 Trusted Access for Cyber, Codex, Claude Code, Copilot or similar) to find and prove exploitable vulns at repo scale
  • GitLab Ultimate; standing up AI-assisted code-analysis infrastructure
  • Detection engineering
  • Application / code security experience (SAST, DAST, SCA)

 
How to apply Applications are treated with absolute confidentiality. Click APPLY or contact Gary at gary@bluefinresources.com.au or an informal conversation about your next career move

Consultant

Gary@bluefinresources.com.au

Reference number: BH-62726
Profession:ICTSecurity / Cyber Security

Company: Bluefin Resources
Date posted: 24th Aug, 2026

Stay Safe While Job Hunting

We vet all employer accounts and do our best to keep job ads safe, but scams can still occur. Be cautious when sharing personal information — never provide financial details or make payments during the application process. For extra security, use the Apply button on our site when proceeding.

Skills

0 of 34 matched
Adversary emulationAgentic toolsAi codingAi-assisted code analysisApplication securityAttack-path analysisAutomationBreached & attack simulation (bas)C.2Cloud securityCloud servicesCode security (sast, dast, sca)Cyber huntCyber securityDetection engineeringExcellent communication skillsExploitationGitlabLog analysisNetwork infrastructureNetwork securityPenetration testingPenetration testing toolsProblem solvingPythonSecurity assessmentSecurity awarenessSecurity controlsSecurity controls validationTeamworkThreat detectionThreat emulationWeb application securityWeb applications

Bluefin Resources

Bluefin Resources Logo