Senior Ethical Hacker, Applications & Cloud

Stantec
Franklin, MI
Full-time

Senior Ethical Hacker, Applications & Cloud - ( 24000331 )

Description

Grow with the best. Join a smart, creative, and inspired team that accomplishes operational excellence. Bringing together individuals with diverse backgrounds, talents, and expertise, our 31,000 team members in over 450 locations worldwide are vital to making our Company stronger.

Your Opportunity

The Senior Ethical Hacker will conduct security assessments on web applications and cloud services by emulating real-world attacks using the Mitre Attack Framework.

Their goal is to identify security weaknesses, help prevent data breaches and enhance the security posture by uncovering vulnerabilities, misconfigurations, and risks proactively before they are discovered by threat actors.

Your Key Responsibilities

Communication

  • Collaborate with cross-functional teams (security, engineering, cloud and network operations).
  • Create reports and communicate findings to various technical teams, architects and engineers.
  • Create and communicate processes that could help engineering teams meet remediation goals.
  • Create and verbally present your test findings in debrief meetings with the C-Suite or sponsors.

Cloud and Application

  • Conduct penetration tests on cloud systems, applications and APIs to identify vulnerabilities.
  • Assess cloud / application specific configurations, access controls, and encryption mechanisms.
  • Validate and exploit security findings within web / thick client apps and cloud environments.
  • Validate various app services, databases, Kubernetes, serverless functions, container instances, images and cloud storage blob / buckets for security issues.

Project work / Knowledge Share

  • Assist / Create rules of engagement for new pen test projects.
  • Create or populate content in the internal training lab so developers and security champions can stay current in offensive security with practical CTF's when time permits.
  • Provide live hacking webinars for teams interested in learning by example.
  • Conduct internal Red Team engagements.
  • Participate in purple team engagements.

Qualifications

Your Capabilities and Credentials

  • Minimum 5-7 years working in some aspect of cybersecurity (Offensive Security, Red Team experience preferred).
  • Proficient with manual web / cloud penetration testing without using any tools.
  • Proficient writing custom attack tools in Python, PHP, Golang and Bash Scripting.
  • Proficient with interception proxies and attacking manually via Burp Suite Enterprise tool.
  • Proficient building / maintaining attack automation systems (Commercial or Open-Source).
  • Proficient building containers and automation pipelines for attacking purposes.
  • Experience combining multiple low / medium findings to weaponize and achieve a higher level.
  • Comfortable working exclusively from Windows or Linux command line.
  • Comfortable "living off the land" using VIM / VI / Bash / SH / Perl / VBScript / WMI / PowerShell for post exploitation and lateral movement.
  • Comfortable with writing XSS attacks, System / SQL injection payloads or weaponizing binaries.
  • Comfortable attacking various popular public cloud services in (Azure / AWS / GCP / Oracle).
  • Comfortable presenting audit findings to a small group or C-Suite during debrief meetings.
  • Comfortable taking ownership for testing actions and performing blameless post-mortems.

Preference for the following additional Skills / Certifications

  • OffSec Web Expert (OSWE) - Preferred
  • GIAC Web Application Penetration Tester (GWAPT)
  • Burp Suite Certified Practitioner (BSCP)
  • Pentester Academy Cloud Security Professional (PACSP)
  • Acknowledged findings in a responsible disclosure or public, private Bug Bounty program.
  • Certified Kubernetes Security Specialist (CKS)
  • Terraform Associate (003)
  • DevSecOps experience

Education and Experience

  • Minimum 5 years relevant experience.
  • Related Degree or Certificate, preferably in area of Offensive Security and Application Security

This description is not a comprehensive listing of activities, duties or responsibilities that may be required of the employee and other duties, responsibilities and activities may be assigned or may be changed at any time with or without notice.

Stantec is a place where the best and brightest come to build on each other's talents, do exciting work, and make an impact on the world around us.

Join us and redefine your personal best.

Benefits Summary : Regular full-time and part-time employees have access to medical, dental, and vision plans, a wellness program, health saving accounts, flexible spending accounts, 401(k) plan, employee stock purchase program, life and accidental death & dismemberment (AD&D) insurance, short-term / long-term disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage and paid family leave.

