Consultant - Offensive Security
Cyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity and access management, and professional services designed to manage the cybersecurity risks of enterprise clients. We specialize in multi-technology, complex environments with the in speed and agility needed to tackle the most advanced cyber threats. We leverage our global scale and decades of experience to accelerate our clients' cyber outcomes through a full lifecycle of cybersecurity services. We are a global company with operating centers in the United States, Canada, the United Kingdom, and India.
Responsibilities :
- Performing threat analysis and recommends appropriate course of action, mitigation, and remediation in response to security events and trends
- Correlates and analyzes threat data from various sources to establish the identity of malicious users active in the computing environment.
- Produce and review intelligence summaries accessible to all clients.
- Engage with clients across report lifecycle : Initial scoping, finished intelligence delivery, and follow-up review / support
- Develop novel, automated, or simpler processes for regular research and analysis
- Track cyber threat trends across industries and technologies, and generate better ways to do so
- Work on projects across multiple research teams with sometimes tight deadlines
- Perform internal and external penetration testing of network infrastructure, applications, and database
- Perform web / mobile application, wireless network, and vulnerability assessments
- Provide support in design and development of purple team and red team exercises performing adversary simulations to test client controls.
- Create comprehensive reports and effectively communicate findings to key stakeholders (technical and / or executive).
- Identify and safely apply attacker tactics, techniques, and procedures (TTPs).
- Develop scripts, tools, or methodologies to enhance Cyderes' red teaming processes.
Requirements :
Certifications such as OSCP, CISSP are preferred2-3 years of experience in three of the following areas :Executing network, wireless, web application, and API penetration testsExperience with Active directory (AD) and KerberosExperience conducting vulnerability management and assessmentsExperience conducting social engineering assessmentsExperience conducting Purple Team and Red Team exercisesExperience with Tenable.IO, Recorded Future, PlexTrac and Cymulate preferredExperience with programming using one or more of the following : Perl, Python, ruby, bash, C or C++, C#, or Java, including scripting, automation, and editing existing codeDeveloping, extending, or modifying exploits, shellcode or exploit toolsReverse engineering malware, data obfuscators, or ciphersSource code review for control flow and security flawsGeneral knowledge of the MITRE ATT&CK FrameworkThorough understanding of network protocols, data on the wire, and covert channelsMastery of Unix / Linux / Mac / Windows operating systems, including bash and PowerShellCyderes is an Equal Opportunity Employer (EOE). Qualified applicants are considered for employment without regard to race, religion, color, sex, age, disability, sexual orientation, genetic information, national origin, or veteran status. Note : This job posting is intended for direct applicants only. We request that outside recruiters do not contact us regarding this position.