Jobs and Careers
GU

Senior OT Penetration Tester- Remote (Anywhere in the U.S.)

GuidePoint Security LLC
United StatesRemotefull_timeVerifiedPosted 15 Feb 2023

About the role

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

Summary

GuidePoint Security’s Threat & Attack Simulation Practice provides attack-oriented professional services, Red Teaming, Purple Teaming, Industrial Control System (ICS) centric Penetration Testing, Physical Penetration Testing, (I)IOT assessments, Social Engineering, and various ad hoc custom assessments to address unique information security and operational/safety concerns for clients.

As a Senior OT Penetration Tester, you will be a technically adept and reliable team member who leverages their knowledge, skills, and experience to deliver exceptional results to OT/ICS clients on the team’s penetration testing service offerings and who will assist with shaping the future of this aspect of the practice within GuidePoint Security. Your primary responsibilities revolve around performing challenging and complex assessments, knowledge sharing to “level up” team members, contributing to the practice's growth and improvement in OT/ICS offerings, and assisting with pre-sales activities for these types of assessments.

Senior OT Penetration Testers are encouraged to interact with the Threat & Attack Simulation Leadership Team and contribute to the Practice's future success in OT assessments. GuidePoint Security’s Threat & Attack Simulation service offerings are perpetually evolving in response to emerging threats and diverse client needs. Your creativity and expertise will assist the Practice by adapting to this rapidly changing environment and helping to identify opportunities for new OT offerings for the team to grow into.

Role Responsibilities

Technical:

  • Assess network security posture of enterprise-level infrastructure by utilizing industry-standard approaches for conducting vulnerability assessments and penetration testing
  • Possess in-depth knowledge of formal assessment methodologies, as well as when to use intuition to creatively deviate from established processes
  • Identify common vulnerabilities through the use of automated tools and practical analysis
  • Identify obscure vulnerabilities by leveraging your expertise through manual analysis
  • Perform safe and reliable exploitation (to the extent possible) for exploitable vulnerabilities
  • Understand network, operating system, and application-based detective and preventative controls and evade and/or circumvent such controls effectively. o
  • Quickly and efficiently perform post-exploitation activities to fully demonstrate the impact of compromise
  • Familiarity with commercial tools, such as Nessus, BurpSuite Pro, intelx.io, Shellter, Cobalt Strike, and Breach and Attack Simulation tools
  • Mastery of common open-source tools, such as Nmap, tcpdump/Wireshark, Metasploit, and the Kali Linux Suite (or equivalent)
  • Proficient with scripting languages, such as Python, Bash, PowerShell, Go, etc.
  • Proven ability to write code to solve problems and automate tedious and time-consuming tasks during assessments
  • Exploit development and reverse engineering experience is strongly preferred
  • Assess wireless infrastructures and clients that utilize technologies including 802.11, Zigbee, RFID, and Bluetooth
  • Proficiency with web application attacks (e.g., OWASP Top 10) is strongly preferred
  • Understanding of modern cloud architectures and common cloud service provider services and offerings
  • Excels at both remote (phishing and vishing) and onsite/in-person social engineering attacks, with a focus on obtaining sensitive information, physical access, and/or logical access
  • Physical security skills are strongly preferred, including lock picking, evasion of defensive controls, obtaining unauthorized access, and collecting sensitive information.
  • Possess a solid understanding of TCP/IP, networking technologies, firewall concepts, and network segmentation
  • Possess a solid understanding of operating systems, such as Microsoft, Linux, and various Unix variants, as well as supporting technologies, such as Active Directory and LDAP
  • Possess a solid understanding of databases, including vendor-specific technologies, such as MS SQL Server, Oracle, MySQL, and PostgreSQL
  • Experience assessing hardware/IoT devices, including firmware analysis is not required but would be a significant advantage
  • Desire to initiate and conduct research projects
  • Familiarity

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GuidePoint Security LLC

View company profile →