Senior Offensive Security Engineer – Infosec
Company | Palo Alto Networks |
---|---|
Location | Santa Clara, CA, USA |
Salary | $Not Provided – $Not Provided |
Type | Full-Time |
Degrees | |
Experience Level | Senior |
Requirements
- 6+ years cyber security experience with minimum 2-4 years experience leading covert end-to-end Red Team engagements
- Experience crafting social engineering campaigns and establishing initial access in a mature environment with a complex technology stack
- Experience developing payloads across languages and platforms while evading endpoint and network security products
- Experience with various command and control frameworks, across a variety of platforms and environments
- Must have the ability to perform targeted attacks with or without the use of automated tools
- Expertise in executing a wide array of adversarial tactics, techniques, and procedures
- Experience performing adversarial simulation
- Experience in conducting surreptitious on-premise and cloud based attacks
- Excellent written and verbal communication skills
- Ability to establish priorities, work independently and proceed with objectives
- Must be well organized and able to leverage best practices, able to thrive in fast-paced environment, and, most importantly, have the ability to approach problems with an innovative, can-do attitude
Responsibilities
- Develop payloads and attack tools which bypass security controls for use in covert operations
- Execute Red Team operations to highlight gaps impacting enterprise security posture and readiness
- Simulate real-world attacks that are relevant to the business
- Deliver detailed reports of technical findings to stakeholders and assist with the development of mitigation plans
- Deliver executive technical outbriefs to leadership across the organization
- Assist with security investigations, root-cause analysis and corrective measures as required
Preferred Qualifications
- Certifications like OSCP/OSCE, CRTP, CRTO/CRTL are nice to have
- Examples of Public Speaking, Community contributions, blogs, research, open source tool, bug bounties are highly desirable