Posted in

Senior Offensive Security Engineer – Infosec

Senior Offensive Security Engineer – Infosec

CompanyPalo Alto Networks
LocationSanta Clara, CA, USA
Salary$Not Provided – $Not Provided
TypeFull-Time
Degrees
Experience LevelSenior

Requirements

  • 6+ years cyber security experience with minimum 2-4 years experience leading covert end-to-end Red Team engagements
  • Experience crafting social engineering campaigns and establishing initial access in a mature environment with a complex technology stack
  • Experience developing payloads across languages and platforms while evading endpoint and network security products
  • Experience with various command and control frameworks, across a variety of platforms and environments
  • Must have the ability to perform targeted attacks with or without the use of automated tools
  • Expertise in executing a wide array of adversarial tactics, techniques, and procedures
  • Experience performing adversarial simulation
  • Experience in conducting surreptitious on-premise and cloud based attacks
  • Excellent written and verbal communication skills
  • Ability to establish priorities, work independently and proceed with objectives
  • Must be well organized and able to leverage best practices, able to thrive in fast-paced environment, and, most importantly, have the ability to approach problems with an innovative, can-do attitude

Responsibilities

  • Develop payloads and attack tools which bypass security controls for use in covert operations
  • Execute Red Team operations to highlight gaps impacting enterprise security posture and readiness
  • Simulate real-world attacks that are relevant to the business
  • Deliver detailed reports of technical findings to stakeholders and assist with the development of mitigation plans
  • Deliver executive technical outbriefs to leadership across the organization
  • Assist with security investigations, root-cause analysis and corrective measures as required

Preferred Qualifications

  • Certifications like OSCP/OSCE, CRTP, CRTO/CRTL are nice to have
  • Examples of Public Speaking, Community contributions, blogs, research, open source tool, bug bounties are highly desirable