Requirements
The Red Team Expert will plan and execute full-scope red team engagements mimicking real-world threat actors, conduct advanced social engineering and targeted phishing campaigns, perform thorough assessments of complex production environments, develop custom malware and exploits to evade EDR, manage C2 frameworks, maintain strict OpSec discipline, and conduct offensive security research. Required certifications include OSCP, OSCE, CRTP, CRTO, and CRTL.
Description
Job DescriptionJoin our dedicated Cyber Assurance Team within the Information Risk Management Department. Reporting to the Cyber Assurance Lead, you will play a critical role in strengthening our organization'ssecurity posture.The Cyber Assurance team is responsible for proactively assessing and enhancing our security defenses. This involves conducting comprehensive ethical hacking activities and adversary simulations toidentify potential vulnerabilities and control gaps. Your expertise will be vital in providing actionable recommendations to fortify our systems and ensure the resilience of our digital assets.ResponsibilitiesRoles and responsibilities:Adversary emulation: Plan and execute full-scope red team engagements that mimic real-world threat actors, including initial access, privilege escalation, and lateral movement.Phishing campaigns: Conduct advanced social engineering and targeted phishing campaigns that bypass modern email gateways.Technical assessments: Perform thorough assessments of complex production environments, including network infrastructure, cloud services, and applications.Malware development and EDR bypass: Develop custom malware, exploits, and post-exploitation tools designed to evade detection by Endpoint Detection and Response (EDR) and other security controls.C2 infrastructure management: Deploy, manage, and operate command-and-control (C2) frameworks such as Cobalt Strike, Brute Ratel C4, and Nighthawk C2.Operational security (OpSec): Maintain strict OpSec discipline to ensure all red team activities remain covert and undetected by defensive teams.Research and development (R&D): Conduct offensive security research to stay current with the latest tactics, techniques, and procedures (TTPs) and develop new tools and methodologies.QualificationsCertificationsOSCPOSCECRTPCRTOCRTL