Regular full-time and part-time employees will receive ten paid holidays in each calendar year. In addition, employees will be eligible to accrue vacation between 10 and 20 days per year and eligible for paid sick leave (and if more generous, in accordance with state and local law).

Temporary / casual employees have access to 401(k) plans, employee stock purchase program, and paid leave, in accordance with state and local law.

The benefits information listed above may not apply to union positions because benefits for such positions are governed by applicable collective bargaining agreements.

Primary Location : United States-Texas-Austin

Other Locations : United States-Georgia-Atlanta, United States-Michigan-Berkley, United States-Florida-Miami, United States-Florida-Tampa, United States-Michigan-Brighton, United States-Pennsylvania-Pittsburgh, United States-Michigan-Farmington Hills

Organization : BC-1973 IT Services-US Corporate

Employee Status : Regular

Job Level : Individual Contributor

Travel : No

Schedule : Full-time

Job Posting : Aug 15, 2024, 8 : 21 : 21 AM

Req ID : 24000331

additional

Stantec provides equal employment opportunities to all qualified employees and applicants for future and current employment and prohibit discrimination on the grounds of race, color, religion, sex, national origin, age, marital status, genetic information, disability, protected veteran status, sexual orientation, gender identity or gender expression.

We prohibit discrimination in decisions concerning recruitment, hiring, referral, promotion, compensation, fringe benefits, job training, terminations or any other condition of employment.

Stantec is in compliance with local, state and federal laws and regulations and ensures equitable opportunities in all aspects of employment.

EEO including Disability / Protected Veterans

30+ days ago
Related jobs
Promoted
Stantec
Franklin, Michigan

Senior Ethical Hacker, Applications & Cloud - ( 24000331 ). The Senior Ethical Hacker will conduct security assessments on web applications and cloud services by emulating real-world attacks using the Mitre Attack Framework. Collaborate with cross-functional teams (security, engineering, cloud a...

Promoted
Buildertrend
Westland, Michigan
Remote

The Product Design Manager will lead and develop a high-performing team of product designers embedded in agile crews who are focused on growth initiatives. As a Product Design Manager, you will work closely with cross-functional teams, including engineers, marketing, and sales teams, to ensure desig...

Promoted
Intuit
Livonia, Michigan
Remote

As part of this position, you have the opportunity to work 100% remotely, collaborating with an exceptional team from the comfort of your home or office. By providing tax advice, full service return preparation, tax calculations, and managing product/software inquiries, you will be working toward ad...

Promoted
Professional Career Solutions
Sterling Heights, Michigan

Remote position (Work from home). Comfortable working remotely and independently. ...

Promoted
Maverick FX
Livonia, Michigan

This is a remote/work from home position. As a contract business, traders will be their own boss, with the opportunity to work full-time or part-time from anywhere in the world with a high-speed internet connection. Operate from anywhere in the world with a high-speed internet connection. Ability to...

Promoted
Online Consumer Panels America
Detroit, Michigan

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies. Online Consumer Panels America is a consulting firm that specializes in product testing and product development work. We design and conduct In-Home Usage Testing...

Promoted
Digital Room LLC
Wixom, Michigan
Remote

Lead our product team to deliver exceptional internal customer experiences across our facilities and operational teams. Create business cases and requirements for a unique product or set of systems, functions, and features in Digital Room’s suite of software and systems. Act as a coordinator o...

Promoted
Dynatrace
Detroit, Michigan

POs, and federal authorities, ensuring the creation of relevant documentation and successful product delivery. CISO, the CPO, product management, development, marketing, and legal. Ideally experienced in the world of SaaS products. ...

Promoted
WebProps.org
Detroit, Michigan
Remote

This is a fantastic opportunity to work from the comfort of your own home, anywhere in the USA -- but we'd prefer you to be on the CST or EST time zone. Fully remote work – your home is your office!. Flexibility to live & work anywhere on any of the US time zones, we especially like it...

Promoted
Great Lion
Sterling Heights, Michigan

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies. A paid Product Tester position is perfect for those looking for an entry-level opportunity, flexible or seasonal work, temporary work or part-time work. Telecomm...