The Senior Offensive Engineering Analyst role focuses on strengthening Income Insurance’s cybersecurity posture through proactive security assurance, BAS-led control validation, and adversary-informed testing.
This includes supporting MAS TRM Guidelines and Cyber Hygiene requirements by providing continuous assurance over the effectiveness of Income’s cybersecurity controls through Breach and Attack Simulation (BAS), control effectiveness testing, and outcome-driven remediation follow-up. This role sits within the IT Risk and Security department under the Cyber Risk Assurance function and reports to the Cyber Risk Assurance Manager.
Key Responsibilities
- Drive continuous Breach and Attack Simulation (BAS) and adversary-informed testing mapped to MITRE ATT&CK to validate preventive, detective, and response controls.
- Collaborate with Cyber Threat Intelligence to develop intelligence-led attack simulations that identify weaknesses across Income’s people, process, and technology pillars.
- Translate BAS and adversary-based testing findings into actionable remediation recommendations for Security Operations and relevant internal teams, enabling improved prevention, detection, response, and overall control effectiveness.
- Strengthen Income’s overall cyber resilience through continuous assurance and control effectiveness assessments.
- Support additional cyber assurance tasks as required, including security testing, hardening compliance reviews, technical risk assessments, process improvement initiatives, and other management-assigned activities.
Qualifications
- Bachelor's Degree in technology, information or cyber risk management, information security or enterprise architecture.
- Minimum of two years’ direct information security experience in cyber assurance, BAS, control validation, technical risk assessment, or similar end-user security roles.
- Hands-on experience operating BAS platforms, designing safe test scenarios, analysing control effectiveness results, and driving remediation or improvement actions.
- Strong automation and coding skillsets, including scripting with Python, PowerShell, APIs, workflow automation, and MCP or AI-assisted automation to improve security assurance processes.
- Good understanding of secure configuration, hardening standards, vulnerability management, OWASP, MAS TRM, compliance review, and enterprise security operations.
- Relevant certifications in security assurance, cloud, automation, offensive security, or risk management such as CISSP, OSCP, GPEN, GWAPT, CREST, or equivalent certifications preferred.
Competencies
- Able to operate BAS end-to-end as a control assurance owner, from test planning and scenario configuration to results analysis, stakeholder follow-up, reporting, and closure tracking. BAS platforms may include Picus Security, Cymulate, or equivalent tools.
- Strong understanding of threat behaviours, TTPs, MITRE ATT&CK mapping, and how these translate into practical control validation, detection engineering, and remediation priorities.
- Able to translate BAS, vulnerability, hardening, and compliance findings into business impact, remediation priorities, measurable improvement actions, and management-ready reporting.
- Keeps abreast of the financial-sector threat landscape, APT groups, and relevant threat actors, and applies these insights to enhance BAS testing and control assurance activities.
- Strong hands-on automation capability, including scripting, API integration, data handling, workflow orchestration, MCP-enabled automation, and the ability to improve repeatability and efficiency of cyber assurance activities.
- Good written communication skills, with the ability to explain security risks and assurance outcomes to technical and non-technical stakeholders.
- Able to work independently as an outcome owner, engage vendors and internal teams effectively, and drive actions to completion across both BAU operations and project initiatives.