Senior Red Team Consultant

Bishop Fox Logo

Bishop Fox

πŸ“Remote - United States

Summary

Join Bishop Fox, a leading offensive security and penetration testing firm, as a remote, US-based red teaming professional. You will run red teaming engagements, from research and profiling organizations to defining attack objectives and performing operations to achieve those objectives. You will help clients understand their attack surface and provide actionable recommendations. As a senior-level consultant, you will solve challenging technical problems, build creative solutions, and advise clients on critical business decisions. You will lead small teams, mentor coworkers, and contribute to the advancement of the consulting practice. Bishop Fox offers a vibrant work environment and comprehensive benefits.

Requirements

  • 5+ years of offensive security experience supporting a variety of adversary emulation engagements (red teaming and purple teaming) with clients from a variety of industries
  • Working knowledge of all common operating systems such as Windows, MacOS, Linux, ChromeOS
  • Expertise in Windows Active Directory exploitation and lateral movement
  • Working knowledge of β€œcloud” platforms (AWS/Azure/GCP and O365/Google Workspace) and container technologies (Kubernetes/Docker)
  • Hands-on experience with c2 frameworks like Sliver, Nighthawk, Mythic, and others
  • Experience with custom tool and payload development, as well as reverse engineering, and evasion techniques
  • Experience researching and developing EDR evasion techniques
  • Proficiency in multiple programming languages (preferably Python, Golang, JavaScript/TypeScript, C#, C/C++, PowerShell, and/or Bash)
  • Network and web-related protocol knowledge (e.g., TCP/IP, HTTP, HTTPS, etc.)
  • Demonstrated experience with social engineering, conducting reconnaissance, development, and delivery of phishing/vishing pretexts as well as an understanding of email security technologies and other related countermeasures
  • Excellent written and verbal communication skills

Responsibilities

  • Run red teaming engagements, starting with research and including profiling organizations, defining attack objectives and crafting attack tree graphs and other key planning efforts
  • Perform operations based on planning to achieve the attack objectives through a variety of potential attack paths, including network, web applications, physical, social engineering, and others
  • Help our customers understand their attack surface by communicating, ability to respond to incidents, report on steps taken, and issues discovered
  • Provide thoughtful, tailored, and actionable recommendations
  • Solve challenging technical problems and build creative solutions in a client-facing role
  • Provide your expert opinion to help our clients navigate difficult business decisions including how to prioritize critical findings
  • Lead small teams on one-of-a-kind engagements, mentor co-workers, and contribute significantly to the advancement of our consulting practice

Preferred Qualifications

  • Expertise in exploit development and/or assembly (x86/arm)
  • Threat modeling, threat intelligence, or incident response experience
  • Experience with DevOps and CI/CD technologies
  • Experience conducting physical penetration testing engagements, including entry skills, RFID hacking, and alarm bypasses
  • OSCP/E, GWAPT, GPEN, or GXPN certifications can be helpful, but are not a necessity

Benefits

  • Generous Time Off and Company-Wide Holidays
  • Team Events and International Travel Opportunities
  • Work From Home Support
  • Monthly Allowance for Cell Phone and Internet
  • Training Budget
  • Retirement; 401k Matching for Traditional and Roth Accounts in the US
  • Health Insurance Options Including Medical, Dental, Vision
  • Paid Parental Leave

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Remote Jobs