Senior Security Consultant-Threat & Attack Simulation- Remote (Anywhere in the U.S.)
GuidePoint Security LLCAbout the role
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
Overview
GuidePoint Security's Threat and Attack Simulation (TAS) Practice is seeking a highly skilled Senior Security Consultant to join our team. We provide attack-oriented professional services, including Red Teaming and Purple Teaming, and various custom assessments. As a Senior Security Consultant, you will leverage your expertise to deliver exceptional results to clients and help shape the future of our practice.
Key Responsibilities
- Conduct offensive engagements ranging in size, scope, focus, and approach
- Deliver TAS professional services, including Red Team Assessments, Purple Team Assessments, and custom assessments
- Author comprehensive assessment deliverables tailored to both technical and managerial audiences
- Contribute to marketing initiatives through research publication, conference speaking, blog writing, and security tool development
- Utilize automation, orchestration, and scripting to improve efficiency and enable new capabilities
- Assist with practice development, including improving existing offerings and mentoring team members
- Foster strong client relationships and represent GuidePoint Security professionally
Technical Requirements
- Serve as a subject matter expert (SME) in two or more areas: initial access, advanced adversary tradecraft, offensive operations against Windows environments, evasion operations, or offensive capability development
- Advanced knowledge of and practical experience with AD-related attacks and privilege escalation techniques
- Advanced knowledge in social engineering tradecraft such as phishing and vishing
- Proficiency in Windows environments and related offensive techniques
- Strong understanding of networking concepts and related offensive techniques
- Experience with red team infrastructure
- Experience with various public cloud components and architectures (AWS, Azure, GCP). Red team experience against these is a bonus!
- Ability to create tools/scripts that support the Practice's day-to-day assessment activities
- Experience with utilizing, configuring, and developing for common commercial C2 frameworks
- Experience developing Beacon Object Files (BOF)
- Experience in evading security detection controls
Required Qualifications
- Minimum of four (4) years of experience performing offensive/attack-oriented security assessments
- Experience in programming with 1 object-oriented and 1 scripting programming language
- Minimum of two (2) years of experience in an enterprise-level consulting services role
- Over six (6+) combined years of IT and information security experience is strongly preferred
- Ability to confidently discuss report findings with both technical and non-technical audiences
- Strong written and verbal communication skills
Desired Qualifications
- OSCP/OSEP certification
- CRTO/CRTL certification
- InfoSec community involvement (conference speaking, blog/whitepaper authoring, podcast speaking/producing)
- Experience managing multiple projects simultaneously
Work Environment
- Remote work
- Expectation to travel domestically and internationally (average 25% over the course of one year, may include bursts up to 50%)
- Collaborative team environment focused on continuous learning and improvement
- We are growing our capabilities as a team. Someone looking to build something new and leave their mark is a bonus!
We use Greenhouse Software as our applicant tracking system and Free Busy for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.
Why GuidePoint?
GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1000 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 4,200 customers.
Firmly-defined core values drive all aspects of the business, which have been paramou
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s