Hybrid 3 days / week onsite at Jersey City, NJ, 07310 / Dallas, TX, 75019 / Tampa, FL, 33647
CTH
2 round interview process
MUST have Network Penetration Testing experience
Description:
Reporting to the Offensive Cyber Operations Team Lead, you are responsible for conducting advanced security assessments including automated and manual testing across a wide range of technologies and systems. As a senior technical assessor, you participate in the planning, execution, and reporting of complex security tests designed to emulate real-world adversaries. You are a key member of the Offensive Cyber Operations (OCO) team and are expected to contribute to threat modeling, emergent technology research, and a high tempo testing schedule. You will routinely collaborate with a diverse group of security testing professionals and may be required to travel domestically and internationally to support assessment activities.
Expectations for the Offensive Cyber Security Senior Associate:
Conduct automated and manual security tests of information systems, including analysis of vulnerability scan results, compliance findings, and penetration test data.
Utilize advanced techniques such as threat modeling, threat simulation, and social engineering to assess system risk.
Research and understand a wide variety of existing and emerging technologies relevant to assessment activities.
Develop test plans, create operational schedules, execute tests, and prepare detailed after action reports.
Document all activities in accordance with DTCC Information Security Policies and Offensive Cyber Operations team standard operating procedures.
Participate in year round testing cycles based on criticality, threat modeling, and new points of vulnerability (NPOV).
Collaborate with teammates to support large, complex, and multi assessor security projects.
Travel up to 10% to support global testing activities.
Maintain strong professional bearing and represent the team effectively when interacting with system owners and business stakeholders.
To succeed in this role, you should:
Have at least five (5) years of professional level experience in one or more technical disciplines, including Penetration Testing, Networking, Firewalls, Server Administration, Encryption, Cloud, Containers, Databases, or Software Development.
Possess hands-on, expert level technical proficiency in at least one critical skill area, supported by relevant certifications.
Hold (or be working toward) multiple professional or associate level certifications, such as CISSP, GCIH, MCSE, CCNP, RHCE, GPEN, GWAPT, OSCP, MPCE, or CEH.
Demonstrate advanced understanding of adversarial tactics, techniques, and procedures (TTPs).
Be proficient with multiple open source and commercial security tools (e.g., Nessus, Burp Suite, AppDetective, Metasploit, NMAP).
Understand the strengths, weaknesses, configuration requirements, and troubleshooting needs of common security tools.
Have strong proficiency working with both UNIX based and Microsoft operating systems, with deep systems engineering experience in at least one of them.
Understand security guidelines such as NIST 800 53 and NIST 800 115.
Be able to synthesize and analyze large volumes of data from complex systems.
Demonstrate the ability to clearly articulate technical findings to both technical and non technical audiences.
Exhibit strong critical thinking ability and creativity in designing and executing test approaches.
EEO: Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.