Red Team Security Engineer
On-siteCharleston, South Carolina, United States
Job Summary
Conduct multiple penetration testing engagements on global customer networks, managing red team and penetration test engagements from cradle to grave. Rapidly develop domain-specific tools and scripts using PowerShell, Bash, and Python to leverage identified vulnerabilities while researching latest exploitation techniques and threat vectors. Design and configure representative test environments, perform web application security assessments, and analyze packet captures using network protocol analyzers. Assist with business development activities including technical documentation creation and proposal writing support. Requires active Secret Clearance with TS/SCI eligibility, DoD 8570 IAT Level II certification, and OSCP or equivalent within one year.
Required Qualifications
- active Secret Clearance with eligibility to obtain a Top Secret/SCI Clearance
- active DoD 8570 IAT Level II certification (CCNA-Security, CySA+, CND, or Security+ CE)
- one of the following certifications: OSCP, OSWE, CRTO, CPTS, CBBH, PNPT, GRTP, GX-PT, GXPN, OR obtain within 1 year from starting
- minimum of an active Secret Clearance with eligibility to obtain a Top Secret/SCI Clearance
- Bachelor's degree in Cybersecurity, Computer Science, Engineering, or Mathematics
- At least 3 years of experience in computer design, software development or computer networks
- At least 1 year of experience in Penetration Testing
- Experience with PowerShell, Bash, and Python
- Experience performing web application security assessments
- Experience with TCP/IP protocols as it relates to network security
- Experience with offensive tool sets such as Kali Linux or Cobalt Strike
- Experience in using network protocol analyzers and sniffers, as well as the ability to decipher packet captures
- Excellent independent, self-motivational, organizational, and project management skills
- Proven ability to work effectively with managers, staff, vendors, and external consultants
- Must think outside the box to emulate adversarial approaches
- Capable of conducting penetration tests on applications, systems and networks utilizing proven/formal processes and industry standards
- Capable of managing red team and/or penetration test engagements from cradle to grave
- In-depth understanding of emerging threats, vulnerabilities, and exploits
- Understanding of what Red Team C2 infrastructure is and how it works regarding covert remote operations
- Have the ability to independently and rapidly develop tools and scripts from concept to production in a high-stress, short deadline, environment using multiple programming languages
- Must be comfortable with prolonged periods of sitting at a desk and working on a computer
- Must be able to lift up to 10-15 pounds at a time
- Less than 25% travel
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.